CWE-755

Medium likelihood

Improper Handling of Exceptional Conditions

Parent: CWE-703 - Improper Check or Handling of Exceptional Conditions

The product does not handle or incorrectly handles an exceptional condition.

572 vulnerabilities with CWE-755
CVE-2026-44505 MEDIUM
Nimiq network-libp2p: Untrusted peer can wedge DHT
CVSS 5.3
CVE-2026-49235 HIGH
Routinator crashes on specifically crafted RRDP XML files
CVSS 7.5
CVE-2026-49232 HIGH
Routinator exits when accepting an incoming HTTP or RTR connection fails
CVE-2026-9516 HIGH
Cpanel::JSON::XS < 4.41 - UTF-8 BOM Decode Denial of Service
CVSS 7.5
CVE-2026-48524 LOW
PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
CVSS 3.7
CVE-2026-44325 HIGH
free5GC: NRF POST /oauth2/token structured-form parser type-confusion panic family (Reflect.Set on incompatible types)
CVSS 7.5
CVE-2026-44319 HIGH
free5GC: NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-controlled notifyUri)
CVSS 7.5
CVE-2026-44902 HIGH
opentelemetry-js: Prometheus exporter process crash via malformed HTTP request
CVSS 7.5
CVE-2026-48961 HIGH
IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID
CVSS 7.3
CVE-2026-42545 MEDIUM
Granian: DoS via WSGI response header panic
CVSS 5.9
CVE-2026-8162 HIGH
multiparty vulnerable to Denial of Service via Uncaught Exception in filename* parameter parsing
CVSS 7.5
CVE-2026-34065 HIGH
nimiq-primitives: Node crash due to missing interlink validation in election macro block proposals
CVSS 7.5
CVE-2026-23666 HIGH
Microsoft .NET Framework - Input Validation Denial of Service
CVSS 7.5
CVE-2026-40074 HIGH
SvelteKit's invalidated redirect in handle hook causes Denial-of-Service
CVSS 7.5
CVE-2026-30798 HIGH
RustDesk Client <=1.4.5 - Protocol Manipulation
CVSS 7.5
CVE-2026-28542 HIGH
System Service Framework - Auth Bypass
CVSS 7.3
CVE-2026-27809 CRITICAL
psd-tools < 1.12.2 - Denial of Service via Malformed RLE-Compressed Image Data
CVSS 9.1
CVE-2026-27195 HIGH
Wasmtime 39.0.0-40.0.3 - Denial of Service via Async Component Function Call Panic
CVSS 7.5
CVE-2026-27586 CRITICAL
Caddy < 2.11.1 - mTLS Authentication Bypass via Missing or Malformed CA Certificate
CVSS 9.1
CVE-2026-25957 MEDIUM
Cubejs-backend Server-core < 1.4.2 - Improper Exception Handling
CVSS 6.5
CVE-2026-23762 MEDIUM
VB-Audio Voicemeeter <1.1.1.9-3.1.1.9 - Memory Corruption
CVE-2026-21906 HIGH
Juniper Junos < 21.4 - Improper Exception Handling
CVSS 7.5
CVE-2026-0203 MEDIUM
Juniper Junos Multiple Versions - Unauthenticated DoS via Malformed ICMPv4 Packet
CVSS 6.5
CVE-2025-69255 MEDIUM
RustFS 1.0.0-alpha.13-1.0.0-alpha.77 - Denial of Service via Malformed gRPC GetMetrics Request
CVSS 4.0
CVE-2025-68274 HIGH
emiago sipgo 0.3.0-1.0.0-alpha-1 - Denial of Service via NewResponseFromRequest Nil Pointer Dereference
CVSS 7.5
Details
Vulnerabilities 572
Exploit Likelihood Medium