CWE-754

Medium likelihood

Improper Check for Unusual or Exceptional Conditions

Parent: CWE-703 - Improper Check or Handling of Exceptional Conditions

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

605 vulnerabilities with CWE-754
CVE-2026-4699 HIGH
Incorrect boundary conditions in the Layout: Text and Fonts component
CVSS 7.5
CVE-2026-4697 HIGH
Incorrect boundary conditions in the Audio/Video: Web Codecs component
CVSS 7.5
CVE-2026-4695 HIGH
Incorrect boundary conditions in the Audio/Video: Web Codecs component
CVSS 7.5
CVE-2026-4694 HIGH
Incorrect boundary conditions, integer overflow in the Graphics component
CVSS 7.5
CVE-2026-4693 HIGH
Incorrect boundary conditions in the Audio/Video: Playback component
CVSS 7.5
CVE-2026-4690 HIGH
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
CVSS 8.6
CVE-2026-4689 CRITICAL
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
CVSS 10.0
CVE-2026-4687 HIGH
Sandbox escape due to incorrect boundary conditions in the Telemetry component
CVSS 8.6
CVE-2026-4686 HIGH
Incorrect boundary conditions in the Graphics: Canvas2D component
CVSS 7.5
CVE-2026-4685 HIGH
Incorrect boundary conditions in the Graphics: Canvas2D component
CVSS 7.5
CVE-2026-33151 HIGH
socket.io allows an unbounded number of binary attachments
CVSS 7.5
CVE-2026-0230 MEDIUM
Palo Alto Cortex XDR macOS - Privilege Escalation
CVE-2026-30900 HIGH
Zoom Client for Windows - Privilege Escalation
CVSS 7.8
CVE-2026-0109 HIGH
Android - Denial of Service in dhd_tcpdata_info_get
CVSS 7.5
CVE-2026-30960 CRITICAL
rssn < 0.2.9 - Arbitrary Code Execution via JIT Compilation Engine
CVE-2026-22760 LOW
Dell Device Management Agent < 26.02 - Denial of Service
CVSS 3.3
CVE-2026-2801 HIGH
Firefox < 148.0 and Thunderbird < 148.0 - Incorrect Boundary Conditions in JavaScript WebAssembly Component
CVSS 7.5
CVE-2026-0229 MEDIUM
Palo Alto Networks PAN-OS Unauthenticated DoS via Advanced DNS Security Packet
CVE-2026-25639 HIGH
axios < 0.30.3 and 1.0.0-1.13.5 - Denial of Service via __proto__ Property in Configuration Object
CVSS 7.5
CVE-2026-0944 MEDIUM
Drupal Group invite < 2.3.9, 3.0.0-3.0.4, 4.0.0-4.0.4 - Forceful Browsing
CVSS 5.3
CVE-2026-24513 LOW
ingress-nginx < 1.13.7 and < 1.14.3 - Authentication Bypass via Misconfigured Custom-Errors Backend
CVSS 3.1
CVE-2026-20419 MEDIUM
MediaTek NBIOT SDK < 3.6 and Software Development Kit < 7.6.7.2 - Denial of Service via Uncaught Exception
CVSS 6.5
CVE-2026-20406 MEDIUM
Modem - Use After Free
CVSS 6.5
CVE-2026-20401 HIGH
MediaTek NR15 and MT Series - Remote Denial of Service via Rogue Base Station
CVSS 7.5
CVE-2026-24054 CRITICAL
Kata Containers <3.26.0 - Info Disclosure
CVSS 10.0
Details
Vulnerabilities 605
Exploit Likelihood Medium