CWE-754

Medium likelihood

Improper Check for Unusual or Exceptional Conditions

Parent: CWE-703 - Improper Check or Handling of Exceptional Conditions

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

605 vulnerabilities with CWE-754
CVE-2026-5343 HIGH
SAML SSO - Service Provider - Critical - Authentication bypass - SA-CONTRIB-2026-031
CVSS 7.4
CVE-2026-39929 HIGH
Lakeside SysTrack Agent LsiAgent.exe Out-of-Bounds Read via UDP
CVSS 7.5
CVE-2026-44324 MEDIUM
free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request)
CVSS 6.5
CVE-2026-44322 HIGH
free5GC: NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failure due to nil ProblemDetails dereference
CVSS 7.5
CVE-2026-44317 MEDIUM
free5GC: PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference
CVSS 6.5
CVE-2026-44316 HIGH
free5GC: PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference
CVSS 7.5
CVE-2026-4915 MEDIUM
Mattermost - Server Panic via Outgoing Webhook Responses
CVSS 6.5
CVE-2026-40094 MEDIUM
nimiq-blockchain: network-libp2p untrusted peer can crash address book via empty peer contact addresses
CVSS 4.3
CVE-2026-5946 HIGH
BIND 9.11.0-9.16.50, 9.18.0-9.18.48, 9.20.0-9.20.22, 9.21.0-9.21.21 - DoS via Non-IN DNS Message Handling
CVSS 7.5
CVE-2026-8491 LOW
Node View Permissions - Moderately critical - Access bypass - SA-CONTRIB-2026-034
CVSS 3.7
CVE-2026-47315 MEDIUM
Samsung Open Source Escargot - Improper Check for Unusual or Exceptional Conditions
CVSS 5.5
CVE-2026-4643 LOW
Calling window.close() from server-side content causes crash in the Mattermost Desktop App
CVSS 3.5
CVE-2026-4054 MEDIUM
SVG content served through Mattermost image proxy despite Content-Type restrictions causes client-side denial of service
CVSS 4.3
CVE-2026-0262 HIGH
PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing
CVSS 7.5
CVE-2026-0241 HIGH
Trust Protection Foundation: Multiple Authorization Bypass Vulnerabilities
CVSS 7.2
CVE-2026-0235 MEDIUM
Prisma Browser: Access and Data Rule Bypass
CVSS 4.7
CVE-2026-42950 MEDIUM
Elecom Co.,ltd. WAB-BE187-M - Improper Check for Unusual or Exceptional Conditions
CVSS 4.3
CVE-2026-20754 MEDIUM
Intel(R) NPU Drivers - Denial of Service via Improper Conditions Check
CVE-2026-42349 HIGH
Clerk: Authorization bypass when combining organization, billing, or reverification checks
CVSS 8.1
CVE-2026-42246 HIGH
net-imap vulnerable to STARTTLS stripping via invalid response timing
CVSS 7.4
CVE-2026-8091 CRITICAL
Incorrect boundary conditions in the Audio/Video: Playback component
CVSS 9.8
CVE-2026-41662 MEDIUM
Admidio: Missing Minimum Administrator Check in Role Membership Removal
CVSS 5.2
CVE-2026-35225 HIGH
Improper timeout handling in CODESYS EtherNetIP
CVE-2026-34066 MEDIUM
nimiq-blockchain: Peer-triggerable panic during history sync
CVSS 5.3
CVE-2026-35366 MEDIUM
uutils coreutils printenv Security Inspection Bypass via UTF-8 Enforcement
CVSS 4.4
Details
Vulnerabilities 605
Exploit Likelihood Medium