CWE-754
Medium likelihoodImproper Check for Unusual or Exceptional Conditions
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
605 vulnerabilities with CWE-754
CVE-2026-4699
HIGH
Incorrect boundary conditions in the Layout: Text and Fonts component
CVSS 7.5
CVE-2026-4697
HIGH
Incorrect boundary conditions in the Audio/Video: Web Codecs component
CVSS 7.5
CVE-2026-4695
HIGH
Incorrect boundary conditions in the Audio/Video: Web Codecs component
CVSS 7.5
CVE-2026-4694
HIGH
Incorrect boundary conditions, integer overflow in the Graphics component
CVSS 7.5
CVE-2026-4693
HIGH
Incorrect boundary conditions in the Audio/Video: Playback component
CVSS 7.5
CVE-2026-4690
HIGH
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
CVSS 8.6
CVE-2026-4689
CRITICAL
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
CVSS 10.0
CVE-2026-4687
HIGH
Sandbox escape due to incorrect boundary conditions in the Telemetry component
CVSS 8.6
CVE-2026-4686
HIGH
Incorrect boundary conditions in the Graphics: Canvas2D component
CVSS 7.5
CVE-2026-4685
HIGH
Incorrect boundary conditions in the Graphics: Canvas2D component
CVSS 7.5
CVE-2026-33151
HIGH
socket.io allows an unbounded number of binary attachments
CVSS 7.5
CVE-2026-0230
MEDIUM
Palo Alto Cortex XDR macOS - Privilege Escalation
CVE-2026-30900
HIGH
Zoom Client for Windows - Privilege Escalation
CVSS 7.8
CVE-2026-0109
HIGH
Android - Denial of Service in dhd_tcpdata_info_get
CVSS 7.5
CVE-2026-30960
CRITICAL
rssn < 0.2.9 - Arbitrary Code Execution via JIT Compilation Engine
CVE-2026-22760
LOW
Dell Device Management Agent < 26.02 - Denial of Service
CVSS 3.3
CVE-2026-2801
HIGH
Firefox < 148.0 and Thunderbird < 148.0 - Incorrect Boundary Conditions in JavaScript WebAssembly Component
CVSS 7.5
CVE-2026-0229
MEDIUM
Palo Alto Networks PAN-OS Unauthenticated DoS via Advanced DNS Security Packet
CVE-2026-25639
HIGH
axios < 0.30.3 and 1.0.0-1.13.5 - Denial of Service via __proto__ Property in Configuration Object
CVSS 7.5
CVE-2026-0944
MEDIUM
Drupal Group invite < 2.3.9, 3.0.0-3.0.4, 4.0.0-4.0.4 - Forceful Browsing
CVSS 5.3
CVE-2026-24513
LOW
ingress-nginx < 1.13.7 and < 1.14.3 - Authentication Bypass via Misconfigured Custom-Errors Backend
CVSS 3.1
CVE-2026-20419
MEDIUM
MediaTek NBIOT SDK < 3.6 and Software Development Kit < 7.6.7.2 - Denial of Service via Uncaught Exception
CVSS 6.5
CVE-2026-20406
MEDIUM
Modem - Use After Free
CVSS 6.5
CVE-2026-20401
HIGH
MediaTek NR15 and MT Series - Remote Denial of Service via Rogue Base Station
CVSS 7.5
CVE-2026-24054
CRITICAL
Kata Containers <3.26.0 - Info Disclosure
CVSS 10.0
Details
Vulnerabilities
605
Exploit Likelihood
Medium