CWE-843: CWE-843

200
Total CVEs
25
Critical
147
High
8.1
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
12
2025
68
2024
52
2023
35
2022
13

Top Affected Vendors

1 Google 67
2 Microsoft 32
3 Apple 25
4 Fedoraproject 21
5 Debian 12
6 Ashlar 7
7 Linux 5
8 Foxit 5
9 Huawei 5
10 Facebook 4

All CWE-843 CVEs (200)

CVE-2026-2796
9.8

A JIT miscompilation vulnerability in Firefox's JavaScript: WebAssembly component could allow arbitrary code execution when processing malicious web c...

Feb 24, 2026
CVE-2025-65570
9.8

A type confusion vulnerability in jsish 2.0 allows incorrect control flow during execution of the OP_NEXT opcode. When an 'instanceof' expression uses...

Dec 29, 2025
CVE-2025-47151
9.8

A type confusion vulnerability in Entr'ouvert Lasso's SAML parsing allows remote code execution when processing malicious SAML responses. This affects...

Nov 5, 2025
CVE-2025-10585
KEV 9.8

A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption by tricking the browser into misinterpreti...

Sep 24, 2025
CVE-2025-22435
9.8

This vulnerability allows memory corruption via type confusion in Android's Bluetooth AVDT protocol implementation. An attacker with paired Bluetooth ...

Sep 2, 2025
CVE-2024-7824
9.8

A type confusion vulnerability in Webroot SecureAnywhere's Web Shield component allows attackers to misuse functionality by accessing resources with i...

Oct 3, 2024
CVE-2024-8381
9.8

This vulnerability allows attackers to trigger type confusion when accessing properties on objects used as 'with' statement environments in Mozilla pr...

Sep 3, 2024
CVE-2024-20078
9.8

This is a critical type confusion vulnerability in MediaTek's venc component that allows local privilege escalation. Attackers can execute arbitrary c...

Jul 1, 2024
CVE-2023-43154
9.8

This vulnerability allows attackers to bypass authentication in Macrob7 Macs Framework CMS 1.1.4f by exploiting PHP type confusion in the login valida...

Sep 27, 2023
CVE-2023-42464
9.8

A Type Confusion vulnerability in Netatalk's afpd service allows remote attackers to potentially execute arbitrary code by sending malicious Spotlight...

Sep 20, 2023
CVE-2023-21287
9.8

This CVE describes a type confusion vulnerability in Android's FreeType library that allows remote code execution without user interaction. Attackers ...

Aug 14, 2023
CVE-2023-25933
9.8

A type confusion vulnerability in Hermes JavaScript engine's TypedArray implementation allows arbitrary code execution when processing untrusted JavaS...

May 18, 2023
CVE-2023-26063
9.8

This vulnerability in Lexmark devices allows attackers to access resources using incompatible types, potentially leading to remote code execution or d...

Apr 10, 2023
CVE-2021-46463
9.8

CVE-2021-46463 is a critical type confusion vulnerability in njs (NGINX JavaScript) that allows attackers to hijack control flow and potentially execu...

Feb 14, 2022
CVE-2021-24044
9.8

This vulnerability in Hermes JavaScript engine allows attackers to cause type confusion by passing invalid JavaScript code with await/yield calls on n...

Jan 15, 2022
CVE-2021-24045
9.8

A type confusion vulnerability in Facebook Hermes JavaScript engine prior to v0.10.0 could allow arbitrary code execution when processing untrusted Ja...

Dec 13, 2021
CVE-2021-1829
9.8

CVE-2021-1829 is a type confusion vulnerability in macOS that allows an application to execute arbitrary code with kernel privileges. This affects mac...

Sep 8, 2021
CVE-2020-1911
9.8

A type confusion vulnerability in Facebook's Hermes JavaScript engine allows attackers to potentially execute arbitrary code by crafting malicious Jav...

Sep 4, 2020
CVE-2024-7971
9.6

This is a type confusion vulnerability in Chrome's V8 JavaScript engine that allows remote attackers to trigger heap corruption via malicious HTML pag...

Aug 21, 2024
CVE-2024-5274
9.6

This is a type confusion vulnerability in Chrome's V8 JavaScript engine that allows remote attackers to execute arbitrary code within the browser's sa...

May 28, 2024
CVE-2024-4947
9.6

This vulnerability is a type confusion flaw in Chrome's V8 JavaScript engine that allows remote attackers to execute arbitrary code within the browser...

May 15, 2024
CVE-2025-64314
9.3

A permission control vulnerability in the memory management module allows unauthorized access to sensitive memory regions. This affects confidentialit...

Nov 28, 2025
CVE-2025-26496
9.3

This CVE describes a type confusion vulnerability in Salesforce Tableau's file upload modules that allows local attackers to include and execute arbit...

Aug 22, 2025
CVE-2026-24874
9.1

This is a type confusion vulnerability in the xray-monolith software that allows attackers to access memory with incompatible types, potentially leadi...

Jan 27, 2026
CVE-2021-46743
9.1

CVE-2021-46743 is an algorithm confusion vulnerability in Firebase PHP-JWT library that allows attackers to forge JWT tokens by exploiting key ID (kid...

Mar 29, 2022
CVE-2026-1862
8.8

A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to corrupt heap memory via malicious web pages. This could lead to ar...

Feb 3, 2026
CVE-2025-13630
8.8

A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption by tricking the engine into treating one d...

Dec 2, 2025
CVE-2025-13229
8.8

A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption by tricking the browser into misinterpreti...

Nov 18, 2025
CVE-2025-13230
8.8

A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption by tricking the engine into treating one d...

Nov 18, 2025
CVE-2025-13226
8.8

A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption by tricking the engine into treating one d...

Nov 18, 2025
CVE-2025-13227
8.8

A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption by tricking the engine into treating one d...

Nov 18, 2025
CVE-2025-13228
8.8

A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption by tricking the engine into treating one d...

Nov 18, 2025
CVE-2025-13224
8.8

This is a type confusion vulnerability in Chrome's V8 JavaScript engine that could allow an attacker to execute arbitrary code or cause heap corruptio...

Nov 17, 2025
CVE-2025-13223
KEV 8.8

A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption by tricking the engine into treating one d...

Nov 17, 2025
CVE-2025-12428
8.8

A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to perform arbitrary memory read/write operations through a malicious...

Nov 10, 2025
CVE-2025-53144
8.8

A type confusion vulnerability in Windows Message Queuing allows authenticated attackers to execute arbitrary code remotely. This affects systems with...

Aug 12, 2025
CVE-2025-8010
8.8

A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption by tricking the engine into treating one d...

Jul 22, 2025
CVE-2025-5959
8.8

This vulnerability allows remote attackers to execute arbitrary code within Chrome's sandbox through type confusion in the V8 JavaScript engine. Users...

Jun 11, 2025
CVE-2025-1920
8.8

A type confusion vulnerability in Chrome's V8 JavaScript engine could allow attackers to execute arbitrary code or cause heap corruption by tricking u...

Mar 10, 2025
CVE-2025-2135
8.8

This is a type confusion vulnerability in Chrome's V8 JavaScript engine that could allow an attacker to trigger heap corruption by tricking the browse...

Mar 10, 2025
CVE-2025-21342
8.8

This vulnerability in Microsoft Edge (Chromium-based) allows remote attackers to execute arbitrary code on affected systems by tricking users into vis...

Feb 6, 2025
CVE-2025-21408
8.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Microsoft Edge. Attackers could exploit...

Feb 6, 2025
CVE-2025-0147
8.8

A type confusion vulnerability in Zoom Workplace App for Linux allows authenticated users to escalate privileges through network access. This affects ...

Jan 30, 2025
CVE-2025-0291
8.8

This is a type confusion vulnerability in Chrome's V8 JavaScript engine that allows remote attackers to execute arbitrary code within the browser's sa...

Jan 8, 2025
CVE-2024-54505
8.8

This CVE describes a type confusion vulnerability in Apple's WebKit browser engine that could allow memory corruption when processing malicious web co...

Dec 12, 2024
CVE-2024-12053
8.8

A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to corrupt memory objects through malicious HTML pages. This could le...

Dec 3, 2024
CVE-2024-11395
8.8

This is a type confusion vulnerability in Chrome's V8 JavaScript engine that allows attackers to trigger heap corruption through malicious web pages. ...

Nov 19, 2024
CVE-2024-10231
8.8

This vulnerability is a type confusion flaw in Chrome's V8 JavaScript engine that allows a remote attacker to trigger heap corruption by tricking the ...

Oct 22, 2024
CVE-2024-9602
8.8

This vulnerability is a type confusion flaw in Chrome's V8 JavaScript engine that allows attackers to write data outside intended memory bounds. Attac...

Oct 8, 2024
CVE-2024-9122
8.8

This vulnerability is a type confusion flaw in Chrome's V8 JavaScript engine that allows attackers to perform out-of-bounds memory access. Attackers c...

Sep 25, 2024

About CWE-843 (CWE-843)

Our database tracks 200 CVEs classified as CWE-843, with 25 rated critical and 147 rated high severity. The average CVSS score for CWE-843 vulnerabilities is 8.1.

External reference: View CWE-843 on MITRE CWE →

Monitor CWE-843 Vulnerabilities

Get alerted when new CWE-843 CVEs affect your infrastructure.

Start Monitoring Free