LibreChat is a ChatGPT clone with additional features. Prior to 0.8.3-rc1, a Denial of Service (DoS) vulnerability exist
ZEBRA is a Zcash node written entirely in Rust. From zebrad versions 2.2.0 to before 4.3.1 and from zebra-rpc versions 1
FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.2, authorized clients have t
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,
SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics whe
SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY r
SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code
SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing quer
SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls
SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or names
SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated
Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an attacker authenticated to an enabled Zebra RPC endpoi
Uncaught exception in the firmware for some 100GbE Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x withi
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
Granian is a Rust HTTP server for Python applications. From 0.2.0 to 2.7.4, Granian aborts a worker process if a WSGI ap
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious block producer can terminate zebrad by placi
Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthentica
Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, On x86-64 platforms with SSE3 disabl
The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs co
Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "
IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0
Starlette-Admin is a fast, beautiful and extensible administrative interface framework for FastAPI and Starlette applica
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada
A vulnerability in the HTML Cascading Style Sheets (CSS) module of ClamAV could allow an unauthenticated, remote attacke
Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, u
A vulnerability has been found in aligungr UERANSIM up to 3.2.7. The affected element is the function rls::DecodeRlsMess
NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-component static asse
Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of b
webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends eit
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX
joi is a schema description language and data validator for JavaScript. Prior to 17.13.4 and 18.2.1, denial of service i
rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a
### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a t
SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owne
A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script w
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.5, a Deno program that opens a client WebSocket
Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malf
CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreD
Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by
Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated
An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated
Kanidm is an identity management platform. Prior to version 1.9.3, a single unauthenticated GET to any /scim/v1/... endp
Pion DTLS is a Go implementation of Datagram Transport Layer Security. Versions prior to 3.1.4 are vulnerable to Remote
NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's .NET single-f
Uncaught exception for some Intel(R) TDX modules within Ring 0: Trust Domain may allow a denial of service. System softw
The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose ki
actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a
Frequently Asked Questions
What is CWE-248?
CWE-248 (CWE-248) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-248?
There are 271 CVE records associated with CWE-248 in our database. Of these, 3 are critical severity, 125 are high severity, and 112 are medium severity.
How can I protect against CWE-248 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-248 using AI-powered security agents.
Detect CWE-248 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-248 vulnerabilities across your infrastructure.
Get Started