CWE-703: CWE-703

39
Total CVEs
7
Critical
18
High
7.3
Avg CVSS

Yearly Trend

2026
4
2025
15
2024
10
2023
7
2022
1

Top Affected Vendors

1 Mozilla 5
2 Google 3
3 Apple 3
4 Zephyrproject 2
5 Bosch 2
6 Juniper 2
7 Linuxfoundation 2
8 Rdkcentral 1
9 Kubevirt 1
10 Fortinet 1

All CWE-703 CVEs (39)

CVE-2025-13021
9.8

A critical vulnerability in Firefox and Thunderbird's WebGPU component allows memory corruption due to incorrect boundary conditions. Attackers can ex...

Nov 11, 2025
CVE-2025-13022
9.8

A critical vulnerability in Firefox and Thunderbird's WebGPU component allows memory corruption due to incorrect boundary conditions. Attackers can ex...

Nov 11, 2025
CVE-2025-13023
9.8

A sandbox escape vulnerability in Firefox and Thunderbird's WebGPU component allows attackers to execute arbitrary code outside browser sandbox restri...

Nov 11, 2025
CVE-2025-13026
9.8

This CVE describes a sandbox escape vulnerability in Firefox and Thunderbird's WebGPU component due to incorrect boundary conditions. Attackers can ex...

Nov 11, 2025
CVE-2021-3329
9.6

CVE-2021-3329 is a critical vulnerability in the Zephyr RTOS Bluetooth HCI Host stack initialization that lacks proper input validation, allowing atta...

Feb 26, 2023
CVE-2023-45927
9.1

CVE-2023-45927 is an arithmetic exception vulnerability in S-Lang 2.3.2's tt_sprintf() function that can lead to denial of service or potentially arbi...

Mar 27, 2024
CVE-2021-23859
9.1

An unauthenticated attacker can send a special HTTP request to crash the service, potentially enabling further unauthenticated commands on standalone ...

Dec 8, 2021
CVE-2024-21525
8.3

CVE-2024-21525 is a buffer overflow vulnerability in the node-twain package where input validation fails to check string length for productName, produ...

Jul 10, 2024
CVE-2024-10781
8.1

The CleanTalk WordPress plugin has a vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins. This can lead to r...

Nov 26, 2024
CVE-2025-70758
7.5

This CVE describes an authentication bypass vulnerability in chetans9 core-php-admin-panel where the authentication validation script sends a redirect...

Feb 3, 2026
CVE-2025-14874
7.5

A denial-of-service vulnerability in Nodemailer allows attackers to crash email-sending applications by sending specially crafted email addresses that...

Dec 18, 2025
CVE-2025-13016
7.5

This vulnerability involves incorrect boundary conditions in the WebAssembly component of Firefox and Thunderbird, potentially allowing memory corrupt...

Nov 11, 2025
CVE-2025-61602
7.5

This vulnerability allows any authenticated user in a BigBlueButton virtual classroom meeting to crash the chat functionality for all participants by ...

Oct 9, 2025
CVE-2025-59531
7.5

Argo CD versions 1.2.0 through 3.2.0-rc1 contain a vulnerability where unauthenticated API requests with malformed Bitbucket Server payloads can crash...

Oct 1, 2025
CVE-2024-47215
7.5

This vulnerability in Snowbridge setups sending data to Google Tag Manager Server Side allows attackers to attach invalid GTM SS preview headers to ev...

Apr 3, 2025
CVE-2024-50954
7.5

A vulnerability in XINJE XL5E-16T and XD5E-24R-E programmable logic controllers allows attackers to crash the PLC by sending specific Modbus messages ...

Jan 15, 2025
CVE-2024-20089
7.5

This vulnerability in MediaTek Wi-Fi drivers allows remote attackers to cause denial of service without authentication or user interaction. It affects...

Sep 2, 2024
CVE-2024-29205
7.5

This vulnerability allows remote unauthenticated attackers to send specially crafted requests to Ivanti Connect Secure and Ivanti Policy Secure gatewa...

Apr 25, 2024
CVE-2023-34348
7.5

This vulnerability allows unauthenticated attackers to remotely crash the PI Message Subsystem in AVEVA PI Server, causing denial-of-service. It affec...

Jan 18, 2024
CVE-2023-32230
7.5

An unauthenticated attacker can send a malformed API request to Bosch BT software products, causing a Denial of Service (DoS) by crashing or disruptin...

Dec 18, 2023
CVE-2023-49786
7.5

A race condition in Asterisk's DTLS-SRTP handshake allows attackers to cause denial of service by preventing new encrypted calls from being establishe...

Dec 14, 2023
CVE-2023-36831
7.5

A memory leak vulnerability in Juniper SRX Series firewalls with SSL Proxy and UTM Web-Filtering enabled causes gradual memory exhaustion when accessi...

Jul 14, 2023
CVE-2022-0016
7.4

A local privilege escalation vulnerability in Palo Alto Networks GlobalProtect app's Connect Before Logon feature allows attackers to gain SYSTEM or r...

Feb 10, 2022
CVE-2021-0240
7.4

A vulnerability in Juniper Networks Junos OS DHCPv6 service allows remote attackers to cause a denial of service by sending malformed DHCPv6 packets. ...

Apr 22, 2021
CVE-2023-5563
7.1

This vulnerability in the Zephyr RTOS SJA1000 CAN controller driver causes a fatal exception when attempting automatic bus-off recovery in interrupt c...

Oct 13, 2023
CVE-2025-68135
6.5

This vulnerability in EVerest EV charging software allows unhandled C++ exceptions in the TbdController loop to cause silent termination of the contro...

Jan 21, 2026
CVE-2025-12890
6.5

This vulnerability allows attackers to crash Bluetooth Low Energy (BLE) peripherals by sending malformed connection requests with illegal parameters. ...

Nov 7, 2025
CVE-2025-24188
6.5

This CVE describes a logic flaw in Safari that could be exploited by malicious web content to cause unexpected crashes. The vulnerability affects Safa...

Jul 30, 2025
CVE-2025-43240
6.2

This CVE describes a logic flaw in macOS and Safari where a download's origin may be incorrectly associated, potentially allowing malicious downloads ...

Jul 30, 2025
CVE-2024-9104
5.6

This vulnerability allows unauthenticated attackers to reset passwords for subscriber accounts in WordPress UltimateAI plugin. Attackers can take over...

Oct 16, 2024
CVE-2023-21026
5.5

This Android vulnerability allows an attacker to set a touchable region beyond its own SurfaceControl due to a logic error in WindowManagerService. Th...

Mar 24, 2023
CVE-2023-21036
5.5

This vulnerability in Android's BitmapExport.java allows attackers to bypass image truncation, potentially causing memory corruption or denial of serv...

Mar 24, 2023
CVE-2025-64435
5.3

This vulnerability in KubeVirt allows attackers to disrupt virtual machine control by creating malicious pods with matching labels. Attackers can caus...

Nov 7, 2025
CVE-2025-11594
5.3

This vulnerability in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore Website allows remote attackers to manipulate quantity values in t...

Oct 11, 2025
CVE-2024-31883
5.3

IBM Security Verify Access versions 10.0.0.0 through 10.0.7.1, under certain configurations, are vulnerable to asymmetric resource consumption denial-...

Jun 27, 2024
CVE-2024-26007
5.3

An unauthenticated attacker can send crafted HTTP requests to the FortiOS administrative interface, causing a denial of service (DoS) that disrupts ma...

May 14, 2024
CVE-2024-37992
4.9

This vulnerability affects multiple Siemens SIMATIC RFID reader models where improper SNMP error handling causes application restart when character li...

Sep 10, 2024
CVE-2026-20640
4.6

An attacker with physical access to an iPhone can take and view screenshots of sensitive data during iPhone Mirroring with a Mac. This vulnerability a...

Feb 11, 2026
CVE-2026-21895
N/A

The rsa crate versions before 0.9.10 panic when creating RSA private keys with a prime value of 1 instead of returning an error. This affects Rust app...

Jan 8, 2026

About CWE-703 (CWE-703)

Our database tracks 39 CVEs classified as CWE-703, with 7 rated critical and 18 rated high severity. The average CVSS score for CWE-703 vulnerabilities is 7.3.

External reference: View CWE-703 on MITRE CWE →

Monitor CWE-703 Vulnerabilities

Get alerted when new CWE-703 CVEs affect your infrastructure.

Start Monitoring Free