CWE-754
Medium likelihoodImproper Check for Unusual or Exceptional Conditions
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
588 vulnerabilities with CWE-754
CVE-2024-38355
HIGH
Socket.IO < 2.5.1 and 3.0.0-4.6.2 - Denial of Service via Crafted Packet
CVSS 7.3
CVE-2024-38461
HIGH
iRODS < 4.3.2 - Denial of Service via Invalid Directory Path Handling
CVSS 7.5
CVE-2024-34694
HIGH
LNbits < 0.12.6 - Payment Timeout Handling Leading to Fund Loss
CVSS 8.1
CVE-2024-5469
LOW
GitLab 16.10.0-16.10.5 and 16.11.0-16.11.2 - Denial of Service via Crafted gRPC Requests
CVSS 3.1
CVE-2024-36128
HIGH
Directus < 10.11.2 - Denial of Service via Random String Generation Utility
CVSS 7.5
CVE-2024-4611
HIGH
AppPresser < 4.4.0 - Unauthenticated Authentication Bypass via Missing OpenSSL Exception Handling
CVSS 8.1
CVE-2024-35785
HIGH
Linux Kernel - Denial of Service via OP-TEE Device Registration Error Handling
CVSS 7.1
CVE-2024-21809
MEDIUM
Intel Quartus Prime < 23.1 - Authenticated Privilege Escalation via Local Access
CVSS 6.7
CVE-2024-4367
HIGH
Firefox < 126 and ESR < 115.11 - Arbitrary JavaScript Execution in PDF.js via Missing Type Check
CVSS 8.8
CVE-2024-34360
HIGH
go-spacemesh < 1.5.2-hotfix1 and api < 1.37.1 - Improper ATX Chain Validation
CVSS 8.2
CVE-2024-32867
MEDIUM
Suricata 6.0.0-6.0.18 - Rule and Policy Mis-detection via Fragmentation Anomaly Handling
CVSS 5.3
CVE-2024-3729
CRITICAL
Frontend Admin by DynamiApps <= 3.19.4 - Privilege Escalation & Auth Bypass via Encryption Handling
CVSS 9.8
CVE-2024-4182
MEDIUM
Mattermost 8.1.0-8.1.11, 9.4.0-9.4.4, 9.5.0-9.5.2 - Authenticated Denial of Service via Malformed Custom Status JSON
CVSS 4.3
CVE-2024-30402
MEDIUM
Juniper Junos OS and Junos OS Evolved - Unauthenticated Denial of Service via l2ald Crash
CVSS 5.9
CVE-2024-30397
HIGH
Juniper Junos Multiple Versions - Unauthenticated DoS in PKI Daemon
CVSS 7.5
CVE-2024-30384
MEDIUM
Juniper Junos OS < 20.4R3-S10; 21.2 < 21.2R3-S7; 21.4 < 21.4R3-S6 - Authenticated Denial of Service via CLI Command
CVSS 5.5
CVE-2024-30409
MEDIUM
Juniper Junos OS and Junos OS Evolved 22.1-22.1R1 - Authenticated Denial of Service via Telemetry Processing
CVSS 5.3
CVE-2024-1713
HIGH
plv8 3.2.1 - Privilege Escalation via Deferred Trigger Execution
CVSS 7.2
CVE-2024-20037
MEDIUM
Android - Local Privilege Escalation via Incorrect Bounds Check in pq
CVSS 6.7
CVE-2024-1622
HIGH
Routinator < 0.13.2 - Denial of Service via RTR Connection Reset
CVSS 7.5
CVE-2024-1556
MEDIUM
Firefox < 123.0 - Invalid Memory Access via Built-in Profiler NULL Check
CVSS 6.5
CVE-2024-25739
MEDIUM
Linux Kernel < 6.7.4 - Denial of Service via Zero-Byte Allocation in UBI Volume Table
CVSS 5.5
CVE-2024-23650
MEDIUM
BuildKit < 0.12.5 - Denial of Service via Crafted Frontend Request
CVSS 5.3
CVE-2024-24567
MEDIUM
vyperlang/vyper < 0.3.10 - Incorrect Value Handling in raw_call Builtin
CVSS 4.8
CVE-2024-0675
MEDIUM
Lamassu Bitcoin ATM Douro <7.1 - Privilege Escalation
CVSS 6.3
Details
Vulnerabilities
588
Exploit Likelihood
Medium