CWE-843: CWE-843

207
Total CVEs
26
Critical
153
High
8.1
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
12
2025
68
2024
52
2023
35
2022
13

Top Affected Vendors

1 Google 67
2 Microsoft 32
3 Apple 25
4 Fedoraproject 21
5 Debian 12
6 Ashlar 7
7 Siemens 6
8 Linux 5
9 Foxit 5
10 Huawei 5

All CWE-843 CVEs (207)

CVE-2021-46878
7.8

CVE-2021-46878 is a type confusion vulnerability in Fluent Bit's msgpack parsing that leads to use-after-free conditions. Attackers can craft maliciou...

Apr 11, 2023
CVE-2022-37377
7.8

This vulnerability in Foxit PDF Editor allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files or visitin...

Mar 29, 2023
CVE-2022-1786
7.8

A use-after-free vulnerability in the Linux kernel's io_uring subsystem allows local attackers to crash the system or potentially escalate privileges....

Jun 2, 2022
CVE-2021-32965
7.8

Delta Electronics DIAScreen versions prior to 1.1.0 contain a type confusion vulnerability that could allow remote attackers to execute arbitrary code...

May 24, 2022
CVE-2022-22661
7.8

This CVE-2022-22661 is a type confusion vulnerability in macOS that allows an application to execute arbitrary code with kernel privileges. It affects...

Mar 18, 2022
CVE-2021-34866
7.8

This vulnerability allows local attackers with low-privileged access to escalate privileges to kernel-level execution through improper eBPF program va...

Jan 25, 2022
CVE-2021-27038
7.8

A Type Confusion vulnerability in Autodesk Design Review allows arbitrary code execution when processing malicious PDF files. This affects users of Au...

Jul 9, 2021
CVE-2021-31461
7.8

This vulnerability in Foxit Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files or visiting ma...

May 7, 2021
CVE-2020-27257
7.8

This vulnerability allows local attackers to execute arbitrary code on Omron CX-One industrial automation software due to improper validation of user-...

Feb 9, 2021
CVE-2021-25177
7.8

A type confusion vulnerability in Open Design Alliance Drawings SDK allows attackers to crash applications by providing malformed .DXF or .DWG files. ...

Jan 18, 2021
CVE-2020-27293
7.8

This vulnerability in Delta Electronics CNCSoft-B allows attackers to execute arbitrary code by exploiting a type confusion issue when processing mali...

Jan 11, 2021
CVE-2024-40676
7.7

This Android vulnerability allows attackers to bypass intent security checks in AccountManagerService, enabling installation of unauthorized apps with...

Jan 28, 2025
CVE-2026-25537
7.5

This vulnerability in the jsonwebtoken Rust library allows attackers to bypass time-based security restrictions like 'Not Before' (nbf) and 'Expiratio...

Feb 4, 2026
CVE-2025-43506
7.5

A logic error in macOS iCloud Private Relay prevents activation when multiple users are logged in simultaneously, potentially exposing network traffic...

Dec 12, 2025
CVE-2025-7424
7.5

A type confusion vulnerability in libxslt's psvi memory field allows attackers to crash applications or corrupt memory during XML transformations. Thi...

Jul 10, 2025
CVE-2025-30397
KEV EPSS 21.3% 7.5

A type confusion vulnerability in Microsoft Scripting Engine allows remote attackers to execute arbitrary code by sending specially crafted network re...

May 13, 2025
CVE-2025-24129
7.5

A type confusion vulnerability in Apple operating systems allows remote attackers to cause unexpected application termination. This affects users runn...

Jan 27, 2025
CVE-2023-44108
7.5

This CVE describes a type confusion vulnerability in Huawei's distributed file module that could allow attackers to cause denial of service through de...

Oct 11, 2023
CVE-2022-30557
7.5

Foxit PDF Reader and PDF Editor versions before 11.2.2 contain a type confusion vulnerability during JavaScript execution that can cause application c...

May 11, 2022
CVE-2021-39987
7.5

CVE-2021-39987 is a data processing error vulnerability in the HwNearbyMain module of HarmonyOS devices. Successful exploitation can cause process res...

Jan 3, 2022
CVE-2021-40872
7.5

This vulnerability in Softing Industrial Automation uaToolkit Embedded allows remote attackers to cause denial of service (DoS) by crashing the OPC/UA...

Nov 10, 2021
CVE-2025-55137
7.4

LinkJoin versions through commit 882f196 lack proper type checking in password reset functionality, allowing attackers to bypass authentication contro...

Aug 7, 2025
CVE-2023-0286
7.4

CVE-2023-0286 is a type confusion vulnerability in OpenSSL's X.400 address processing that can cause memory corruption when CRL checking is enabled. A...

Feb 8, 2023
CVE-2025-14325
7.3

A JIT (Just-In-Time) compilation vulnerability in Mozilla's JavaScript engine allows memory corruption through miscompiled code. This affects Firefox,...

Dec 9, 2025
CVE-2024-11344
7.3

A type confusion vulnerability in the Postscript interpreter of Lexmark devices allows attackers to execute arbitrary code by sending specially crafte...

Feb 13, 2025
CVE-2024-11346
7.3

A type confusion vulnerability in Lexmark printer PostScript interpreters allows attackers to inject resources and potentially execute arbitrary code....

Feb 13, 2025
CVE-2021-23440
7.3

CVE-2021-23440 is a type confusion vulnerability in the set-value npm package that allows attackers to bypass previous security fixes (CVE-2019-10747)...

Sep 12, 2021
CVE-2024-49860
7.1

This CVE-2024-49860 is a Linux kernel vulnerability in the ACPI sysfs subsystem where improper validation of the _STR method's return type could lead ...

Oct 21, 2024
CVE-2023-1077
7.0

CVE-2023-1077 is a type confusion vulnerability in the Linux kernel's real-time scheduler that can lead to memory corruption. This allows local attack...

Mar 27, 2023
CVE-2025-54104
6.7

A type confusion vulnerability in Windows Defender Firewall Service allows authenticated attackers to execute arbitrary code with elevated SYSTEM priv...

Sep 9, 2025
CVE-2025-53810
6.7

This CVE describes a type confusion vulnerability in the Windows Defender Firewall Service that allows an authenticated attacker to escalate privilege...

Sep 9, 2025
CVE-2025-14799
6.5

This vulnerability allows unauthenticated attackers to bypass authorization in the Brevo WordPress plugin using PHP type juggling. Attackers can disco...

Feb 18, 2026
CVE-2025-12899
6.5

A vulnerability in Zephyr's network stack allows specially crafted IPv4 packets with ICMP type 128 to be incorrectly processed as ICMPv6 Echo Requests...

Jan 30, 2026
CVE-2025-7259
6.5

An authorized MongoDB user can cause a server crash by issuing queries containing duplicate _id fields, leading to denial of service. This affects Mon...

Jul 7, 2025
CVE-2025-29806
6.5

This vulnerability in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute arbitrary code over a network connection. It affects ...

Mar 23, 2025
CVE-2025-21279
6.5

This vulnerability in Microsoft Edge (Chromium-based) allows remote attackers to execute arbitrary code on affected systems by tricking users into vis...

Feb 6, 2025
CVE-2024-43489
6.5

This vulnerability in Microsoft Edge (Chromium-based) allows remote attackers to execute arbitrary code on affected systems by tricking users into vis...

Sep 19, 2024
CVE-2024-5843
6.5

This vulnerability in Google Chrome allows attackers to hide security warnings during file downloads, potentially tricking users into opening maliciou...

Jun 11, 2024
CVE-2023-46842
6.5

A Xen hypervisor vulnerability where HVM guests can set register values outside expected ranges during hypercall continuations, triggering a hyperviso...

May 16, 2024
CVE-2024-38207
6.3

This vulnerability in Microsoft Edge allows attackers to execute arbitrary code by exploiting memory corruption through specially crafted HTML content...

Aug 23, 2024
CVE-2025-43297
6.2

A type confusion vulnerability in macOS allows malicious applications to cause denial-of-service conditions by manipulating memory incorrectly. This a...

Sep 15, 2025
CVE-2026-22028
6.1

A regression in Preact versions 10.26.5 through 10.28.1 weakens JSON serialization protection, allowing specially-crafted JSON payloads to be incorrec...

Jan 8, 2026
CVE-2025-21225
5.9

This vulnerability in Windows Remote Desktop Gateway allows attackers to cause a denial of service by sending specially crafted requests. It affects o...

Jan 14, 2025
CVE-2025-43355
5.5

A type confusion vulnerability in Apple operating systems allows malicious apps to cause denial-of-service conditions by exploiting memory handling fl...

Sep 15, 2025
CVE-2024-54507
5.5

A type confusion vulnerability in Apple operating systems allows attackers with user privileges to read kernel memory. This affects macOS, iOS, and iP...

Jan 27, 2025
CVE-2024-54524
5.5

This CVE describes a logic flaw in macOS file handling that allows malicious applications to bypass intended access restrictions and read arbitrary fi...

Dec 12, 2024
CVE-2024-34742
5.5

This vulnerability in Android's framework prevents Mobile Device Management (MDM) policies from being properly saved due to a logic error in the Owner...

Aug 15, 2024
CVE-2024-40788
5.5

This CVE describes a type confusion vulnerability in Apple operating systems that allows a local attacker to cause unexpected system shutdowns. The is...

Jul 29, 2024
CVE-2022-50590
5.3

This vulnerability allows remote unauthenticated attackers to exploit a type confusion flaw in SuiteCRM's deleteAttachment functionality to modify dat...

Nov 6, 2025
CVE-2024-37603
4.6

A type confusion vulnerability exists in the user data import/export function of Mercedes Benz NTG 6 head units. Attackers with physical access to the...

Feb 13, 2025

About CWE-843 (CWE-843)

Our database tracks 207 CVEs classified as CWE-843, with 26 rated critical and 153 rated high severity. The average CVSS score for CWE-843 vulnerabilities is 8.1.

External reference: View CWE-843 on MITRE CWE →

Monitor CWE-843 Vulnerabilities

Get alerted when new CWE-843 CVEs affect your infrastructure.

Start Monitoring Free