CWE-754

Medium likelihood

Improper Check for Unusual or Exceptional Conditions

Parent: CWE-703 - Improper Check or Handling of Exceptional Conditions

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

605 vulnerabilities with CWE-754
CVE-2026-0667 CRITICAL
Schneider Electric SCADAPack 47x - Improper Check for Unusual or Exceptional Conditions
CVE-2026-65904 MEDIUM
DOMPurify before 3.4.4 Cross-Site Scripting via IN_PLACE mode
CVSS 4.7
CVE-2026-44621 MEDIUM
Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated
CVSS 5.9
CVE-2026-63754 MEDIUM
SurrealDB before 3.1.0 Denial of Service via LIVE Query
CVSS 6.5
CVE-2026-21764 LOW
Insufficient Input Validation in DevOps Loop
CVSS 3.1
CVE-2026-8075 MEDIUM
Posting a malicious markdown image crashes the Mattermost Desktop App
CVSS 6.5
CVE-2026-57031 MEDIUM
Junos OS: MX Series: For subscribers configured on static interfaces, input filters are not in effect
CVSS 4.7
CVE-2026-57022 MEDIUM
Junos OS MX/SRX PFE - Packet-Triggered Denial of Service
CVSS 5.9
CVE-2026-57020 MEDIUM
Junos OS: QFX10000 Series: IPv6 multicast traffic received on non-IRB interfaces causes a multicast flood
CVSS 6.5
CVE-2026-33801 MEDIUM
Junos OS and Junos OS Evolved: When a specifically malformed BGP route update is received RPD crashes
CVSS 6.5
CVE-2026-33794 MEDIUM
Junos OS Evolved: PTX Series: Receipt of repeated ECMP routing updates results in PFE crash
CVSS 5.9
CVE-2026-0287 HIGH
PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing
CVSS 7.5
CVE-2026-54775 MEDIUM
CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.
CVSS 6.5
CVE-2026-56812 HIGH
Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff
CVSS 7.5
CVE-2026-43928 LOW
FOSSBilling: Payment amount not validated in PayPalEmail adapter allows invoice underpayment
CVE-2026-55577 MEDIUM
ImageMagick: Heap Buffer Overflow in ImageMagick MVG decoder
CVSS 5.9
CVE-2026-54269 MEDIUM
protobufjs: Schema-derived names can shadow runtime-significant properties
CVSS 5.3
CVE-2026-47216 HIGH
Typesense: Unauthenticated Denial of Service in the Typesense /multi_search Endpoint
CVE-2026-0269 MEDIUM
PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing
CVSS 5.7
CVE-2026-46541 HIGH
Nimiq network-libp2p: DHT query poisoning via first-record verification failure
CVSS 7.5
CVE-2026-45678 HIGH
OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads
CVSS 7.5
CVE-2026-49325 MEDIUM
Indian Scout Bobber 2025 WCM voltage-based shutdown
CVSS 4.6
CVE-2026-49318 LOW
Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at boot
CVSS 2.4
CVE-2026-49317 LOW
Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at boot
CVSS 2.4
CVE-2026-49316 MEDIUM
Indian Scout Bobber 2025 WCM CAN bus-off attack silently bypasses anti-theft shutdown
CVSS 4.6
Details
Vulnerabilities 605
Exploit Likelihood Medium