CWE-248— Uncaught Exception
An exception is thrown from a function, but it is not caught.— MITRE CWE catalog
328 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-248page 4 of 7
- CVE-2023-1691HIGHCVSS 7.5EG 7.52023-07-06
Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally.
- CVE-2023-3405HIGHCVSS 7.5EG 7.52023-06-27
Unchecked parameter value in M-Files Server in versions before 23.6.12695.3 (excluding 23.2 SR2 and newer) allows anonymous user to cause denial of service
- CVE-2023-2251HIGHCVSS 7.5EG 7.52023-04-24
Uncaught Exception in GitHub repository eemeli/yaml prior to 2.0.0-5.
- CVE-2023-0158HIGHCVSS 7.5EG 7.52023-01-17
NLnet Labs Krill supports direct access to the RRDP repository content through its built-in web server at the "/rrdp" endpoint. Prior to 0.12.1 a direct query for any existing directory under "/rrdp/", rather than an RRDP file such as "/rr…
- CVE-2022-38166HIGHCVSS 7.5EG 7.52022-11-25
In F-Secure Endpoint Protection for Windows and macOS before channel with Capricorn database 2022-11-22_07, the aerdl.dll unpacker handler crashes. This can lead to a scanning engine crash, triggerable remotely by an attacker for denial of…
- CVE-2022-39386HIGHCVSS 7.5EG 7.52022-11-08
@fastify/websocket provides WebSocket support for Fastify. Any application using @fastify/websocket could crash if a specific, malformed packet is sent. All versions of fastify-websocket are also impacted. That module is deprecated, so it …
- CVE-2022-24434HIGHCVSS 7.5EG 7.52022-05-20
This affects all versions of package dicer. A malicious attacker can send a modified form to server, and crash the nodejs service. An attacker could sent the payload again and again so that the service continuously crashes.
- CVE-2021-41545HIGHCVSS 7.5EG 7.52022-05-10
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). When the…
- CVE-2022-25324HIGHCVSS 7.5EG 7.52022-05-06
All versions of package bignum are vulnerable to Denial of Service (DoS) due to a type-check exception in V8, when verifying the type of the second argument to the .powm function, V8 will crash regardless of Node try/catch blocks.
- CVE-2022-24822HIGHCVSS 7.5EG 7.52022-04-06
Podium is a library for building micro frontends. @podium/layout is a module for building a Podium layout server, and @podium/proxy is a module for proxying HTTP requests from a layout server to a podlet server. In @podium/layout prior to …
- CVE-2021-33010HIGHCVSS 7.5EG 7.52022-04-04
An exception is thrown from a function in AVEVA System Platform versions 2017 through 2020 R2 P01, but it is not caught, which may cause a denial-of-service condition.
- CVE-2021-37714HIGHCVSS 7.5EG 7.52021-08-18
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that cau…
- CVE-2020-15796HIGHCVSS 7.5EG 7.52020-12-14
A vulnerability has been identified in SIMATIC ET 200SP Open Controller (incl. SIPLUS variants) (V20.8), SIMATIC S7-1500 Software Controller (V20.8). The web server of the affected products contains a vulnerability that could allow a remot…
- CVE-2020-6019HIGHCVSS 7.5EG 7.52020-11-13
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function CConnectionTransportUDPBase::Received_Data(), leading to an exception thrown from libprotobuf and resulting in a crash.
- CVE-2020-10604HIGHCVSS 7.5EG 7.52020-07-25
In OSIsoft PI System multiple products and versions, a remote, unauthenticated attacker could crash PI Network Manager service through specially crafted requests. This can result in blocking connections and queries to PI Data Archive.
- CVE-2020-5129HIGHCVSS 7.5EG 7.52020-03-26
A vulnerability in the SonicWall SMA1000 HTTP Extraweb server allows an unauthenticated remote attacker to cause HTTP server crash which leads to Denial of Service. This vulnerability affected SMA1000 Version 12.1.0-06411 and earlier.
- CVE-2019-6829HIGHCVSS 7.5EG 7.52019-09-17
A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware version prior to V2.90) and Modicon M340 (firmware version prior to V3.10), which could cause a possible denial of service when writing to specific memory address…
- CVE-2019-6828HIGHCVSS 7.5EG 7.52019-09-17
A CWE-248: Uncaught Exception vulnerability exists Modicon M580 (firmware version prior to V2.90), Modicon M340 (firmware version prior to V3.10), Modicon Premium (all versions), and Modicon Quantum (all versions), which could cause a poss…
- CVE-2019-6809HIGHCVSS 7.5EG 7.52019-09-17
A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware versions prior to V2.90), Modicon M340 (firmware versions prior to V3.10), Modicon Premium (all versions), Modicon Quantum (all versions), which could cause a pos…
- CVE-2019-10931HIGHCVSS 7.5EG 7.52019-07-11
A vulnerability has been identified in All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respective Ethernet communication modules (All versions ), DIGSI 5 engineering software (All versions < V7.90), SIPROTEC 5 d…
- CVE-2018-7852HIGHCVSS 7.5EG 7.52019-05-22
A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service when an invalid private command parameter is sent to the control…
- CVE-2019-6575HIGHCVSS 7.5EG 7.52019-04-17
A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V2.7), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (incl. SIPLUS variant…
- CVE-2016-10363HIGHCVSS 7.5EG 7.52017-06-16
Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets could perform a denial of service attack on the Logstash instance. The errors resulting fro…
- CVE-2023-22941HIGHCVSS 6.5EG 7.52023-02-14
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, an improperly-formatted ‘INGEST_EVAL’ parameter in a Field Transformation crashes the Splunk daemon (splunkd).
- CVE-2026-96274HIGHCVSS 7.4EG 7.42026-09-29
In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS payload. Because the eNodeB does not properly validate this payload, it forwards t…
- CVE-2024-20276HIGHCVSS 7.4EG 7.42024-03-27
A vulnerability in Cisco IOS Software for Cisco Catalyst 6000 Series Switches could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly. This vulnerability is due to improper handling of proces…
- CVE-2022-20761HIGHCVSS 7.4EG 7.42022-04-15
A vulnerability in the integrated wireless access point (AP) packet processing of the Cisco 1000 Series Connected Grid Router (CGR1K) could allow an unauthenticated, adjacent attacker to cause a denial of service condition on an affected d…
- CVE-2023-22292HIGHCVSS 7.3EG 7.32023-11-14
Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2026-27819HIGHCVSS 7.2EG 7.22026-02-25
Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the restoreConfig function in vikunja/pkg/modules/dump/restore.go of the go-vikunja/vikunja repository fails to sanitize file paths within the provided…
- CVE-2021-33145HIGHCVSS 7.2EG 7.22024-02-23
Uncaught exception in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2025-44019HIGHCVSS 7.1EG 7.12025-06-12
AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI Data Archive subsystems, resulting in a denial of service. Depending on the t…
- CVE-2025-24836HIGHCVSS 7.1EG 7.12025-02-13
With a specially crafted Python script, an attacker could send continuous startMeasurement commands over an unencrypted Bluetooth connection to the affected device. This would prevent the device from connecting to a clinician's app to t…
- CVE-2024-54106HIGHCVSS 7.1EG 7.12024-12-12
Null pointer dereference vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2022-41940HIGHCVSS 7.1EG 7.12022-11-22
Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the No…
- CVE-2026-72813MEDIUMCVSS 6.9EG 6.92026-08-14
actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the process on-demand by sending a GET request…
- CVE-2026-52738MEDIUMCVSS 6.9EG 6.92026-07-02
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a consensus-valid block containing a long chain of transparent self-spends to one address can permanently halt Zebra nodes. In zebra-state/src/service/finalized_state/zebra_db…
- CVE-2026-100722MEDIUMCVSS 6.8EG 6.82026-09-27
vm2 before 3.12.2 does not apply host-side Promise rejection handling in the sandbox-to-host construct trap. In BaseHandler, the apply trap calls markHostPromiseHandled() on the returned value, but the adjacent construct path returns the r…
- CVE-2026-65834MEDIUMCVSS 6.8EG 6.82026-07-30
Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMetadata.ForbiddenLabels.Regex and CapsuleConfiguration.Spec.NodeMetadata.ForbiddenAnnotations.Regex were not validated by…
- CVE-2023-20628MEDIUMCVSS 6.7EG 6.72023-03-07
In thermal, there is a possible memory corruption due to an uncaught exception. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS074944…
- CVE-2026-105757MEDIUMCVSS 6.5EG 6.52026-10-05
vLLM is an inference and serving engine for large language models. Prior to 0.30.0, structured-output request failures can escape request-scoped validation and reach the EngineCore fatal-error path. A per-request backend mismatch can re-ra…
- CVE-2026-105756MEDIUMCVSS 6.5EG 6.52026-10-05
vLLM is an inference and serving engine for large language models. Prior to 0.30.0, OpenAI-compatible request models accept a non-empty cache_salt value without enforcing the character and length restrictions required by the IPCCacheServer…
- CVE-2026-100675MEDIUMCVSS 6.5EG 6.52026-09-26
stoatchat versions before 0.15.5 contain a denial of service vulnerability in the acknowledgement worker that processes mass mention messages. Authenticated users can send five crafted role-mention messages to terminate all acknowledgement…
- CVE-2026-69839MEDIUMCVSS 6.5EG 6.52026-09-08
Uncaught exception in Windows iSCSI Target Service allows an authorized attacker to deny service over a network.
- CVE-2026-82058MEDIUMCVSS 6.5EG 6.52026-09-08
A flaw in MongoDB's JSON Schema validation error generation code allows an authenticated user with readWrite privileges to crash the mongod server. When a BSON document containing an array with a malformed numeric field name fails a $jsonS…
- CVE-2022-51014MEDIUMCVSS 6.5EG 6.52026-09-07
PocketMine-MP before 4.0.7 contains an unhandled exception vulnerability in the ModalFormResponsePacket handler when processing malformed JSON from clients. Attackers can send specially crafted form response packets with invalid JSON to tr…
- CVE-2026-72644MEDIUMCVSS 6.5EG 6.52026-09-01
Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only the low-privileged feature access required to use the Observability AI Assistant can submit …
- CVE-2026-72660MEDIUMCVSS 6.5EG 6.52026-08-13
Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged access can cause an interna…
- CVE-2025-71391MEDIUMCVSS 6.5EG 6.52026-07-18
SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated users to crash the database. Attackers can send crafted HTTP queries containing null bytes to the /sql endpoint, causin…
- CVE-2024-58369MEDIUMCVSS 6.5EG 6.52026-07-18
SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic. Authorized clients can invoke these entities at unsupported levels to crash the Surr…
- CVE-2024-58365MEDIUMCVSS 6.5EG 6.52026-07-18
SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls to nonexistent built-in functions. Authorized clients can craft pre-parsed queries invoking nonexistent functions to tr…
Map vulnerabilities like CWE-248 to your infrastructure
EchelonGraph correlates every CVE — across CWE-248 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →