CWE-248— Uncaught Exception
An exception is thrown from a function, but it is not caught.— MITRE CWE catalog
328 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-248page 3 of 7
- CVE-2026-32770HIGHCVSS 7.5EG 7.52026-03-18
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.19 and 8.6.43, a remote attacker can crash the Parse Server by subscribing to a LiveQuery with an invalid regular …
- CVE-2026-32314HIGHCVSS 7.5EG 7.52026-03-16
Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. Prior to 0.13.10, the Rust implementation of Yamux can panic when processing a crafted inbound Data frame that sets SYN and uses a body length greater than DE…
- CVE-2026-2229HIGHCVSS 7.5EG 7.52026-03-12
ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it automa…
- CVE-2026-1528HIGHCVSS 7.5EG 7.52026-03-12
ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process.…
- CVE-2026-31870HIGHCVSS 7.5EG 7.52026-03-11
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.1, when a cpp-httplib client uses the streaming API (httplib::stream::Get, httplib::stream::Post, etc.), the library calls std::stoull() direct…
- CVE-2026-1507HIGHCVSS 7.5EG 7.52026-02-10
The affected products are vulnerable to an uncaught exception that could allow an unauthenticated attacker to remotely crash core PI services resulting in a denial-of-service.
- CVE-2026-25577HIGHCVSS 7.5EG 7.52026-02-10
Emmett is a framework designed to simplify your development process. Prior to 1.3.11, the cookies property in mmett_core.http.wrappers.Request does not handle CookieError exceptions when parsing malformed Cookie headers. This allows unauth…
- CVE-2026-25128HIGHCVSS 7.5EG 7.52026-01-30
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 5.0.9 through 5.3.3, a RangeError vulnerability exists in the numeric entity proce…
- CVE-2025-59466HIGHCVSS 7.5EG 7.52026-01-20
We have identified a bug in Node.js error handling where "Maximum call stack size exceeded" errors become uncatchable when `async_hooks.createHook()` is enabled. Instead of reaching `process.on('uncaughtException')`, the process terminates…
- CVE-2025-59465HIGHCVSS 7.5EG 7.52026-01-20
A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unhandled `TLSSocket` error `ECONNRESET`. Instead of safely closing the connection, the process crashes, enabling a remote …
- CVE-2025-66578HIGHCVSS 7.5EG 7.52025-12-09
xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Versions 3.1.3 contain an authentication bypass vulnerability due to a flaw in the libxml2 canonicalization process during document transformation. When…
- CVE-2025-12423HIGHCVSS 7.5EG 7.52025-10-28
Protocol manipulation might lead to denial of service.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
- CVE-2025-59462HIGHCVSS 7.5EG 7.52025-10-27
An attacker who tampers with the C++ CLI client may crash the UpdateService during file transfers, disrupting updates and availability.
- CVE-2025-62370HIGHCVSS 7.5EG 7.52025-10-15
Alloy Core libraries at the root of the Rust Ethereum ecosystem. Prior to 0.8.26 and 1.4.1, an uncaught panic triggered by malformed input to alloy_dyn_abi::TypedData could lead to a denial-of-service (DoS) via eip712_signing_hash(). Softw…
- CVE-2025-59538HIGHCVSS 7.5EG 7.52025-10-01
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. For versions 2.9.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.6 and 3.0.17, when the webhook.azuredevops.username and webhook.azuredevops.password are not…
- CVE-2025-55557HIGHCVSS 7.5EG 7.52025-09-25
A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS).
- CVE-2025-55553HIGHCVSS 7.5EG 7.52025-09-25
A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).
- CVE-2013-10065HIGHCVSS 7.5EG 7.52025-08-05
A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A specially crafted SSH key exchange packet can trigger a crash in the service, resulting in loss of availability. The flaw is triggered durin…
- CVE-2025-7338HIGHCVSS 7.5EG 7.52025-07-17
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.2 allows an attacker to trigger a Denial of Service (DoS) by sending a malformed mu…
- CVE-2025-29785HIGHCVSS 7.5EG 7.52025-06-02
quic-go is an implementation of the QUIC protocol in Go. The loss recovery logic for path probe packets that was added in the v0.50.0 release can be used to trigger a nil-pointer dereference by a malicious QUIC client. In order to do so, t…
- CVE-2025-47944HIGHCVSS 7.5EG 7.52025-05-19
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.0 allows an attacker to trigger a Denial of Service (DoS) by sending a malformed mu…
- CVE-2025-23166HIGHCVSS 7.5EG 7.52025-05-19
The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untruste…
- CVE-2025-3891HIGHCVSS 7.5EG 7.52025-04-29
A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The serve…
- CVE-2025-20664HIGHCVSS 7.5EG 7.52025-04-07
In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed…
- CVE-2025-20663HIGHCVSS 7.5EG 7.52025-04-07
In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed…
- CVE-2024-58112HIGHCVSS 7.5EG 7.52025-04-07
Exception capture failure vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2024-58111HIGHCVSS 7.5EG 7.52025-04-07
Exception capture failure vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2025-3083HIGHCVSS 7.5EG 7.52025-04-01
Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur without using an authenticated connection. This issue affects MongoDB v5.0 versions prior to 5.0.31, MongoDB v6.0 ver…
- CVE-2024-8249HIGHCVSS 7.5EG 7.52025-03-20
mintplex-labs/anything-llm version git 6dc3642 contains an unauthenticated Denial of Service (DoS) vulnerability in the API for the embeddable chat functionality. An attacker can exploit this vulnerability by sending a malformed JSON paylo…
- CVE-2024-8020HIGHCVSS 7.5EG 7.52025-03-20
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the `/api/v1/state` endpoint of `LightningApp`. This issue occurs due to improper hand…
- CVE-2024-11172HIGHCVSS 7.5EG 7.52025-03-20
A vulnerability in danny-avila/librechat version git a1647d7 allows an unauthenticated attacker to cause a denial of service by sending a crafted payload to the server. The middleware `checkBan` is not surrounded by a try-catch block, and …
- CVE-2025-20637HIGHCVSS 7.5EG 7.52025-02-03
In network HW, there is a possible system hang due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR003990…
- CVE-2024-20137HIGHCVSS 7.5EG 7.52024-12-02
In wlan driver, there is a possible client disconnection due to improper handling of exceptional conditions. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exp…
- CVE-2024-43367HIGHCVSS 7.5EG 7.52024-08-15
Boa is an embeddable and experimental Javascript engine written in Rust. Starting in version 0.16 and prior to version 0.19.0, a wrong assumption made when handling ECMAScript's `AsyncGenerator` operations can cause an uncaught exception o…
- CVE-2024-38525HIGHCVSS 7.5EG 7.52024-06-28
dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malformed unicode, it logs the list of audited headers and their values using the `nlohmann` JSON library. However, due to the …
- CVE-2023-5038HIGHCVSS 7.5EG 7.52024-06-25
badmonkey, a Security Researcher has found a flaw that allows for a unauthenticated DoS attack on the camera. An attacker runs a crafted URL, nobody can access the web management page of the camera. and must manually restart the device or …
- CVE-2024-34363HIGHCVSS 7.5EG 7.52024-06-04
Envoy is a cloud-native, open source edge and service proxy. Due to how Envoy invoked the nlohmann JSON library, the library could throw an uncaught exception from downstream data if incomplete UTF-8 strings were serialized. The uncaught e…
- CVE-2024-3052HIGHCVSS 7.5EG 7.52024-04-26
Malformed S2 Nonce Get command classes can be sent to crash the gateway. A hard reset is required to recover the gateway.
- CVE-2024-3051HIGHCVSS 7.5EG 7.52024-04-26
Malformed Device Reset Locally command classes can be sent to temporarily deny service to an end device. Any frames sent by the end device will not be acknowledged by the gateway during this time.
- CVE-2023-52342HIGHCVSS 7.5EG 7.52024-04-08
In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed
- CVE-2023-3966HIGHCVSS 7.5EG 7.52024-02-22
A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink…
- CVE-2024-23325HIGHCVSS 7.5EG 7.52024-02-09
Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that isn’t supported by the OS. Envoy is susceptible to crashing on a host with IPv6 disabled and a listener config with pr…
- CVE-2023-46765HIGHCVSS 7.5EG 7.52023-11-08
Vulnerability of uncaught exceptions in the NFC module. Successful exploitation of this vulnerability can affect NFC availability.
- CVE-2023-46239HIGHCVSS 7.5EG 7.52023-10-31
quic-go is an implementation of the QUIC protocol in Go. Starting in version 0.37.0 and prior to version 0.37.3, by serializing an ACK frame after the CRYTPO that allows a node to complete the handshake, a remote node could trigger a nil p…
- CVE-2023-46135HIGHCVSS 7.5EG 7.52023-10-25
rs-stellar-strkey is a Rust lib for encode/decode of Stellar Strkeys. A panic vulnerability occurs when a specially crafted payload is used.`inner_payload_len` should not above 64. This vulnerability has been patched in version 0.0.8.
- CVE-2023-42447HIGHCVSS 7.5EG 7.52023-09-19
blurhash-rs is a pure Rust implementation of Blurhash, software for encoding images into ASCII strings that can be turned into a gradient of colors representing the original image. In version 0.1.1, the blurhash parsing code may panic due …
- CVE-2023-42444HIGHCVSS 7.5EG 7.52023-09-19
phonenumber is a library for parsing, formatting and validating international phone numbers. Prior to versions `0.3.3+8.13.9` and `0.2.5+8.11.3`, the phonenumber parsing code may panic due to a panic-guarded out-of-bounds access on the pho…
- CVE-2023-4785HIGHCVSS 7.5EG 7.52023-09-13
Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. No…
- CVE-2023-39948HIGHCVSS 7.5EG 7.52023-08-11
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0 and 2.6.5, the `BadParamException` thrown by Fast CDR is not caught in Fast DDS. This can remotely…
- CVE-2023-38504HIGHCVSS 7.5EG 7.52023-07-27
Sails is a realtime MVC Framework for Node.js. In Sails apps prior to version 1.5.7,, an attacker can send a virtual request that will cause the node process to crash. This behavior was fixed in Sails v1.5.7. As a workaround, disable the s…
Map vulnerabilities like CWE-248 to your infrastructure
EchelonGraph correlates every CVE — across CWE-248 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →