Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-248

MITRE ↗

CWE-248

3
CRITICAL
125
HIGH
112
MEDIUM
5
LOW
265 CVEs · Page 4/6
5.3
CVE-2025-20754

In Modem, there is a possible system crash due to an incorrect bounds check. This could lead to remote denial of service

4.9
CVE-2025-0648

Unexpected server crash in database driver in M-Files Server before 25.1.14445.5 and before 24.8 LTS SR3 allows a highl

4.9
CVE-2025-8870

On affected platforms running Arista EOS, certain serial console input might result in an unexpected reload of the devic

4.9
CVE-2025-66305

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Denial of Service (DoS) vulnerability was identified in the

4.9
CVE-2025-20758

In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if

4.6
CVE-2024-13417

Specifically crafted payloads sent to the RFID reader could cause DoS of RFID reader. After the device is restarted, it

4.3
CVE-2025-20097

Uncaught exception in OpenBMC Firmware for the Intel(R) Server M50FCP Family and Intel(R) Server D50DNP Family before ve

4.3
CVE-2025-54777

Uncaught exception issue exists in Multiple products in bizhub series. If a malformed file is imported as an S/MIME Emai

2.7
CVE-2025-59014

An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 l

CVE-2025-24883

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced

CVE-2025-43855

tRPC allows users to build & consume fully typesafe APIs without schemas or code generation. In versions starting from 1

CVE-2025-48997

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1

CVE-2025-53365

The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to versi

CVE-2025-53366

The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to versi

CVE-2025-53620

@builder.io/qwik-city is the meta-framework for Qwik. When a Qwik Server Action QRL is executed it dynamically load the

CVE-2025-9124

A denial-of-service security issue in the affected product. The security issue stems from a fault occurring when a craft

CVE-2025-0657

A weakness in Automated Logic and Carrier i-Vu Gen5 router on driver version drv_gen5_106-01-2380, allows malformed

9.3
CVE-2024-42037

Vulnerability of uncaught exceptions in the Graphics module Impact: Successful exploitation of this vulnerability may af

8.6
CVE-2024-43357

ECMA-262 is the language specification for the scripting language ECMAScript. A problem in the ECMAScript (JavaScript) s

7.5
CVE-2024-23325

Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that i

7.5
CVE-2023-3966

A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a

7.5
CVE-2023-52342

In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote

7.5
CVE-2024-3051

Malformed Device Reset Locally command classes can be sent to temporarily deny service to an end device. Any frames sent

7.5
CVE-2024-3052

Malformed S2 Nonce Get command classes can be sent to crash the gateway. A hard reset is required to recover the gateway

7.5
CVE-2024-34363

Envoy is a cloud-native, open source edge and service proxy. Due to how Envoy invoked the nlohmann JSON library, the lib

7.5
CVE-2023-5038

badmonkey, a Security Researcher has found a flaw that allows for a unauthenticated DoS attack on the camera. An attacke

7.5
CVE-2024-38525

dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malforme

7.5
CVE-2024-43367

Boa is an embeddable and experimental Javascript engine written in Rust. Starting in version 0.16 and prior to version 0

7.5
CVE-2024-20137

In wlan driver, there is a possible client disconnection due to improper handling of exceptional conditions. This could

7.4
CVE-2024-20276

A vulnerability in Cisco IOS Software for Cisco Catalyst 6000 Series Switches could allow an unauthenticated, adjacent a

7.2
CVE-2021-33145

Uncaught exception in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may a

7.1
CVE-2024-54106

Null pointer dereference vulnerability in the image decoding module Impact: Successful exploitation of this vulnerabilit

6.5
CVE-2024-0754

Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.

6.5
CVE-2023-27318

StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.13 are susceptible to a Denial of Service (D

6.5
CVE-2024-21983

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 are susceptible to a Denial of Service (DoS) vulnera

6.5
CVE-2023-6533

Malformed Device Reset Locally Command Class packets can be sent to the controller, causing the controller to assume the

6.5
CVE-2023-6640

Malformed S2 Nonce Get Command Class packets can be sent to crash PC Controller v5.54.0 and earlier.

6.5
CVE-2024-31904

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 integration nodes could allow an au

6.5
CVE-2024-33848

Uncaught exception in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially ena

6.2
CVE-2024-20048

In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information

6.2
CVE-2024-32995

Denial of service (DoS) vulnerability in the AMS module Impact: Successful exploitation of this vulnerability will affec

5.5
CVE-2024-29076

Uncaught exception for some Intel(R) CST software before version 8.7.10803 may allow an authenticated user to potentiall

5.3
CVE-2024-31217

Strapi is an open-source content management system. Prior to version 4.22.0, a denial-of-service vulnerability is presen

5.3
CVE-2024-51518

Vulnerability of message types not being verified in the advanced messaging modul Impact: Successful exploitation of thi

5.3
CVE-2024-11738

A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmente

5.0
CVE-2024-28835

A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially cra

5.0
CVE-2024-51750

Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over f

4.4
CVE-2024-20049

In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information

4.3
CVE-2023-26586

Uncaught exception for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may al

4.3
CVE-2024-23449

An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment pro

Frequently Asked Questions

What is CWE-248?

CWE-248 (CWE-248) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-248?

There are 271 CVE records associated with CWE-248 in our database. Of these, 3 are critical severity, 125 are high severity, and 112 are medium severity.

How can I protect against CWE-248 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-248 using AI-powered security agents.

Detect CWE-248 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-248 vulnerabilities across your infrastructure.

Get Started