CWE-754: CWE-754

128
Total CVEs
8
Critical
65
High
6.9
Avg CVSS

Yearly Trend

2026
18
2025
40
2024
40
2023
13
2022
7

Top Affected Vendors

1 Juniper 24
2 Linux 14
3 Mattermost 6
4 Huawei 5
5 Apple 4
6 Ibm 4
7 Openssl 3
8 Schneider Electric 3
9 Cisco 2
10 Paloaltonetworks 2

All CWE-754 CVEs (128)

CVE-2024-50284
5.5

This CVE-2024-50284 is a missing error check vulnerability in the Linux kernel's ksmbd (SMB server) module. When xa_store() fails due to invalid param...

Nov 19, 2024
CVE-2024-35424
5.5

CVE-2024-35424 is a segmentation violation vulnerability in vmir's WebAssembly parser that can cause denial of service or potentially allow arbitrary ...

Nov 8, 2024
CVE-2024-50195
5.5

A missing input validation vulnerability in the Linux kernel's posix-clock subsystem allows attackers to pass invalid timespec64 values to PTP clock d...

Nov 8, 2024
CVE-2024-50184
5.5

A vulnerability in the Linux kernel's virtio_pmem driver could cause system hangs when attempting to flush data from a non-activated persistent memory...

Nov 8, 2024
CVE-2024-44174
5.5

This macOS vulnerability allows attackers to bypass lock screen protections and view restricted content when a device is locked. It affects macOS user...

Oct 28, 2024
CVE-2024-40933
5.5

This CVE involves an improper check for error conditions in the Linux kernel's MLX90635 temperature sensor driver. When devm_regmap_init_i2c() fails d...

Jul 12, 2024
CVE-2023-52678
5.5

This CVE addresses a NULL pointer dereference vulnerability in the AMD GPU kernel driver (amdkfd) of the Linux kernel. The issue occurs when the drive...

May 17, 2024
CVE-2026-0944
5.3

This vulnerability in Drupal Group invite allows attackers to bypass access controls through forceful browsing, potentially accessing restricted conte...

Feb 4, 2026
CVE-2026-22796
5.3

A type confusion vulnerability in OpenSSL's PKCS#7 signature verification allows attackers to cause denial of service by providing malformed signed PK...

Jan 27, 2026
CVE-2025-66357
5.3

The CHOCO TEI WATCHER mini (IB-MCT001) has an improper condition check vulnerability in its Video Download feature that can cause abnormal resource co...

Dec 16, 2025
CVE-2025-13080
5.3

This vulnerability in Drupal core allows attackers to bypass access controls through forceful browsing, potentially accessing restricted content or fu...

Nov 18, 2025
CVE-2024-26008
5.3

This vulnerability allows an unauthenticated attacker to repeatedly reset the fgfm connection via crafted SSL encrypted TCP requests, causing denial o...

Oct 14, 2025
CVE-2025-21597
5.3

An unauthenticated, logically adjacent BGP peer can cause a denial of service by triggering a crash and restart of the routing protocol daemon (rpd) i...

Apr 9, 2025
CVE-2024-43435
5.3

This vulnerability in Moodle allows users with course-level glossary restoration permissions to improperly restore glossaries into the global site glo...

Nov 11, 2024
CVE-2024-42411
5.3

This vulnerability in Mattermost allows authenticated users to manipulate the creation date of their accounts via the POST /api/v4/users endpoint, tri...

Aug 22, 2024
CVE-2024-32867
5.3

This vulnerability in Suricata involves improper handling of IP fragmentation anomalies, which can cause the intrusion detection/prevention system to ...

May 7, 2024
CVE-2025-12657
5.0

MongoDB's KMIP response parser accepts malformed packets that create invalid objects, causing read access violations when accessed. This affects Mongo...

Nov 3, 2025
CVE-2025-64704
4.7

This vulnerability in WebAssembly Micro Runtime (WAMR) allows a segmentation fault to be triggered via a specially crafted v128.store instruction in W...

Nov 25, 2025
CVE-2024-44235
4.6

This vulnerability allows an attacker to bypass lock screen restrictions on iOS/iPadOS devices to view sensitive content that should be protected. It ...

Oct 28, 2024
CVE-2024-54114
4.4

This CVE describes an out-of-bounds access vulnerability in the DASH module during playback, which could cause crashes or service disruption. It prima...

Dec 12, 2024
CVE-2025-62605
4.3

This vulnerability allows attackers to bypass quote controls in Mastodon by reblogging a post and then quoting their own reblog, effectively quoting c...

Oct 21, 2025
CVE-2024-54116
4.3

An out-of-bounds read vulnerability in the M3U8 module could allow attackers to read memory beyond allocated buffers. This affects systems using Huawe...

Dec 12, 2024
CVE-2025-32088
3.3

An improper conditions check in Intel QAT Windows software before version 2.6.0 allows authenticated local users to cause denial of service via low-co...

Nov 11, 2025
CVE-2026-24513
3.1

This CVE describes an authentication bypass vulnerability in ingress-nginx when using custom error backends. If administrators configure a defective c...

Feb 3, 2026
CVE-2026-0229
N/A

An unauthenticated denial-of-service vulnerability in Palo Alto Networks PAN-OS Advanced DNS Security feature allows attackers to cause system reboots...

Feb 11, 2026
CVE-2025-15542
N/A

CVE-2025-15542 is a denial-of-service vulnerability in TP-Link VX800v v1.0 VoIP phones where improper handling of SIP INVITE messages allows attackers...

Jan 29, 2026
CVE-2025-12387
N/A

A vulnerability in Pix-Link LV-WR21Q routers allows remote attackers to cause a denial of service (DoS) by sending a specially crafted HTTP POST reque...

Jan 27, 2026
CVE-2025-64342
N/A

This vulnerability in ESP-IDF allows attackers to disrupt Bluetooth Low Energy advertising on ESP32 devices by sending connection requests with invali...

Nov 17, 2025

About CWE-754 (CWE-754)

Our database tracks 128 CVEs classified as CWE-754, with 8 rated critical and 65 rated high severity. The average CVSS score for CWE-754 vulnerabilities is 6.9.

External reference: View CWE-754 on MITRE CWE →

Monitor CWE-754 Vulnerabilities

Get alerted when new CWE-754 CVEs affect your infrastructure.

Start Monitoring Free