CWE-130: CWE-130

24
Total CVEs
0
Critical
15
High
6.8
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
1
2025
8
2024
7
2023
2
2022
3

Top Affected Vendors

1 Djangoproject 2
2 Microsoft 2
3 Juniper 2
4 Indutny 1
5 Objectcomputing 1
6 Yokogawa 1
7 Tweedegolf 1
8 Mitsubishi 1
9 Apache 1
10 Netapp 1

All CWE-130 CVEs (24)

CVE-2024-37989
8.0

This Secure Boot vulnerability allows attackers to bypass security features and execute unauthorized code during the boot process. It affects systems ...

Jul 9, 2024
CVE-2024-38011
8.0

CVE-2024-38011 is a Secure Boot security feature bypass vulnerability that allows attackers to circumvent Secure Boot protections on affected systems....

Jul 9, 2024
CVE-2025-10458
7.6

This CVE describes a parameter validation vulnerability in Zephyr RTOS where untrusted input is not properly sanitized before being used in internal o...

Sep 19, 2025
CVE-2025-14847
KEV EPSS 57.7% 7.5

This vulnerability allows unauthenticated clients to read uninitialized heap memory from MongoDB servers by exploiting mismatched length fields in Zli...

Dec 19, 2025
CVE-2024-38875
7.5

This vulnerability in Django's urlize and urlizetrunc template filters allows attackers to cause denial of service by providing inputs with excessive ...

Jul 10, 2024
CVE-2024-39614
7.5

This vulnerability in Django's get_supported_language_variant() function allows attackers to cause denial-of-service by sending very long strings with...

Jul 10, 2024
CVE-2023-33192
7.5

CVE-2023-33192 is a denial-of-service vulnerability in ntpd-rs where improper validation of NTS cookie length allows attackers to crash the server wit...

May 27, 2023
CVE-2023-28964
7.5

This vulnerability allows an unauthenticated attacker to crash the routing protocol daemon (RPD) on Juniper devices by sending a malformed BGP flowspe...

Apr 17, 2023
CVE-2022-0677
7.5

This vulnerability allows an attacker to cause a Denial-of-Service (DoS) in Bitdefender's Update Server and GravityZone components by exploiting impro...

Apr 7, 2022
CVE-2021-43666
7.5

This vulnerability in mbed TLS allows attackers to cause a Denial of Service by providing an empty password to the mbedtls_pkcs12_derivation function....

Mar 24, 2022
CVE-2021-20610
7.5

This vulnerability in Mitsubishi Electric PLCs allows remote unauthenticated attackers to send specially crafted packets that cause a denial-of-servic...

Dec 1, 2021
CVE-2021-35517
7.5

CVE-2021-35517 is a denial-of-service vulnerability in Apache Commons Compress where specially crafted TAR archives can trigger excessive memory alloc...

Jul 13, 2021
CVE-2023-5393
7.4

This vulnerability allows remote attackers to cause a stack overflow by sending a malformed message to a Honeywell server, potentially leading to remo...

Apr 11, 2024
CVE-2024-35313
7.3

This vulnerability in Tor Arti allows circuits to incorrectly have a length of 3 when full vanguards are enabled, potentially reducing anonymity prote...

May 17, 2024
CVE-2021-38445
7.0

This vulnerability in OpenDDS allows remote attackers to execute arbitrary code by sending specially crafted data packets that exploit inconsistent le...

May 5, 2022
CVE-2025-8531
6.8

A remote attacker can send specially crafted packets to cause an integer underflow in Mitsubishi Electric MELSEC-Q Series PLCs, stopping Ethernet comm...

Sep 19, 2025
CVE-2025-48022
6.5

A vulnerability in Yokogawa's Vnet/IP Interface Package allows attackers to crash the Vnet/IP software stack by sending maliciously crafted packets. T...

Feb 13, 2026
CVE-2025-52949
6.5

A vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a logically adjacent BGP peer to crash the routing protocol daemon (rpd) by s...

Jul 11, 2025
CVE-2020-16224
6.5

This vulnerability in Philips Patient Information Center iX (PICiX) allows attackers to cause denial of service by sending specially crafted messages ...

Sep 11, 2020
CVE-2025-5514
5.3

A remote unauthenticated attacker can send specially crafted HTTP requests to exploit an improper length parameter handling vulnerability in Mitsubish...

Aug 25, 2025
CVE-2023-53157
5.3

The rosenpass crate for Rust versions before 0.2.1 contains a vulnerability where processing a specially crafted one-byte UDP packet causes a panic, l...

Jul 28, 2025
CVE-2024-42460
5.3

This vulnerability in the Elliptic package for Node.js allows attackers to create multiple valid signatures for the same message due to missing valida...

Aug 2, 2024
CVE-2025-54646
5.1

This CVE describes an inadequate packet length check vulnerability in BLE (Bluetooth Low Energy) modules. Attackers could send specially crafted packe...

Aug 6, 2025
CVE-2025-53604
4.0

The web-push crate for Rust before version 0.10.3 is vulnerable to denial of service through memory exhaustion. Attackers can send HTTP requests with ...

Jul 5, 2025

About CWE-130 (CWE-130)

Our database tracks 24 CVEs classified as CWE-130, with 0 rated critical and 15 rated high severity. The average CVSS score for CWE-130 vulnerabilities is 6.8.

External reference: View CWE-130 on MITRE CWE →

Monitor CWE-130 Vulnerabilities

Get alerted when new CWE-130 CVEs affect your infrastructure.

Start Monitoring Free