CWE-755— Improper Handling of Exceptional Conditions
The product does not handle or incorrectly handles an exceptional condition.— MITRE CWE catalog
634 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-755page 7 of 13
- CVE-2017-3832HIGHCVSS 7.5EG 7.52017-04-06
A vulnerability in the web management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to…
- CVE-2024-47491HIGHCVSS 5.9EG 7.52024-10-11
An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause Denial of Service (DoS). When a …
- CVE-2022-20726HIGHCVSS 5.5EG 7.52022-04-15
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying …
- CVE-2006-5170HIGHCVSS v2 7.5EG 7.52006-10-10
pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which…
- CVE-2023-4537HIGHCVSS 7.4EG 7.42024-02-15
Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affects ERP XL: from 2020.2.2 throug…
- CVE-2022-0016HIGHCVSS 7.4EG 7.42022-02-10
An improper handling of exceptional conditions vulnerability exists within the Connect Before Logon feature of the Palo Alto Networks GlobalProtect app that enables a local attacker to escalate to SYSTEM or root privileges when authenticat…
- CVE-2021-32066HIGHCVSS 7.4EG 7.42021-08-01
An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exception when StartTLS fails with an an unknown response, which might allow man-in-the-middle attackers to bypass the T…
- CVE-2021-0259HIGHCVSS 7.4EG 7.42021-04-22
Due to a vulnerability in DDoS protection in Juniper Networks Junos OS and Junos OS Evolved on QFX5K Series switches in a VXLAN configuration, instability might be experienced in the underlay network as a consequence of exceeding the defau…
- CVE-2021-0241HIGHCVSS 7.4EG 7.42021-04-22
On Juniper Networks Junos OS platforms configured as DHCPv6 local server or DHCPv6 Relay Agent, Juniper Networks Dynamic Host Configuration Protocol Daemon (JDHCPD) process might crash with a core dump if a specific DHCPv6 packet is receiv…
- CVE-2021-0240HIGHCVSS 7.4EG 7.42021-04-22
On Juniper Networks Junos OS platforms configured as DHCPv6 local server or DHCPv6 Relay Agent, the Juniper Networks Dynamic Host Configuration Protocol Daemon (JDHCPD) process might crash if a malformed DHCPv6 packet is received, resultin…
- CVE-2020-5665HIGHCVSS 7.4EG 7.42020-12-14
Improper check or handling of exceptional conditions in MELSEC iQ-F series FX5U(C) CPU unit firmware version 1.060 and earlier allows an attacker to cause a denial-of-service (DoS) condition on program execution and communication by sendin…
- CVE-2026-48961HIGHCVSS 7.3EG 7.32026-05-27
IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID. When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extr…
- CVE-2025-29826HIGHCVSS 7.3EG 7.32025-05-13
Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
- CVE-2023-22292HIGHCVSS 7.3EG 7.32023-11-14
Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2017-17172HIGHCVSS 7.3EG 7.32018-06-14
Huawei smart phones LYO-L21 with software LYO-L21C479B107, LYO-L21C479B107 have a privilege escalation vulnerability. An authenticated, local attacker can crafts malformed packets after tricking a user to install a malicious application an…
- CVE-2021-25380HIGHCVSS 5.8EG 7.32021-04-09
Improper handling of exceptional conditions in Bixby prior to version 3.0.53.02 allows attacker to execute the actions registered by the user.
- CVE-2026-28542HIGHCVSS 5.5EG 7.32026-03-05
Permission bypass vulnerability in the system service framework. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2020-1676HIGHCVSS 7.2EG 7.22020-10-16
When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle SAML responses, allowing a remote attacker to modify a valid SAML response without invalidating its cryptographic signature to bypass SAML authent…
- CVE-2025-24478HIGHCVSS 7.1EG 7.12025-01-28
A denial-of-service vulnerability exists in the affected products. The vulnerability could allow a remote, non-privileged user to send malicious requests resulting in a major nonrecoverable fault causing a denial-of-service.
- CVE-2022-27167HIGHCVSS 7.1EG 7.12022-05-10
Privilege escalation vulnerability in Windows products of ESET, spol. s r.o. allows attacker to exploit "Repair" and "Uninstall" features what may lead to arbitrary file deletion. This issue affects: ESET, spol. s r.o. ESET NOD32 Antivirus…
- CVE-2021-30283HIGHCVSS 7.1EG 7.12022-01-03
Possible denial of service due to improper handling of debug register trap from user applications in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
- CVE-2021-1894HIGHCVSS 7.1EG 7.12022-01-03
Improper access control in TrustZone due to improper error handling while handling the signing key in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Musi…
- CVE-2017-11472HIGHCVSS 7.1EG 7.12017-07-20
The acpi_ns_terminate() function in drivers/acpi/acpica/nsutils.c in the Linux kernel before 4.12 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory …
- CVE-2017-7496HIGHCVSS 7.0EG 7.02017-06-26
fedora-arm-installer up to and including 1.99.16 is vulnerable to local privilege escalation due to lack of checking the error condition of mount operation failure on unsafely created temporary directories.
- CVE-2017-0622HIGHCVSS 7.0EG 7.02017-05-12
An elevation of privilege vulnerability in the Goodix touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromis…
- CVE-2026-59952MEDIUMCVSS 6.9EG 6.92026-07-24
Valibot helps validate data using a schema. Versions prior to 1.4.2 can throw a TypeError inside its flatten() helper when validation issues contain attacker-controlled object keys such as toString, valueOf, or hasOwnProperty. The issue is…
- CVE-2026-23762MEDIUMCVSS 6.9EG 6.92026-01-22
VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and earlier, respectively), as well as VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlie…
- CVE-2024-41886MEDIUMCVSS 6.9EG 6.92024-12-24
Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker could inject malformed data into url input parameters to reboot the NVR. The manufacturer has released patch firmware fo…
- CVE-2024-47609MEDIUMCVSS 6.9EG 6.92024-10-01
Tonic is a native gRPC client & server implementation with async/await support. When using tonic::transport::Server there is a remote DoS attack that can cause the server to exit cleanly on accepting a TCP/TLS stream. This can be triggered…
- CVE-2023-28842MEDIUMCVSS 6.8EG 6.82023-04-04
Moby) is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as mo…
- CVE-2023-28841MEDIUMCVSS 6.8EG 6.82023-04-04
Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as mob…
- CVE-2020-1071MEDIUMCVSS 6.8EG 6.82020-05-21
An elevation of privilege vulnerability exists when Windows improperly handles errors tied to Remote Access Common Dialog. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To explo…
- CVE-2019-15894MEDIUMCVSS 6.8EG 6.82019-10-07
An issue was discovered in Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.6, 3.2.x through 3.2.3, and 3.3.x through 3.3.1. An attacker who uses fault injection to physically disrupt the ESP32 CPU can bypass the Secure Boot d…
- CVE-2017-6628MEDIUMCVSS 6.8EG 6.82017-05-03
A vulnerability in SMART-SSL Accelerator functionality for Cisco Wide Area Application Services (WAAS) 6.2.1, 6.2.1a, and 6.2.3a could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition where the WAN opt…
- CVE-2024-34638MEDIUMCVSS 6.7EG 6.72024-09-04
Improper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1 allows local attackers to delete non-preloaded applications.
- CVE-2022-32655MEDIUMCVSS 6.7EG 6.72023-02-06
In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: G…
- CVE-2022-32659MEDIUMCVSS 6.7EG 6.72023-01-03
In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: G…
- CVE-2022-32658MEDIUMCVSS 6.7EG 6.72023-01-03
In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: G…
- CVE-2022-32657MEDIUMCVSS 6.7EG 6.72023-01-03
In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: G…
- CVE-2022-32590MEDIUMCVSS 6.7EG 6.72022-10-07
In wlan, there is a possible use after free due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07299425…
- CVE-2021-0679MEDIUMCVSS 6.7EG 6.72021-12-17
In apusys, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS056721…
- CVE-2021-0668MEDIUMCVSS 6.7EG 6.72021-11-18
In apusys, there is a possible memory corruption due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0567…
- CVE-2021-34716MEDIUMCVSS 6.7EG 6.72021-08-18
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating sy…
- CVE-2026-45819MEDIUMCVSS 6.6EG 6.62026-08-13
baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.
- CVE-2023-42509MEDIUMCVSS 6.6EG 6.62024-03-07
JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data.
- CVE-2026-105757MEDIUMCVSS 6.5EG 6.52026-10-05
vLLM is an inference and serving engine for large language models. Prior to 0.30.0, structured-output request failures can escape request-scoped validation and reach the EngineCore fatal-error path. A per-request backend mismatch can re-ra…
- CVE-2026-101017MEDIUMCVSS 6.5EG 6.52026-09-28
A vulnerability was found in Trusted Domain Project OpenDMARC up to 1.4.2. This vulnerability affects the function strcasecmp in the library libopendmarc/opendmarc_policy.c. The manipulation results in handling of exceptional conditions. T…
- CVE-2026-101016MEDIUMCVSS 6.5EG 6.52026-09-28
A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_policy_parse_dmarc in the library libopendmarc/opendmarc_policy.c. The manipulation of the argument fo/rf/ri/pct/sp/adkim/a…
- CVE-2026-54775MEDIUMCVSS 6.5EG 6.52026-06-19
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service listening on a Kafka topic stops processing new records from that topic when KafkaTransportPump recei…
- CVE-2026-25957MEDIUMCVSS 6.5EG 6.52026-02-09
Cube is a semantic layer for building data applications. From 1.1.17 to before 1.5.13 and 1.4.2, it is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint. This vulnerability is…
Map vulnerabilities like CWE-755 to your infrastructure
EchelonGraph correlates every CVE — across CWE-755 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →