CVEs classified under CWE-248, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2018-11466 — CVSS 9.8 (critical): A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All…
CVE-2024-42037 — CVSS 9.3 (critical): Vulnerability of uncaught exceptions in the Graphics module Impact: Successful exploitation of this vulnerability may affect service…
CVE-2025-53620: @builder.io/qwik-city is the meta-framework for Qwik. When a Qwik Server Action QRL is executed it dynamically load the file containing the…
CVE-2026-61666: websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host…
CVE-2026-96277: Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings. This issue affects Apache…
CVE-2026-96294: Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift NodeJS bindings. This issue affects Apache…
CVE-2026-94646: Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes…
CVE-2026-94642: Uncaught exception vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to…
CVE-2026-85493: Uncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME bindings. This issue affects Apache Thrift: before 0.25.0. Users are…
CVE-2026-82410: Pocketbase is an open source web backend written in go. Prior to 0.22.48 and 0.39.7, PocketBase's panic-recovery middleware covers regular…
CVE-2026-63403: Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the server is vulnerable to an unauthenticated denial of…
CVE-2026-53530: RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, the public parser entrypoint…
CVE-2026-46689: Kanidm is an identity management platform. Prior to version 1.9.3, a single unauthenticated GET to any /scim/v1/... endpoint with a…
CVE-2026-9509: An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated remote attacker to…
CVE-2025-9124: A denial-of-service security issue in the affected product. The security issue stems from a fault occurring when a crafted CIP unconnected…
CVE-2025-53366: The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.9.4, a…
CVE-2025-53365: The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.10.0, if a…
CVE-2025-48997: Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and…
CVE-2025-43855: tRPC allows users to build & consume fully typesafe APIs without schemas or code generation. In versions starting from 11.0.0 to before…
CVE-2025-24883: go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash…
CVE-2026-92954 — CVSS 8.6 (high): vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3.11.7, Promises returned from the host…
CVE-2026-44001 — CVSS 8.6 (high): vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox escape vulnerability in vm2 v3.10.5 allows any sandboxed code to…
CVE-2024-43357 — CVSS 8.6 (high): ECMA-262 is the language specification for the scripting language ECMAScript. A problem in the ECMAScript (JavaScript) specification of…
CVE-2023-20086 — CVSS 8.6 (high): A vulnerability in ICMPv6 processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software…
CVE-2026-96286: Uncaught exception vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to…
CVE-2026-90440: Uncaught exception, improper handling of exceptional conditions, improper resource shutdown vulnerability in Apache Thrift D…
CVE-2026-94639: improper handling of exceptional conditions, Allocation of resources without limits or throttling, Uncaught exception vulnerability in…
CVE-2026-102984: Astro is a web framework for content-driven websites. Prior to 11.1.3, the @astrojs/node adapter builds a request URL from the Host header…
CVE-2026-61544: libp2p-rust is the official Rust language implementation of the libp2p networking stack. Prior to 0.13.1, libp2p-quic could panic during an…
CVE-2023-39945 — CVSS 8.2 (high): eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions…
CVE-2026-58859 — CVSS 7.8 (high): In multiple places, there is a possible denial of service due to an uncaught exception. This could lead to local escalation of privilege…
CVE-2025-20176 — CVSS 7.7 (high): A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to…
CVE-2025-20173 — CVSS 7.7 (high): A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to…
CVE-2025-20172 — CVSS 7.7 (high): A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an authenticated…
CVE-2025-20171 — CVSS 7.7 (high): A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to…
CVE-2026-102281 — CVSS 7.5 (high): Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0.2, a single message with a deeply…
CVE-2026-95842 — CVSS 7.5 (high): Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, SessionEventLoop.run catches only InterruptedException, and…
CVE-2026-62985 — CVSS 7.5 (high): request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Prior to 3.2.1…
CVE-2026-94622 — CVSS 7.5 (high): vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode…
CVE-2026-88411 — CVSS 7.5 (high): Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c) of FalkorDB (Redis module) v4.20.1 leads to a Denial of…
CVE-2026-32641 — CVSS 7.5 (high): Parseable is a log analytics platform built for high-volume data ingestion and analysis. Prior to 3.0.0, src/handlers/http/middleware.rs…
CVE-2026-65410 — CVSS 7.5 (high): The issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27…
CVE-2022-51009 — CVSS 7.5 (high): PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data…
CVE-2026-19534 — CVSS 7.5 (high): undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the…
CVE-2026-81517 — CVSS 7.5 (high): An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection…
CVE-2026-77078 — CVSS 7.5 (high): multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially crafted text field…
CVE-2026-55484 — CVSS 7.5 (high): ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.0-20260617230736-314…
CVE-2026-82254 — CVSS 7.5 (high): gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers…