Threats Tagged 'cwe-754'
View all threats tagged with 'cwe-754'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-754'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-69185: CWE-20: Improper Input Validation in socketio socket.ioCVE-2026-69185 0 Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6. Join the discussion | CVE Database V5 | 08/03/2026, 20:17:00 UTC Added: 08/03/2026, 19:49:19 UTC |
CVE-2026-20486: CWE-754 Improper Check for Unusual or Exceptional Conditions in MediaTek, Inc. MediaTek chipsetCVE-2026-20486 0 In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11012302; Issue ID: MSV-7833. Join the discussion | CVE Database V5 | 08/03/2026, 02:05:51 UTC Added: 08/03/2026, 02:48:36 UTC |
CVE-2026-0667: CWE-754: Improper Check for Unusual or Exceptional Conditions in Schneider Electric SCADAPack 47xCVE-2026-0667 0 CVE-2026-0667 is a critical vulnerability in Schneider Electric SCADAPack 47x devices involving improper checks for unusual or exceptional conditions. This flaw affects communication over the Modbus TCP protocol and could lead to arbitrary code execution, denial of service, and loss of confidentiality and integrity. The vulnerability has a high CVSS 4.0 score of 9.3, indicating severe impact. No specific affected versions or patches have been disclosed yet, and there are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 07/29/2026, 12:35:34 UTC Added: 07/29/2026, 13:22:41 UTC |
CVE-2026-44621: CWE-754: Improper Check for Unusual or Exceptional Conditions in NLnet Labs UnboundCVE-2026-44621 0 With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-reply-threshold', could eventually be abruptly terminated if the threshold is reached and libunbound needs to call 'libworker_alloc_cleanup' since the function is absent from the function call allow list. When an application using libunbound sets 'unwanted-reply-threshold' to any non-zero value and the iterator queries an authoritative that replies with enough wrong-transaction-ID UDP datagrams to cross the threshold, the 'libworker_alloc_cleanup' will eventually be called. Since the function is absent from the function call allow list, this leads to a fatal exit of libunbound and eventual termination of the embedding application.Unbound itself is not affected since its relevant function 'worker_alloc_cleanup' is registed in the allow list and proceeds to perform the documented cache flush. Join the discussion | CVE Database V5 | 07/22/2026, 13:06:28 UTC Added: 07/22/2026, 13:22:41 UTC |
CVE-2026-21764: CWE-754: Improper Check for Unusual or Exceptional Conditions in HCLSoftware DevOps LoopCVE-2026-21764 0 HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restricted. This may result in unintended application behavior under certain conditions. Join the discussion | CVE Database V5 | 07/17/2026, 17:11:01 UTC Added: 07/18/2026, 11:08:38 UTC |
CVE-2026-57031: CWE-754 Improper Check for Unusual or Exceptional Conditions in Juniper Networks Junos OSCVE-2026-57031 0 An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series allows adjacent subscribers to bypass configured firewall filters. On MX Series devices with MPC10/11, LC4800/9600, and MX304 with subscribers configured on static interfaces, ingress firewall filters are not enforced, so that neither protocol level nor upstream bandwidth limitation are in effect. This issue affects Junos OS on MX with MPC10/11, LC4800/9600/4802, and MX304: * 23.2 versions from 23.2R2-S1 before 23.2R2-S7, * 23.4 versions from 23.4R2 before 23.4R2-S7, * 24.2 versions before 24.2R2-S3, * 24.4 versions before 24.4R2-S2, * 25.2 versions before 25.2R2. Join the discussion | CVE Database V5 | 07/09/2026, 21:13:46 UTC Added: 07/09/2026, 21:48:08 UTC |
CVE-2026-57022: CWE-754 Improper Check for Unusual or Exceptional Conditions in Juniper Networks Junos OSCVE-2026-57022 0 An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When an affected device initiates a TCP connection to an attacker-controlled system that responds with a specific packet, this causes a PFE crash and restart, which affects all services until the system has automatically recovered. This issue can happen among others in the following scenarios: ALG, SSL proxy, UTM, RTLOG, AppQoE probing, AAMW, ICAP, URL filtering. This issue affects Junos OS on MX Series with SPC3, SRX5k Series with SPC3, SRX1600 Series, SRX2300 Series, SRX4000 Series, and vSRX Series: * all versions before 23.2R2-S4, * 23.4 versions before 23.4R2-S5, * 24.2 versions before 24.2R2. Join the discussion | CVE Database V5 | 07/09/2026, 21:06:06 UTC Added: 07/09/2026, 21:48:06 UTC |
CVE-2026-57020: CWE-754 Improper Check for Unusual or Exceptional Conditions in Juniper Networks Junos OSCVE-2026-57020 0 An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on QFX10000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). On all QFX10000 platforms in an EVPN-VxLAN scenario, if an attacker sends IPv6 multicast traffic and these packets reach the non-IRB interface of a spine switch it floods the packet to other spines and all Ethernet Segment Identifier (ESI) leaf switches. This flooding causes the packet to be forwarded in a endless loop, which can lead to saturation of the involved links and in turn impact to legitimate traffic. This issue affects Junos OS on QFX10000 Series: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S4. This issue does not affect Junos version after 24.4 as the QFX10000 Series devices are not supported on newer versions anymore. Join the discussion | CVE Database V5 | 07/09/2026, 21:05:07 UTC Added: 07/09/2026, 21:48:04 UTC |
CVE-2026-33801: CWE-754 Improper Check for Unusual or Exceptional Conditions in Juniper Networks Junos OSCVE-2026-33801 0 An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker sending a specific BGP update over an established BGP session to cause a Denial-of-Service (DoS). Upon receipt of a specifically malformed non-inet/inet6 unicast BGP update, an RPD crash and restart is triggered, which will cause a complete service outage until routing has reconverged. The rpd crash occurs before the update can be readvertised, so there is no downstream propagation. This issue affects: * Junos OS versions 25.2 before 25.2R2; * Junos OS Evolved versions 25.2 before 25.2R2-EVO. This issue doesn't affect Junos OS versions before 25.2R1 nor Junos OS Evolved versions before 25.2R1-EVO. Join the discussion | CVE Database V5 | 07/09/2026, 21:03:24 UTC Added: 07/09/2026, 21:18:21 UTC |
CVE-2026-33794: CWE-754 Improper Check for Unusual or Exceptional Conditions in Juniper Networks Junos OS EvolvedCVE-2026-33794 0 An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker generating continuous routing updates, resulting in unilist ECMP routes, to crash the evo-aftmand process on the PFE, leading to a Denial-of-Service (DoS). The conditions required for successful exploitation are based on a sequence of events that are outside an attacker's direct control. Unified list (unilist) ECMP routes are a specific ECMP behavior where multiple equal-cost routes share a single logical next-hop list entry. The router treats them as one route with multiple next hops and load balances traffic across that unified list. Due to an issue processing unilist ECMP routing updates, internal state corruption may occur, especially in large-scale ECMP unilist deployments, leading to the evo-aftmand process crashing, resulting in an evo-aftmand-bx core. Manual intervention is required to recover by rebooting the system or restarting the FPC. This issue affects Junos OS Evolved on PTX : * from 24.4R2-EVO before 24.4R2-S3-EVO; * from 25.2 before 25.2R2-EVO. Join the discussion | CVE Database V5 | 07/09/2026, 21:02:05 UTC Added: 07/09/2026, 21:18:21 UTC |
Showing 1 to 10 of 11 results