CWE-755— Improper Handling of Exceptional Conditions
The product does not handle or incorrectly handles an exceptional condition.— MITRE CWE catalog
634 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-755page 1 of 13
- CVE-2020-7247CRITICALCVSS 9.8EG 9.8⚠ KEV2020-01-29
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacters in a MAIL FROM f…
- CVE-2017-5638CRITICALCVSS 9.8EG 9.8⚠ KEV2017-03-11
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary com…
- CVE-2021-38003CRITICALCVSS 8.8EG 9.0⚠ KEV2021-11-23
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2018-0155CRITICALCVSS 8.6EG 9.0⚠ KEV2018-03-28
A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the…
- CVE-2024-29748CRITICALCVSS 7.8EG 9.0⚠ KEV2024-04-05
there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
- CVE-2021-1906CRITICALCVSS 6.2EG 9.0⚠ KEV2021-05-07
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, …
- CVE-2022-22265CRITICALCVSS 5.0EG 9.0⚠ KEV2022-01-10
An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.
- CVE-2025-34193CRITICALCVSS 9.8EG 9.82025-09-19
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to 25.1.1413 include Windows client components (PrinterInstallerClientInterface.exe, PrinterInstallerClient.exe, PrinterI…
- CVE-2025-10156CRITICALCVSS 9.8EG 9.82025-09-17
An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 picklescan allows a remote attacker to bypass security scans. This is achieved by crafting a ZIP archive containing a file wit…
- CVE-2021-42142CRITICALCVSS 9.8EG 9.82024-01-23
An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers mishandle the early use of a large epoch number. This vulnerability allows remote attackers to cause a denial of service and false-positive packet d…
- CVE-2021-42141CRITICALCVSS 9.8EG 9.82024-01-22
An issue was discovered in Contiki-NG tinyDTLS through 2018-08-30. One incorrect handshake could complete with different epoch numbers in the packets Client_Hello, Client_key_exchange, and Change_cipher_spec, which may cause denial of serv…
- CVE-2023-38406CRITICALCVSS 9.8EG 9.82023-11-06
bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."
- CVE-2022-23121CRITICALCVSS 9.8EG 9.82023-03-28
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parse_entries function. The issue…
- CVE-2021-4105CRITICALCVSS 9.8EG 9.82023-02-24
Improper Handling of Parameters vulnerability in BG-TEK COSLAT Firewall allows Remote Code Inclusion. This issue affects COSLAT Firewall: from 5.24.0.R.20180630 before 5.24.0.R.20210727.
- CVE-2022-48329CRITICALCVSS 9.8EG 9.82023-02-20
MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.
- CVE-2022-48328CRITICALCVSS 9.8EG 9.82023-02-20
app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.
- CVE-2022-31799CRITICALCVSS 9.8EG 9.82022-06-02
Bottle before 0.12.20 mishandles errors during early request binding.
- CVE-2021-40391CRITICALCVSS 9.8EG 9.82021-11-19
An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd), and the forked version of Gerbv (commit 71493260). A specially-crafted drill file can lead to code exec…
- CVE-2021-43272CRITICALCVSS 9.8EG 9.82021-11-14
An improper handling of exceptional conditions vulnerability exists in Open Design Alliance ODA Viewer sample before 2022.11. ODA Viewer continues to process invalid or malicious DWF files instead of stopping upon an exception. An attacker…
- CVE-2021-38384CRITICALCVSS 9.8EG 9.82021-08-10
Serverless Offline 8.0.0 returns a 403 HTTP status code for a route that has a trailing / character, which might cause a developer to implement incorrect access control, because the actual behavior within the Amazon AWS environment is a 20…
- CVE-2021-36128CRITICALCVSS 9.8EG 9.82021-07-02
An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. Autoblocks for CentralAuth-issued suppression blocks are not properly implemented.
- CVE-2020-13859CRITICALCVSS 9.8EG 9.82021-02-01
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - OpenWrt Configuration Interface framework, allows the undocumented system account mofidev to …
- CVE-2020-24753CRITICALCVSS 9.8EG 9.82020-09-17
A memory corruption vulnerability in Objective Open CBOR Run-time (oocborrt) in versions before 2020-08-12 could allow an attacker to execute code via crafted Concise Binary Object Representation (CBOR) input to the cbor2json decoder. An u…
- CVE-2009-5043CRITICALCVSS 9.8EG 9.82019-10-31
burn allows file names to escape via mishandled quotation marks
- CVE-2019-17195CRITICALCVSS 9.8EG 9.82019-10-15
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
- CVE-2019-14431CRITICALCVSS 9.8EG 9.82019-07-29
In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of up to 256 bytes and possible Remote Code Execution in parseSSLHandshake in sslDecode.c. During proc…
- CVE-2019-12815CRITICALCVSS 9.8EG 9.82019-07-19
An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.
- CVE-2019-6256CRITICALCVSS 9.8EG 9.82019-01-14
A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer crash in handleHTTPCmd_TunnelingPOST, when RTSP-over-HTTP tunneling is supported, via x-sess…
- CVE-2018-19991CRITICALCVSS 9.8EG 9.82018-12-10
VeryNginx 0.3.3 allows remote attackers to bypass the Web Application Firewall feature because there is no error handler (for get_uri_args or get_post_args) to block the API misuse described in CVE-2018-9230.
- CVE-2017-2877CRITICALCVSS 9.8EG 9.82018-09-19
A missing error check exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. A specially crafted request on port 10001 could allow an attacker to reset the user accounts to facto…
- CVE-2024-7521CRITICALCVSS 8.8EG 9.82024-08-06
Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
- CVE-2021-20588CRITICALCVSS 7.5EG 9.82021-02-19
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer ver…
- CVE-2026-53459CRITICALCVSS 9.3EG 9.32026-09-15
Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Starting in version 0.1.6 and prior to version 0.2.4.4, a fail-open in the authentication code allows any attacker to bypass authentication by floodin…
- CVE-2020-11012CRITICALCVSS 9.3EG 9.32020-04-23
MinIO versions before RELEASE.2020-04-23T00-58-49Z have an authentication bypass issue in the MinIO admin API. Given an admin access key, it is possible to perform admin API operations i.e. creating new service accounts for existing access…
- CVE-2026-27809CRITICALCVSS 9.1EG 9.12026-02-26
psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file contains malformed RLE-compressed image data (e.g. a literal run that extends past the expected row size), decode_rle() rais…
- CVE-2026-27586CRITICALCVSS 9.1EG 9.12026-02-24
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` cause mTLS client certificate authentication to silently fail open when a CA certificate f…
- CVE-2021-23859CRITICALCVSS 9.1EG 9.12021-12-08
An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM installation this crash also opens the possibility to send further unauthenticated commands to…
- CVE-2019-14287HIGHCVSS 8.8EG 8.92019-10-17
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows b…
- CVE-2026-40371HIGHCVSS 8.8EG 8.82026-06-09
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.
- CVE-2024-3150HIGHCVSS 8.8EG 8.82024-06-06
In mintplex-labs/anything-llm, a vulnerability exists in the thread update process that allows users with Default or Manager roles to escalate their privileges to Administrator. The issue arises from improper input validation when handling…
- CVE-2024-3152HIGHCVSS 8.8EG 8.82024-06-06
mintplex-labs/anything-llm is vulnerable to multiple security issues due to improper input validation in several endpoints. An attacker can exploit these vulnerabilities to escalate privileges from a default user role to an admin role, rea…
- CVE-2023-6866HIGHCVSS 8.8EG 8.82023-12-19
TypedArrays can be fallible and lacked proper exception handling. This could lead to abuse in other APIs which expect TypedArrays to always succeed. This vulnerability affects Firefox < 121.
- CVE-2022-22150HIGHCVSS 8.8EG 8.82022-02-04
A memory corruption vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.1.0.52543. A specially-crafted PDF document can trigger an exception which is improperly handled, leaving the engine in an inval…
- CVE-2021-1578HIGHCVSS 8.8EG 8.82021-08-25
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker to elevate privileges t…
- CVE-2021-33477HIGHCVSS 8.8EG 8.82021-05-20
rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A response is terminated by a newline.
- CVE-2020-7468HIGHCVSS 8.8EG 8.82021-03-26
In FreeBSD 12.2-STABLE before r365772, 11.4-STABLE before r365773, 12.1-RELEASE before p10, 11.4-RELEASE before p4 and 11.3-RELEASE before p14 a ftpd(8) bug in the implementation of the file system sandbox, combined with capabilities avail…
- CVE-2020-16005HIGHCVSS 8.8EG 8.82020-11-03
Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2019-5031HIGHCVSS 8.8EG 8.82019-10-02
An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, version 9.4.1.16828. A specially crafted PDF document can trigger an out-of-memory condition which isn't handled properly,…
- CVE-2019-14378HIGHCVSS 8.8EG 8.82019-07-29
ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.
- CVE-2019-5051HIGHCVSS 8.8EG 8.82019-07-03
An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and potential code execution. An attacker can provide a specially cr…
Map vulnerabilities like CWE-755 to your infrastructure
EchelonGraph correlates every CVE — across CWE-755 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →