CWE-248

Uncaught Exception

Parent: CWE-705 - Incorrect Control Flow Scoping

An exception is thrown from a function, but it is not caught.

206 vulnerabilities with CWE-248
CVE-2026-46689 HIGH
Kanidm: Unauthenticated process abort via SCIM filter stack exhaustion
CVE-2026-46545 HIGH
nimiq-primitives: Panic DoS in trie chunk processing via ROOT-keyed item
CVSS 7.5
CVE-2026-46411 MEDIUM
FlashMQ: Client can trigger uncaught exception on FlashMQ 1.26.1 and older
CVSS 6.5
CVE-2026-45685 HIGH
OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages
CVSS 7.5
CVE-2026-45676 MEDIUM
OpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed ELF to crash agent
CVSS 5.5
CVE-2026-45554 MEDIUM
NiceGUI: Unauthenticated log-flood DoS via trailing slash on ESM and per-component resource routes
CVSS 5.3
CVE-2026-9509 HIGH
Suprema BioStar 2 Server - Unhandled Exception Denial of Service
CVE-2026-44905 HIGH
Vanetza: Remote Denial of Service via Uncaught OER Encoding Exception in Cryptographic Verification
CVSS 7.5
CVE-2026-43988 HIGH
Vanetza: Remote Denial of Service via Uncaught Exception in ASN.1/OER Parsing
CVSS 7.5
CVE-2026-44001 HIGH
vm2: Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS)
CVSS 8.6
CVE-2026-42545 MEDIUM
Granian: DoS via WSGI response header panic
CVSS 5.9
CVE-2026-42544 HIGH
Granian: Unauthenticated DoS via WebSocket subprotocol header panic
CVSS 7.5
CVE-2026-42268 HIGH
ModSecurity: Unsigned integer underflow in @verifySSN / @verifyCPF / @verifySVNR operators
CVSS 7.5
CVE-2026-8161 HIGH
multiparty vulnerable to Denial of Service via Prototype Pollution leading to Uncaught Exception
CVSS 7.5
CVE-2026-41585 MEDIUM
ZEBRA: Denial of Service via Interrupted JSON-RPC Requests from Authenticated Clients
CVSS 6.5
CVE-2026-37554 HIGH
Vanetza V2X v26.02 - Unauthenticated Denial of Service via OpenSSL ECC Point Validation Exception
CVSS 7.5
CVE-2026-7183 MEDIUM
aligungr UERANSIM Radio Link Simulation Layer rls_pdu.cpp DecodeRlsMessage uncaught exception
CVSS 5.3
CVE-2026-5937 MEDIUM
Foxit PDF Editor/Reader's insufficient parameter validation leads to denial-of-service vulnerability
CVSS 5.5
CVE-2026-35348 MEDIUM
uutils coreutils sort Local Denial of Service via Forced UTF-8 Parsing
CVSS 5.5
CVE-2026-34944 MEDIUM
Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on x86-64
CVSS 5.7
CVE-2026-34943 HIGH
Wasmtime panics when lifting `flags` component value
CVSS 7.5
CVE-2026-24175 HIGH
NVIDIA Triton Inference Server < 26.02 - Denial of Service via Malformed Request Header
CVSS 7.5
CVE-2026-34986 HIGH
Go JOSE affect by a panic in JWE decryption
CVSS 7.5
CVE-2026-34752 HIGH
Haraka affected by DoS via `__proto__` email header
CVSS 7.5
CVE-2026-33203 HIGH
SiYuan <3.6.2 WebSocket Auth Keepalive - Denial of Service
CVSS 7.5
Details
Vulnerabilities 206