CWE-789: CWE-789

21
Total CVEs
1
Critical
12
High
7.0
Avg CVSS

Yearly Trend

2026
5
2025
8
2024
4
2023
2
2022
2

Top Affected Vendors

1 Ibm 7
2 Cisco 2
3 Apache 1
4 Svelte 1
5 Linuxfoundation 1
6 Openssl 1
7 Gofiber 1
8 Parallels 1
9 T2bot 1
10 Codesys 1

All CWE-789 CVEs (21)

CVE-2023-43632
9.0

CVE-2023-43632 is a stack-based buffer overflow vulnerability in EVE's VTPM server that allows remote attackers to execute arbitrary code with high pr...

Sep 21, 2023
CVE-2021-34868
8.8

This vulnerability in Parallels Desktop allows local attackers to escalate privileges from a guest VM to the hypervisor. Attackers must first execute ...

Jan 25, 2022
CVE-2024-20260
8.6

This vulnerability allows unauthenticated remote attackers to cause memory exhaustion on Cisco ASAv and FTDv virtual firewall platforms by flooding th...

Oct 23, 2024
CVE-2026-20048
7.7

An authenticated remote attacker can cause a denial of service (DoS) on Cisco Nexus 9000 Series Fabric Switches in ACI mode by sending continuous SNMP...

Feb 25, 2026
CVE-2026-25899
7.5

CVE-2026-25899 is a memory exhaustion vulnerability in GoFiber v3 web framework where a specially crafted 10-character cookie value triggers unvalidat...

Feb 24, 2026
CVE-2026-22803
7.5

CVE-2026-22803 is a denial-of-service vulnerability in SvelteKit's experimental form remote function that allows attackers to cause memory exhaustion ...

Jan 15, 2026
CVE-2025-61910
7.5

This vulnerability in NASA's ION-DTN software allows an attacker to cause a denial-of-service (DoS) by sending a specially crafted BPv7 bundle with a ...

Oct 7, 2025
CVE-2025-3632
7.5

This vulnerability in IBM 4769 Developers Toolkit allows remote attackers to trigger a denial of service in the Hardware Security Module (HSM) by send...

May 12, 2025
CVE-2025-27533
7.5

This vulnerability in Apache ActiveMQ allows attackers to cause denial of service by sending specially crafted OpenWire commands that trigger excessiv...

May 7, 2025
CVE-2025-30211
7.5

This vulnerability in Erlang/OTP allows attackers to cause denial of service through memory exhaustion by sending specially crafted SSH KEX init messa...

Mar 28, 2025
CVE-2022-31804
7.5

CVE-2022-31804 is a memory allocation vulnerability in CODESYS Gateway Server V2 where unauthenticated attackers can send oversized requests to cause ...

Jun 24, 2022
CVE-2025-20140
7.4

An unauthenticated adjacent wireless attacker can cause denial of service on Cisco IOS XE WLCs by sending crafted IPv6 packets that trigger memory exh...

May 7, 2025
CVE-2023-20089
7.4

An unauthenticated attacker on the same network segment can send crafted LLDP packets to Cisco Nexus 9000 ACI switches, causing a memory leak that lea...

Feb 23, 2023
CVE-2025-2668
6.5

IBM Db2 database servers running versions 11.5.0 through 11.5.9 are vulnerable to denial of service attacks. An authenticated user can crash the serve...

Jan 30, 2026
CVE-2024-35152
6.5

This vulnerability in IBM Db2 allows authenticated users to cause denial of service through specially crafted queries that trigger improper memory all...

Aug 14, 2024
CVE-2025-66199
5.9

A TLS 1.3 vulnerability in OpenSSL allows attackers to force large memory allocations (up to 22 MiB per connection) via certificate compression, poten...

Jan 27, 2026
CVE-2024-35116
5.9

IBM MQ versions 9.0 LTS through 9.3 CD are vulnerable to denial of service attacks when configuration changes are applied. Attackers can exploit this ...

Jun 28, 2024
CVE-2025-2534
5.3

IBM Db2 databases running vulnerable versions can be crashed by a specially crafted query, causing denial of service. This affects Db2 11.1.0-11.1.4.7...

Nov 7, 2025
CVE-2025-2533
5.3

IBM Db2 for Linux versions 12.1.0 through 12.1.2 contain a vulnerability where a specially crafted query can cause the database server to crash, resul...

Jul 29, 2025
CVE-2024-52791
5.3

Matrix Media Repo (MMR) versions before 1.3.8 are vulnerable to memory exhaustion attacks when processing malicious JSON responses from external serve...

Jan 16, 2025
CVE-2024-41761
5.3

IBM Db2 databases on Linux, UNIX, and Windows (including Db2 Connect Server) versions 10.5, 11.1, and 11.5 can be crashed by a specially crafted query...

Nov 23, 2024

About CWE-789 (CWE-789)

Our database tracks 21 CVEs classified as CWE-789, with 1 rated critical and 12 rated high severity. The average CVSS score for CWE-789 vulnerabilities is 7.0.

External reference: View CWE-789 on MITRE CWE →

Monitor CWE-789 Vulnerabilities

Get alerted when new CWE-789 CVEs affect your infrastructure.

Start Monitoring Free