Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-248

MITRE ↗

CWE-248

3
CRITICAL
125
HIGH
112
MEDIUM
5
LOW
265 CVEs · Page 3/6
CVE-2026-23938

An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/sc

CVE-2026-52738

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a consensus-valid block containing a long chain of trans

CVE-2026-53530

RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, the public parser entrypoint

CVE-2026-63403

Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the server is vulnerable to an unauth

7.7
CVE-2025-20171

A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remo

7.7
CVE-2025-20172

A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allo

7.7
CVE-2025-20173

A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remo

7.7
CVE-2025-20176

A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remo

7.7
CVE-2025-47281

Kyverno is a policy engine designed for cloud native platform engineering teams. In versions 1.14.1 and below, a Denial

7.5
CVE-2025-20637

In network HW, there is a possible system hang due to an uncaught exception. This could lead to remote denial of service

7.5
CVE-2024-11172

A vulnerability in danny-avila/librechat version git a1647d7 allows an unauthenticated attacker to cause a denial of ser

7.5
CVE-2024-8020

A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sendi

7.5
CVE-2024-8249

mintplex-labs/anything-llm version git 6dc3642 contains an unauthenticated Denial of Service (DoS) vulnerability in the

7.5
CVE-2025-3083

Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur

7.5
CVE-2024-58111

Exception capture failure vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation

7.5
CVE-2024-58112

Exception capture failure vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation

7.5
CVE-2025-20663

In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This could lead to remote (p

7.5
CVE-2025-20664

In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This could lead to remote (p

7.5
CVE-2025-3891

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to

7.5
CVE-2025-23166

The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executi

7.5
CVE-2025-47944

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1

7.5
CVE-2025-29785

quic-go is an implementation of the QUIC protocol in Go. The loss recovery logic for path probe packets that was added i

7.5
CVE-2025-7338

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1

7.5
CVE-2013-10065

A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A specially crafted SSH

7.5
CVE-2025-55553

A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).

7.5
CVE-2025-55557

A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading

7.5
CVE-2025-59538

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. For versions 2.9.0-rc1 through 2.14.19, 3.0.0-

7.5
CVE-2025-62370

Alloy Core libraries at the root of the Rust Ethereum ecosystem. Prior to 0.8.26 and 1.4.1, an uncaught panic triggered

7.5
CVE-2025-12423

Protocol manipulation might lead to denial of service.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.

7.1
CVE-2025-24836

With a specially crafted Python script, an attacker could send continuous startMeasurement commands over an unencrypted

7.1
CVE-2025-44019

AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated

6.5
CVE-2024-11173

An unhandled exception in the danny-avila/librechat repository, version git 600d217, can cause the server to crash, lead

6.5
CVE-2024-49705

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to client-side Denial of Servise (DoS) attacks. A

6.5
CVE-2025-32944

The vulnerability allows any authenticated user to cause the PeerTube server to stop functioning in a persistent manner.

6.5
CVE-2025-20054

Uncaught exception in the core management mechanism for some Intel(R) Processors may allow an authenticated user to pote

6.5
CVE-2025-48942

vLLM is an inference and serving engine for large language models (LLMs). In versions 0.8.0 up to but excluding 0.9.0, h

6.5
CVE-2025-48943

vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a

6.5
CVE-2025-36539

AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticate

6.5
CVE-2025-54134

HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the

6.5
CVE-2025-59462

An attacker who tampers with the C++ CLI client may crash the UpdateService during file transfers, disrupting updates an

6.2
CVE-2025-48907

Deserialization vulnerability in the IPC module Impact: Successful exploitation of this vulnerability may affect availab

6.0
CVE-2025-66578

xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Versions 3.1.3 contain an authent

5.7
CVE-2025-55194

Part-DB is an open source inventory management system for electronic components. Prior to version 1.17.3, any authentica

5.5
CVE-2025-0158

IBM EntireX 11.1 could allow a local user to cause a denial of service due to an unhandled error and fault isolation.

5.5
CVE-2025-59229

Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally.

5.5
CVE-2025-48430

Uncaught Exception (CWE-248) in the Command Centre Server allows an Authorized and Privileged Operator to crash the Comm

5.3
CVE-2024-56946

Denial of service in DNS-over-QUIC in Technitium DNS Server <= v13.2.2 allows remote attackers to permanently stop the s

5.3
CVE-2024-52903

IBM Db2 for Linux, UNIX and Windows 12.1.0 and 12.1.1 is vulnerable to a denial of service as the server may crash under

5.3
CVE-2025-35436

CISA Thorium uses '.unwrap()' to handle errors related to account verification email messages. An unauthenticated remote

5.3
CVE-2025-20753

In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if

Frequently Asked Questions

What is CWE-248?

CWE-248 (CWE-248) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-248?

There are 271 CVE records associated with CWE-248 in our database. Of these, 3 are critical severity, 125 are high severity, and 112 are medium severity.

How can I protect against CWE-248 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-248 using AI-powered security agents.

Detect CWE-248 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-248 vulnerabilities across your infrastructure.

Get Started