CWE-754: CWE-754

127
Total CVEs
8
Critical
64
High
6.9
Avg CVSS

Yearly Trend

2026
18
2025
40
2024
40
2023
13
2022
7

Top Affected Vendors

1 Juniper 24
2 Linux 14
3 Mattermost 6
4 Huawei 5
5 Apple 4
6 Ibm 4
7 Openssl 3
8 Schneider Electric 3
9 Paloaltonetworks 2
10 Mediatek 2

All CWE-754 CVEs (127)

CVE-2023-35849
7.5

CVE-2023-35849 is an improper validation vulnerability in VirtualSquare picoTCP (PicoTCP-NG) where the library fails to properly check header sizes, p...

Jun 19, 2023
CVE-2023-25619
7.5

This vulnerability allows attackers to cause denial of service on Schneider Electric controllers by sending specially crafted Modbus TCP packets that ...

Apr 19, 2023
CVE-2023-28976
7.5

An unauthenticated network attacker can cause denial of service on Juniper MX Series routers by sending specific traffic that exceeds DDoS protection ...

Apr 17, 2023
CVE-2023-27772
7.5

CVE-2023-27772 is a segmentation fault vulnerability in libiec61850's ControlObjectClient_setOrigin() function that can cause denial of service or pot...

Apr 13, 2023
CVE-2022-23712
7.5

CVE-2022-23712 is a Denial of Service vulnerability in Elasticsearch where an unauthenticated attacker can send a specially crafted network request to...

Jun 6, 2022
CVE-2022-29369
7.5

CVE-2022-29369 is a segmentation fault vulnerability in Nginx NJS (JavaScript engine) that can cause denial of service or potentially allow arbitrary ...

May 12, 2022
CVE-2021-42020
7.5

This vulnerability in Siemens RUGGEDCOM industrial networking devices allows attackers to exploit a TFTP functionality flaw where file names lack prop...

Mar 8, 2022
CVE-2022-24321
7.5

A vulnerability in Geo SCADA servers allows denial of service attacks when processing malformed HTTP requests. This affects ClearSCADA and EcoStruxure...

Feb 9, 2022
CVE-2021-22816
7.5

This vulnerability allows remote attackers to cause a Denial of Service (DoS) on Schneider Electric SCADAPack RTUs by sending specially crafted Modbus...

Jan 28, 2022
CVE-2022-22180
7.5

This CVE describes an improper condition check vulnerability in Juniper EX Series devices that allows specially crafted IPv6 packets to exhaust Packet...

Jan 19, 2022
CVE-2021-31351
7.5

This vulnerability allows an attacker to cause a denial of service on Juniper MX Series routers by sending specially crafted packets that trigger a re...

Oct 19, 2021
CVE-2021-38599
7.5

WAL-G backup tool versions before 1.1 silently ignore encryption keys when using official binary releases, uploading backups in cleartext instead of e...

Aug 12, 2021
CVE-2021-22447
7.5

This vulnerability in Huawei smartphones allows attackers to trigger a system reset by exploiting improper exception handling. It affects Huawei smart...

Aug 2, 2021
CVE-2021-0282
7.5

This vulnerability allows an attacker to cause a denial of service on Juniper Junos OS devices by sending a specially crafted BGP UPDATE message. The ...

Jul 15, 2021
CVE-2021-26038
7.5

This vulnerability in Joomla! allows authenticated users with installer component access to install extensions without proper superuser authorization ...

Jul 7, 2021
CVE-2020-36382
7.5

CVE-2020-36382 is a denial-of-service vulnerability in OpenVPN Access Server where remote attackers can trigger an assertion failure during user authe...

Jun 4, 2021
CVE-2025-59960
7.4

A vulnerability in Juniper's DHCP service allows a DHCP client in one subnet to exhaust address pools in other subnets, causing Denial of Service on d...

Jan 15, 2026
CVE-2025-20625
7.4

An improper conditions check in Intel PROSet/Wireless WiFi Software for Windows allows unauthenticated attackers on adjacent networks to potentially c...

Aug 12, 2025
CVE-2024-10945
7.3

This local privilege escalation vulnerability allows attackers with low-privileged local access to replace files during software updates, gaining elev...

Nov 12, 2024
CVE-2025-24975
7.1

Firebird database servers with external connection pooling enabled (ExtConnPoolSize not set to 0) are vulnerable to a segmentation fault that can cras...

Aug 15, 2025
CVE-2024-35785
7.1

A kernel panic vulnerability in the Linux kernel's TEE (Trusted Execution Environment) OP-TEE driver allows local attackers to crash the system by tri...

May 17, 2024
CVE-2024-42162
7.0

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's gve driver when reading NIC statistics. The vulnerability occurs when the...

Jul 30, 2024
CVE-2025-20201
6.7

This vulnerability allows authenticated local attackers with privilege level 15 access on Cisco IOS XE devices to escalate privileges to root on the u...

May 7, 2025
CVE-2026-20419
6.5

This vulnerability in MediaTek wlan AP/STA firmware allows remote attackers within wireless range to cause denial of service by making the system unre...

Feb 2, 2026
CVE-2026-21910
6.5

An unauthenticated network-adjacent attacker can cause denial of service by flapping an interface in EVPN-VXLAN configurations on affected Juniper dev...

Jan 15, 2026
CVE-2025-4675
6.5

This CVE describes an improper check for unusual or exceptional conditions vulnerability in ABB WebPro SNMP Card PowerValue devices. Attackers could e...

Jan 7, 2026
CVE-2025-20761
6.5

This vulnerability in MediaTek modems allows remote denial of service attacks when a user equipment (UE) connects to a rogue base station controlled b...

Jan 6, 2026
CVE-2025-59958
6.5

An unauthenticated network attacker can send specially crafted packets to PTX Series routers running vulnerable Junos OS Evolved versions, causing res...

Oct 9, 2025
CVE-2025-10532
6.5

This vulnerability involves incorrect boundary conditions in Firefox and Thunderbird's JavaScript garbage collector (GC) component, which could allow ...

Sep 16, 2025
CVE-2024-52895
6.5

This vulnerability allows privileged users on IBM i 7.4 and 7.5 systems to bypass database capability restrictions, potentially deleting or modifying ...

Feb 14, 2025
CVE-2024-51470
6.5

This vulnerability in IBM MQ allows authenticated users to cause denial-of-service by sending messages with improperly set values. It affects multiple...

Dec 18, 2024
CVE-2024-39517
6.5

An unauthenticated adjacent attacker can cause denial of service by sending high volumes of specific Layer 2 packets in EVPN/VXLAN scenarios, causing ...

Jul 10, 2024
CVE-2025-3359
6.2

A segmentation fault vulnerability in GNUPlot's IO_str_init_static_internal function allows attackers to crash the application, potentially leading to...

Apr 7, 2025
CVE-2025-11925
6.1

This vulnerability allows HTML/JavaScript injection in API responses due to incorrect Content-Type headers. Attackers could potentially execute cross-...

Oct 17, 2025
CVE-2025-55035
6.1

This vulnerability in Mattermost Desktop App allows attackers to create a denial-of-service condition by tricking users into configuring a malicious s...

Oct 16, 2025
CVE-2024-42224
6.1

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's Marvell 88E6xxx Ethernet switch driver. The incorrect check for empt...

Jul 30, 2024
CVE-2025-54463
5.9

The Mattermost Confluence Plugin before version 1.5.0 contains an improper input validation vulnerability that allows attackers to crash the plugin by...

Aug 11, 2025
CVE-2025-53514
5.9

The Mattermost Confluence Plugin before version 1.5.0 contains an improper input validation vulnerability that allows attackers to crash the plugin by...

Aug 11, 2025
CVE-2024-39559
5.9

This vulnerability allows a network-based attacker to crash Juniper Junos OS Evolved devices by sending a specific TCP packet over an established TCP ...

Jul 10, 2024
CVE-2025-60011
5.8

An unauthenticated network attacker can send a specific BGP attribute to Juniper Junos devices, causing them to modify it incorrectly before forwardin...

Jan 15, 2026
CVE-2024-39561
5.8

This vulnerability allows attackers to bypass TCP packet filtering on Juniper SRX firewalls by sending TCP packets with SYN/FIN or SYN/RST flags when ...

Jul 10, 2024
CVE-2026-22795
5.5

This CVE describes a type confusion vulnerability in OpenSSL's PKCS#12 parsing code where an invalid or NULL pointer dereference occurs when processin...

Jan 27, 2026
CVE-2025-62875
5.5

An Improper Check for Unusual or Exceptional Conditions vulnerability in OpenSMTPD allows local users to crash the service through a denial-of-service...

Nov 20, 2025
CVE-2025-10937
5.5

This vulnerability in Oxford Nanopore's MinKNOW software allows local users to cause a denial-of-service by locking a temporary authentication token f...

Oct 23, 2025
CVE-2025-30655
5.5

A local privilege escalation vulnerability in Juniper Junos OS and Junos OS Evolved allows low-privileged users to cause a denial-of-service by runnin...

Apr 9, 2025
CVE-2024-54175
5.5

This vulnerability in IBM MQ allows a local user to cause a denial of service by exploiting improper error handling. It affects IBM MQ 9.3 LTS, 9.3 CD...

Feb 28, 2025
CVE-2024-56776
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's STI DRM driver. If exploited, it could cause a kernel panic leading ...

Jan 8, 2025
CVE-2024-56778
5.5

This CVE involves a Linux kernel vulnerability in the STI DRM driver where the drm_atomic_get_crtc_state() function's return value isn't properly chec...

Jan 8, 2025
CVE-2024-56725
5.5

This CVE addresses an improper check for return values in the Linux kernel's octeontx2-pf driver, specifically in the Data Center Bridging (DCB) netwo...

Dec 29, 2024
CVE-2024-50284
5.5

This CVE-2024-50284 is a missing error check vulnerability in the Linux kernel's ksmbd (SMB server) module. When xa_store() fails due to invalid param...

Nov 19, 2024

About CWE-754 (CWE-754)

Our database tracks 127 CVEs classified as CWE-754, with 8 rated critical and 64 rated high severity. The average CVSS score for CWE-754 vulnerabilities is 6.9.

External reference: View CWE-754 on MITRE CWE →

Monitor CWE-754 Vulnerabilities

Get alerted when new CWE-754 CVEs affect your infrastructure.

Start Monitoring Free