CWE-754

Medium likelihood

Improper Check for Unusual or Exceptional Conditions

Parent: CWE-703 - Improper Check or Handling of Exceptional Conditions

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

557 vulnerabilities with CWE-754
CVE-2026-35225 HIGH
Improper timeout handling in CODESYS EtherNetIP
CVE-2026-34066 MEDIUM
nimiq-blockchain: Peer-triggerable panic during history sync
CVSS 5.3
CVE-2026-35366 MEDIUM
uutils coreutils printenv Security Inspection Bypass via UTF-8 Enforcement
CVSS 4.4
CVE-2026-40343 MEDIUM
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation
CVSS 5.8
CVE-2026-6772 HIGH
Incorrect boundary conditions in the Libraries component in NSS
CVSS 7.5
CVE-2026-6766 HIGH
Incorrect boundary conditions in the Libraries component in NSS
CVSS 7.5
CVE-2026-40249 MEDIUM
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors
CVSS 5.3
CVE-2026-21009 MEDIUM
Samsung Mobile Devices - App Pinning Bypass
CVSS 6.8
CVE-2026-21007 MEDIUM
Samsung Mobile Devices - Auth Bypass
CVSS 6.8
CVE-2026-33790 HIGH
Junos OS: SRX Series: In a NAT64 configuration, receipt of a specific, malformed ICMPv6 packet will cause the srxpfe process to crash and restart.
CVSS 7.5
CVE-2026-33787 MEDIUM
Junos OS: SRX1500, SRX4100, SRX4200, SRX4600: When a specific show command is executed chassisd crashes
CVSS 5.5
CVE-2026-33786 MEDIUM
Junos OS: SRX1600, SRX2300, SRX4300: When a specific show command is executed chassisd crashes
CVSS 5.5
CVE-2026-33781 MEDIUM
Junos OS: EX Series, QFX Series: In a VXLAN scenario when specific control protocol packets are received, memory leaks and eventually no traffic is passed
CVSS 6.5
CVE-2026-33774 MEDIUM
Junos OS: MX Series: Firewall filters on lo0.<non-0> in the default routing instance are not in effect
CVSS 6.5
CVE-2026-40069 HIGH
bsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcasts
CVSS 7.5
CVE-2026-31790 HIGH
Incorrect Failure Handling in RSA KEM RSASVE Encapsulation
CVSS 7.5
CVE-2026-39395 MEDIUM
Cosign's verify-blob-attestation reports false positive when payload parsing fails
CVSS 4.3
CVE-2026-4748 HIGH
pf silently ignores certain rules
CVSS 7.5
CVE-2026-33939 HIGH
Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation
CVSS 7.5
CVE-2026-3109 LOW
Missing timestamp validation in Zoom webhook handler
CVSS 2.2
CVE-2026-20719 MEDIUM
DoS via URL Previews Rendering Malicious SVGs
CVSS 4.3
CVE-2026-4719 HIGH
Incorrect boundary conditions in the Graphics: Text component
CVSS 7.5
CVE-2026-4714 HIGH
Incorrect boundary conditions in the Audio/Video component
CVSS 7.5
CVE-2026-4713 HIGH
Incorrect boundary conditions in the Graphics component
CVSS 7.5
CVE-2026-4709 HIGH
Incorrect boundary conditions in the Audio/Video: GMP component
CVSS 7.5
Details
Vulnerabilities 557
Exploit Likelihood Medium