CWE-755: CWE-755

81
Total CVEs
12
Critical
53
High
7.7
Avg CVSS

Yearly Trend

2026
8
2025
10
2024
20
2023
16
2022
10

Top Affected Vendors

1 Juniper 11
2 Debian 7
3 Google 6
4 Fedoraproject 4
5 Arm 3
6 Huawei 3
7 Autodesk 2
8 Contiki Ng 2
9 Mozilla 2
10 Newtonsoft 1

All CWE-755 CVEs (81)

CVE-2025-10156
9.8

This vulnerability allows attackers to bypass security scans in mmaitre314 picklescan by crafting ZIP archives with bad CRC values. When exploited, ma...

Sep 17, 2025
CVE-2021-42142
9.8

This vulnerability in Contiki-NG tinyDTLS allows remote attackers to cause denial of service and false-positive packet drops by sending DTLS packets w...

Jan 23, 2024
CVE-2021-42141
9.8

This vulnerability in Contiki-NG's tinyDTLS implementation allows an attacker to cause denial of service by exploiting inconsistent epoch numbers duri...

Jan 22, 2024
CVE-2023-38406
9.8

CVE-2023-38406 is a critical buffer overflow vulnerability in FRRouting's BGP flowspec component that allows remote attackers to execute arbitrary cod...

Nov 6, 2023
CVE-2022-23121
9.8

CVE-2022-23121 is a critical remote code execution vulnerability in Netatalk's AppleDouble parsing functionality. Unauthenticated attackers can exploi...

Mar 28, 2023
CVE-2021-4105
9.8

This vulnerability allows remote attackers to execute arbitrary code on BG-TEK COSLAT Firewall devices by exploiting improper parameter handling. It a...

Feb 24, 2023
CVE-2022-48328
9.8

This vulnerability in MISP (Malware Information Sharing Platform) allows SQL injection through mishandled URL parameters in the IndexFilterComponent. ...

Feb 20, 2023
CVE-2022-31799
9.8

CVE-2022-31799 is a critical vulnerability in Bottle web framework where improper error handling during early request binding can lead to remote code ...

Jun 2, 2022
CVE-2021-43272
9.8

This vulnerability allows remote code execution through malicious DWF files in Open Design Alliance ODA Viewer sample versions before 2022.11. Attacke...

Nov 14, 2021
CVE-2021-38384
9.8

Serverless Offline 8.0.0 incorrectly returns a 403 HTTP status code for routes with trailing slashes, while AWS Lambda returns 200. This discrepancy c...

Aug 10, 2021
CVE-2021-36128
9.8

This vulnerability in MediaWiki's CentralAuth extension allows improper implementation of autoblocks for suppression blocks. Attackers could bypass ac...

Jul 2, 2021
CVE-2026-27586
9.1

CVE-2026-27586 is a critical authentication bypass vulnerability in Caddy server where mTLS client certificate authentication silently fails open when...

Feb 24, 2026
CVE-2024-7521
8.8

A use-after-free vulnerability in WebAssembly exception handling in Mozilla products could allow remote code execution. This affects Firefox, Firefox ...

Aug 6, 2024
CVE-2024-3150
8.8

This vulnerability allows users with Default or Manager roles in mintplex-labs/anything-llm to escalate their privileges to Administrator by exploitin...

Jun 6, 2024
CVE-2023-6866
8.8

This vulnerability involves improper exception handling in TypedArrays in Firefox, which can be exploited through other APIs that expect TypedArrays t...

Dec 19, 2023
CVE-2021-33477
8.8

This vulnerability allows remote code execution in multiple terminal emulators (rxvt-unicode, rxvt, mrxvt, Eterm) through improper handling of ESC G Q...

May 20, 2021
CVE-2023-21409
8.4

This vulnerability allows unprivileged users to access administrator credentials due to insufficient file permissions. Attackers could use these crede...

Aug 3, 2023
CVE-2022-20111
8.4

This CVE describes a use-after-free vulnerability in the ION memory management subsystem on MediaTek devices. It allows local attackers to escalate pr...

May 3, 2022
CVE-2022-1965
8.1

CVE-2022-1965 is an improper error handling vulnerability in multiple CODESYS products that allows low-privilege remote attackers to delete arbitrary ...

Jun 24, 2022
CVE-2025-54634
8.0

This vulnerability involves improper handling of abnormal conditions during huge page separation in memory management. Successful exploitation could c...

Aug 6, 2025
CVE-2024-9413
8.0

A buffer overflow vulnerability in SCP-Firmware's transport_message_handler function allows an Application Processor to potentially execute arbitrary ...

Nov 13, 2024
CVE-2024-27442
7.8

This vulnerability allows local privilege escalation in Zimbra Collaboration Suite. An attacker with access to the zimbra user account can exploit imp...

Aug 12, 2024
CVE-2024-29748
7.8

CVE-2024-29748 is a logic error vulnerability in Android that allows local privilege escalation without requiring additional execution privileges. Att...

Apr 5, 2024
CVE-2023-43251
7.8

CVE-2023-43251 is a buffer overflow vulnerability in XNSoft Nconvert 7.136 where a crafted image file can corrupt the exception handler chain. Attacke...

Oct 19, 2023
CVE-2023-20993
7.8

This vulnerability in Android's SnoozeHelper component allows local privilege escalation without user interaction due to uncaught exceptions that prev...

Mar 24, 2023
CVE-2022-27872
7.8

This vulnerability in Autodesk Navisworks 2022 allows attackers to craft malicious PDF files that cause pointer dereference issues during parsing, pot...

Jun 21, 2022
CVE-2022-20088
7.8

This vulnerability in the aee driver allows local privilege escalation due to incorrect reference count handling during error conditions. Attackers wi...

May 3, 2022
CVE-2022-25795
7.8

CVE-2022-25795 is a memory corruption vulnerability in Autodesk TrueView that allows remote code execution when processing malicious DWG files. Attack...

Apr 13, 2022
CVE-2021-28705
7.8

This vulnerability in Xen hypervisor allows x86 HVM and PVH guests to cause memory corruption through improper error handling in partially successful ...

Nov 24, 2021
CVE-2021-0478
7.8

This vulnerability allows local privilege escalation on Android devices by bypassing permission checks. An uncaught exception in the status bar icon u...

Jun 21, 2021
CVE-2020-16895
7.8

This Windows vulnerability allows an authenticated attacker to delete arbitrary files by exploiting improper handling of process crashes in Windows Er...

Oct 16, 2020
CVE-2026-27195
7.5

A bug in Wasmtime's async component model implementation causes a panic when call_async futures are dropped before completion and then called again on...

Feb 24, 2026
CVE-2026-21906
7.5

An unauthenticated attacker can crash the packet forwarding engine on vulnerable Juniper SRX Series devices by sending a specific ICMP packet through ...

Jan 15, 2026
CVE-2025-58047
7.5

This vulnerability in Volto (React frontend for Plone CMS) allows anonymous users to crash the NodeJS server by visiting a specific URL, causing denia...

Aug 28, 2025
CVE-2024-11864
7.5

CVE-2024-11864 is a vulnerability in SCP-Firmware where specially crafted SCMI messages can cause a Usage Fault and crash the System Control Processor...

Jan 14, 2025
CVE-2024-39547
7.5

An unauthenticated network attacker can send crafted TCP traffic to Juniper Junos OS routing engines to cause CPU-based denial of service in the rpd-s...

Oct 11, 2024
CVE-2024-6594
7.5

A denial-of-service vulnerability in WatchGuard Single Sign-On Client for Windows allows attackers with network access to crash the SSO service by sen...

Sep 25, 2024
CVE-2024-45038
7.5

This CVE describes a denial-of-service vulnerability in Meshtastic device firmware's MQTT handling. Attackers can crash devices by sending malicious M...

Aug 27, 2024
CVE-2024-39555
7.5

This vulnerability allows remote attackers to cause denial of service by sending specially crafted BGP update messages to Juniper devices with segment...

Jul 10, 2024
CVE-2024-36730
7.5

This vulnerability in OneFlow v0.9.1 allows attackers to cause Denial of Service (DoS) by providing negative values to the oneflow.zeros/ones paramete...

Jun 6, 2024
CVE-2024-32652
7.5

This vulnerability in @hono/node-server versions before 1.10.1 causes application hangs when receiving malformed Host headers. Attackers can send spec...

Apr 19, 2024
CVE-2024-30382
7.5

This vulnerability allows network-based attackers to cause a denial of service on Juniper devices by sending malicious routing updates that trigger me...

Apr 12, 2024
CVE-2024-21907
7.5

Newtonsoft.Json versions before 13.0.1 contain a vulnerability where specially crafted JSON data can trigger a StackOverflowException when deserialize...

Jan 3, 2024
CVE-2023-52075
7.5

The ReVanced API lacks proper error caching, causing rate limits to be triggered unnecessarily and increasing server load. This leads to denial of ser...

Dec 27, 2023
CVE-2023-5824
7.5

A vulnerability in Squid proxy server allows cached HTTP response headers to exceed configured size limits, causing worker process stalls or crashes w...

Nov 3, 2023
CVE-2023-41317
7.5

A Denial-of-Service vulnerability in Apollo Router versions 1.28.0-1.29.0 causes the router to crash and terminate when specific conditions are met wi...

Sep 5, 2023
CVE-2023-36832
7.5

An unauthenticated network attacker can send specific packets to Aggregated Multiservices (AMS) interfaces on vulnerable Juniper MX Series devices, ca...

Jul 14, 2023
CVE-2023-24510
7.5

This vulnerability in Arista EOS DHCP relay agent allows an attacker to cause a denial of service by sending a malformed DHCP packet, leading to the a...

Jun 5, 2023
CVE-2022-27978
7.5

CVE-2022-27978 is an improper input validation vulnerability in Tooljet v1.6 that allows attackers to reset arbitrary user passwords via crafted API r...

Apr 26, 2023
CVE-2021-38363
7.5

This vulnerability in ONOS (Open Network Operating System) allows memory exhaustion through orphaned intents that cannot be cleaned up. When an intent...

Apr 20, 2023

About CWE-755 (CWE-755)

Our database tracks 81 CVEs classified as CWE-755, with 12 rated critical and 53 rated high severity. The average CVSS score for CWE-755 vulnerabilities is 7.7.

External reference: View CWE-755 on MITRE CWE →

Monitor CWE-755 Vulnerabilities

Get alerted when new CWE-755 CVEs affect your infrastructure.

Start Monitoring Free