CWE-248: CWE-248

62
Total CVEs
2
Critical
37
High
6.8
Avg CVSS

Yearly Trend

2026
5
2025
33
2024
13
2023
8
2022
3

Top Affected Vendors

1 Cisco 6
2 Huawei 5
3 Intel 3
4 Mediatek 2
5 Ibm 2
6 Librechat 2
7 Svelte 1
8 Rustls Project 1
9 Debian 1
10 Grpc 1

All CWE-248 CVEs (62)

CVE-2024-42037
9.3

This vulnerability involves uncaught exceptions in the Graphics module that could allow attackers to access sensitive information. It affects systems ...

Aug 8, 2024
CVE-2025-67647
9.1

SvelteKit versions 2.19.0 through 2.49.4 are vulnerable to server-side request forgery (SSRF) and denial of service (DoS) attacks. The vulnerability a...

Jan 15, 2026
CVE-2023-20086
8.6

An unauthenticated remote attacker can send crafted ICMPv6 messages to Cisco ASA or FTD devices with IPv6 enabled, causing the device to reload and cr...

Nov 1, 2023
CVE-2023-42447
8.6

CVE-2023-42447 is a denial-of-service vulnerability in blurhash-rs, a Rust library for encoding images into ASCII strings. Attackers can craft malicio...

Sep 19, 2023
CVE-2023-23774
8.4

Motorola EBTS/MBTS Site Controller devices expose a debug prompt on the serial port when encountering unhandled exceptions. This allows attackers with...

Aug 29, 2023
CVE-2025-20172
7.7

A vulnerability in Cisco IOS, IOS XE, and IOS XR Software allows authenticated remote attackers to cause denial of service by sending crafted SNMP req...

Feb 5, 2025
CVE-2025-20173
7.7

A vulnerability in Cisco IOS and IOS XE SNMP subsystems allows authenticated remote attackers to cause denial of service by sending crafted SNMP reque...

Feb 5, 2025
CVE-2025-20176
7.7

A vulnerability in Cisco IOS and IOS XE SNMP subsystems allows authenticated remote attackers to cause denial of service by sending crafted SNMP reque...

Feb 5, 2025
CVE-2025-20171
7.7

A vulnerability in Cisco IOS and IOS XE SNMP subsystems allows authenticated remote attackers to cause denial of service by sending crafted SNMP reque...

Feb 5, 2025
CVE-2023-0790
7.6

CVE-2023-0790 is an uncaught exception vulnerability in phpMyFAQ that can lead to denial of service or information disclosure. Attackers can trigger u...

Feb 12, 2023
CVE-2026-25577
7.5

This vulnerability in the Emmett framework allows unauthenticated attackers to send malformed Cookie headers that trigger unhandled CookieError except...

Feb 10, 2026
CVE-2025-59466
7.5

This vulnerability in Node.js causes applications to crash unrecoverably when deep recursion triggers 'Maximum call stack size exceeded' errors while ...

Jan 20, 2026
CVE-2025-12423
7.5

A protocol manipulation vulnerability in BLU-IC2 and BLU-IC4 devices allows attackers to cause denial of service by sending specially crafted network ...

Oct 28, 2025
CVE-2025-62370
7.5

This vulnerability in Alloy Core libraries allows attackers to cause denial-of-service (DoS) by sending malformed input to the eip712_signing_hash() f...

Oct 15, 2025
CVE-2025-59538
7.5

This vulnerability in Argo CD allows an unauthenticated attacker to crash the argocd-server process by sending a specially crafted Azure DevOps webhoo...

Oct 1, 2025
CVE-2025-55557
7.5

A vulnerability in PyTorch v2.7.0 causes a Name Error when models containing torch.cummin operations are compiled with Inductor, leading to Denial of ...

Sep 25, 2025
CVE-2025-23166
7.5

This vulnerability in Node.js allows remote attackers to crash the runtime by triggering an uncaught exception in the SignTraits::DeriveBits() cryptog...

May 19, 2025
CVE-2025-20663
7.5

This vulnerability in MediaTek wlan AP driver allows unauthenticated attackers within wireless range to potentially access sensitive information from ...

Apr 7, 2025
CVE-2024-58111
7.5

This vulnerability in the ArkUI framework's SVG parsing module allows attackers to cause denial of service by exploiting exception capture failures. I...

Apr 7, 2025
CVE-2025-3083
7.5

A vulnerability in MongoDB's mongos query router allows unauthenticated attackers to send specially crafted wire protocol messages that cause the serv...

Apr 1, 2025
CVE-2024-8249
7.5

This vulnerability allows unauthenticated attackers to crash the Anything-LLM server by sending malformed JSON payloads to the embeddable chat API end...

Mar 20, 2025
CVE-2024-11172
7.5

An unauthenticated denial-of-service vulnerability in librechat allows attackers to crash the server by sending a crafted payload. The vulnerability e...

Mar 20, 2025
CVE-2025-20637
7.5

This vulnerability in MediaTek network hardware allows remote attackers to cause a system hang (denial of service) without authentication or user inte...

Feb 3, 2025
CVE-2024-20137
7.5

This vulnerability in MediaTek wlan drivers allows remote attackers to cause denial of service by forcing client disconnections without authentication...

Dec 2, 2024
CVE-2023-5038
7.5

This vulnerability allows unauthenticated attackers to cause a denial-of-service condition on affected cameras by accessing a crafted URL. The attack ...

Jun 25, 2024
CVE-2024-34363
7.5

This vulnerability in Envoy proxy allows remote attackers to cause a denial-of-service (DoS) by sending incomplete UTF-8 strings that trigger an uncau...

Jun 4, 2024
CVE-2024-3051
7.5

This vulnerability allows attackers to send malformed Device Reset Locally command classes to temporarily deny service to end devices. When exploited,...

Apr 26, 2024
CVE-2023-3966
7.5

CVE-2023-3966 is a vulnerability in Open vSwitch where specially crafted Geneve packets can cause denial of service and invalid memory accesses when h...

Feb 22, 2024
CVE-2023-4785
7.5

This vulnerability in gRPC's TCP server on POSIX-compatible platforms allows attackers to cause denial of service by flooding the server with connecti...

Sep 13, 2023
CVE-2023-39948
7.5

This vulnerability in eprosima Fast DDS allows remote attackers to crash any Fast DDS process by triggering an uncaught BadParamException. It affects ...

Aug 11, 2023
CVE-2023-1691
7.5

This vulnerability involves improper exception handling in Huawei's communication framework, allowing attackers to trigger abnormal behavior in affect...

Jul 6, 2023
CVE-2021-41545
7.5

A vulnerability in Siemens Desigo building automation controllers allows attackers to send a specially crafted BACnet protocol packet that causes the ...

May 10, 2022
CVE-2022-24822
7.5

This vulnerability in Podium's @podium/layout and @podium/proxy modules allows attackers to cause denial of service by sending specially crafted HTTP ...

Apr 6, 2022
CVE-2022-20761
7.4

An unauthenticated attacker on the same network can send crafted traffic to Cisco CGR1K routers, causing the integrated wireless access point to stop ...

Apr 15, 2022
CVE-2023-22292
7.3

This vulnerability in Intel Unison software allows authenticated local users to trigger an uncaught exception that could lead to privilege escalation....

Nov 14, 2023
CVE-2021-33145
7.2

This vulnerability in Intel Ethernet Adapters and Controller I225 Manageability firmware allows a privileged user to trigger an uncaught exception, po...

Feb 23, 2024
CVE-2025-44019
7.1

AVEVA PI Data Archive products contain an uncaught exception vulnerability that allows authenticated users to crash critical subsystems, causing denia...

Jun 12, 2025
CVE-2025-24836
7.1

This vulnerability allows attackers to send continuous startMeasurement commands via unencrypted Bluetooth to affected medical devices, causing denial...

Feb 13, 2025
CVE-2024-54106
7.1

This CVE describes a null pointer dereference vulnerability in Huawei's image decoding module that can cause denial of service. Attackers can crash af...

Dec 12, 2024
CVE-2025-59462
6.5

This vulnerability allows an attacker to crash the UpdateService by tampering with the C++ CLI client during file transfers, disrupting update functio...

Oct 27, 2025
CVE-2025-48943
6.5

This CVE describes a Regular Expression Denial of Service (ReDoS) vulnerability in vLLM versions 0.8.0 through 0.9.0. Attackers can crash vLLM servers...

May 30, 2025
CVE-2024-11173
6.5

An unhandled exception vulnerability in LibreChat allows attackers to crash the server, causing denial of service. Attackers can exploit this by sendi...

Mar 20, 2025
CVE-2024-33848
6.5

An uncaught exception vulnerability in Intel RAID Web Console software allows authenticated local users to trigger a denial of service condition. This...

Sep 16, 2024
CVE-2024-31904
6.5

This vulnerability in IBM App Connect Enterprise allows authenticated users to trigger an uncaught exception, causing a denial of service (DoS) condit...

May 22, 2024
CVE-2025-48907
6.2

This CVE describes a deserialization vulnerability in the IPC module that could allow attackers to cause denial of service. The vulnerability affects ...

Jun 6, 2025
CVE-2024-20048
6.2

This vulnerability in MediaTek's flashc component allows local information disclosure due to an uncaught exception. Attackers with system execution pr...

Apr 1, 2024
CVE-2025-66578
6.0

CVE-2025-66578 is an authentication bypass vulnerability in xmlseclibs PHP library versions 3.1.3 and earlier. When processing invalid XML input durin...

Dec 9, 2025
CVE-2025-55194
5.7

In Part-DB versions before 1.17.3, any authenticated user can upload a profile picture with a misleading file extension (like .jpg.txt), causing a per...

Aug 13, 2025
CVE-2025-48430
5.5

An uncaught exception vulnerability in Gallagher Command Centre Server allows authorized privileged operators to crash the server intentionally. This ...

Oct 23, 2025
CVE-2025-0158
5.5

This vulnerability in IBM EntireX 11.1 allows a local user to cause a denial of service through an unhandled error condition. The issue stems from imp...

Feb 6, 2025

About CWE-248 (CWE-248)

Our database tracks 62 CVEs classified as CWE-248, with 2 rated critical and 37 rated high severity. The average CVSS score for CWE-248 vulnerabilities is 6.8.

External reference: View CWE-248 on MITRE CWE →

Monitor CWE-248 Vulnerabilities

Get alerted when new CWE-248 CVEs affect your infrastructure.

Start Monitoring Free