CWE-248: CWE-248

62
Total CVEs
2
Critical
37
High
6.8
Avg CVSS

Yearly Trend

2026
5
2025
33
2024
13
2023
8
2022
3

Top Affected Vendors

1 Cisco 6
2 Huawei 5
3 Intel 3
4 Mediatek 2
5 Ibm 2
6 Librechat 2
7 Svelte 1
8 Rustls Project 1
9 Debian 1
10 Grpc 1

All CWE-248 CVEs (62)

CVE-2026-20031
5.3

A vulnerability in ClamAV's HTML CSS parser allows remote attackers to cause denial of service by submitting specially crafted HTML files. This affect...

Mar 4, 2026
CVE-2025-35436
5.3

CVE-2025-35436 is an uncaught exception vulnerability in CISA Thorium's account verification email handling. An unauthenticated remote attacker can ca...

Sep 17, 2025
CVE-2024-56946
5.3

This vulnerability in Technitium DNS Server allows remote attackers to cause a denial of service by sending specially crafted DNS-over-QUIC requests t...

Feb 3, 2025
CVE-2024-11738
5.3

A vulnerability in Rustls 0.23.13 and related APIs allows denial of service through a panic when processing fragmented TLS ClientHello messages. This ...

Dec 6, 2024
CVE-2024-51750
5.0

A malicious Matrix homeserver can send specially crafted invalid messages over federation that cause Element Web and Desktop clients to fail rendering...

Nov 12, 2024
CVE-2025-66305
4.9

A Denial of Service vulnerability in Grav's admin panel allows attackers to crash the entire web application by submitting malformed input to the Lang...

Dec 1, 2025
CVE-2025-8870
4.9

This vulnerability in Arista EOS allows an attacker to cause a denial of service by triggering an unexpected device reload through specific serial con...

Nov 14, 2025
CVE-2025-0648
4.9

A configuration change vulnerability in M-Files Server's database driver allows highly privileged attackers to cause unexpected server crashes, leadin...

Jan 23, 2025
CVE-2024-13417
4.6

This vulnerability allows attackers to send specially crafted payloads to 2N RFID readers, causing a denial-of-service condition that requires a devic...

Feb 6, 2025
CVE-2025-13064
4.5

This CVE describes a server-side injection vulnerability where a malicious administrator with a tampered client can inject and execute malicious scrip...

Feb 10, 2026
CVE-2025-54777
4.3

An uncaught exception vulnerability in Konica Minolta bizhub multifunction printers allows denial-of-service attacks via malformed S/MIME email certif...

Aug 29, 2025
CVE-2025-20097
4.3

An uncaught exception vulnerability in OpenBMC firmware for specific Intel server families allows authenticated users to potentially cause denial of s...

Feb 12, 2025

About CWE-248 (CWE-248)

Our database tracks 62 CVEs classified as CWE-248, with 2 rated critical and 37 rated high severity. The average CVSS score for CWE-248 vulnerabilities is 6.8.

External reference: View CWE-248 on MITRE CWE →

Monitor CWE-248 Vulnerabilities

Get alerted when new CWE-248 CVEs affect your infrastructure.

Start Monitoring Free