Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-754'

View all threats tagged with 'cwe-754'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-754

Threats Tagged 'cwe-754'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-54269: CWE-674: Uncontrolled Recursion in protobufjs protobuf.jsCVE-2026-54269
0

protobuf.js versions prior to 8.6.0 and 7.6.3 contain a vulnerability where certain schema-derived names can collide with internal runtime helper properties. This can cause uncontrolled recursion or deterministic exceptions during decoding, verification, object conversion, JSON serialization, or RPC helper invocation. The issue arises from accepting field or service method names like hasOwnProperty, $type, or rpcCall that interfere with protobufjs internals. This vulnerability has a medium severity score of 5.3 and is fixed in versions 8.6.0 and 7.6.3.

Join the discussion
CVE-2026-0269: CWE-754: Improper Check for Unusual or Exceptional Conditions in Palo Alto Networks Cloud NGFWCVE-2026-0269
0

A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

Join the discussion
CVE-2026-46541: CWE-754: Improper Check for Unusual or Exceptional Conditions in nimiq core-rs-albatrossCVE-2026-46541
0

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, iIn handle_dht_get(), the DhtResults accumulator is only initialized when the first DHT record passes verification. If the first record fails (from a malicious DHT node), DhtResults is never created, and all subsequent valid records are discarded with "DHT inconsistent state" errors. This issue has been patched in version 1.4.0.

Join the discussion
CVE-2026-45678: CWE-20: Improper Input Validation in open-telemetry opentelemetry-ebpf-instrumentationCVE-2026-45678
0

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Postgres protocol parser assumes BIND message payloads contain a valid NUL-terminated portal name. A crafted empty or unterminated payload can make OBI slice beyond the end of the captured buffer and panic. This issue has been patched in version 0.9.0.

Join the discussion
CVE-2026-49325: CWE-1384 Improper Handling of Physical or Environmental Conditions in Indian Motorcycle (Polaris Inc.) Scout Bobber + TechCVE-2026-49325
0

Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows a physical attacker with access to the Wireless Control Module (WCM) wiring harness to bypass the anti-theft shutdown. The WCM signals shutdown to a peer ECU via a falling-edge voltage transition on a dedicated wire pair. The receiving ECU does not distinguish between an active shutdown pulse and an open-circuit / disconnected condition; interrupting the relevant wires leaves the motorcycle fully operable even though the WCM never validated the rider's PIN. Specific connector details have been withheld pending vendor remediation.

Join the discussion
CVE-2026-49318: CWE-696 Incorrect Behavior Order in Indian Motorcycle (Polaris Inc.) Scout Bobber + TechCVE-2026-49318
0

Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a proxy for whether an immobilizer is fitted; if no WCM messages are observed, it skips the PIN entry screen and shows the normal user interface. An attacker who silences the WCM during the boot window — for example via a separately tracked CAN bus-off technique — can present a fully unlocked Infotainment despite the PIN never being entered. Specific timing and protocol details have been withheld pending vendor remediation.

Join the discussion
CVE-2026-49317: CWE-696 Incorrect Behavior Order in Indian Motorcycle (Polaris Inc.) Scout Bobber + TechCVE-2026-49317
0

Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a proxy for whether an immobilizer is fitted; if no WCM messages are observed, it skips the PIN entry screen and shows the normal user interface. An attacker who silences the WCM during the boot window — for example via a separately tracked CAN bus-off technique — can present a fully unlocked Infotainment despite the PIN never being entered. Specific timing and protocol details have been withheld pending vendor remediation.

Join the discussion
CVE-2026-49316: CWE-440 Expected Behavior Violation in Indian Motorcycle (Polaris Inc.) Scout Bobber + TechCVE-2026-49316
0

Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the motorcycle's anti-theft shutdown by forcing the Wireless Control Module (WCM) into the CAN bus-off state. Using a well-known CAN error-frame injection technique against a periodic WCM transmission, the attacker drives the WCM CAN controller's transmit error counter past the bus-off threshold, after which the WCM stops transmitting all messages, including the shutdown command. Peer ECUs do not interpret WCM silence as a security event and continue normal operation, allowing the motorcycle to be operated despite the immobilizer never having been unlocked. Specific protocol details have been withheld pending vendor remediation.

Join the discussion
CVE-2026-5343: CWE-754 Improper Check for Unusual or Exceptional Conditions in Drupal SAML SSO - Service ProviderCVE-2026-5343
0

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Privilege Escalation. This issue affects SAML SSO - Service Provider: from 0.0.0 before 3.1.4.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Tag: cwe-754
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses