A flaw was found in curl before version 7.51. If cookie state is written into a cookie jar file that is later read back
phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request.
An issue was discovered in Pivotal GemFire for PCF 1.6.x versions prior to 1.6.5 and 1.7.x versions prior to 1.7.1. The
Unauthenticated messages processed by the UE. Certain NAS messages are processed when no EPS security context exists in
The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean
An issue was discovered on the D-Link DWR-932B router. HELODBG on port 39889 (UDP) launches the "/sbin/telnetd -l /bin/s
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "WebSheet" compon
web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker
IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force
In all Qualcomm products with Android releases from CAF using the Linux kernel, a UE can respond to a UEInformationReque
WAGO IO 750-849 01.01.27 and WAGO IO 750-881 01.02.05 do not contain privilege separation.
The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary toke
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. `www/delivery/asyncspc.php` was vulnerable
The content renderer client in Google Chrome prior to 54.0.2840.85 for Android insufficiently enforced the Same Origin P
The management interface on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V
Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file,
A spoofing vulnerability in the Core of BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote attackers to
Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote attackers to obtain sensitive informatio
Tor Browser Launcher (aka torbrowser-launcher) before 0.2.4, during the initial run, allows man-in-the-middle attackers
ASA 5515-X Adaptive Security Appliance Adaptive Security Appliance (ASA) Software 9.4.x before 9.4.1 Interim, 9.2.x befo
The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain ac
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS b
Huawei Honor 6, Honor 6 Plus, Honor 7 phones with software versions earlier than 6.9.16 could allow attackers to disable
The Grandstream Wave app 1.0.1.26 and earlier for Android does not use HTTPS when retrieving update information, which m
The Bzrtp library (aka libbzrtp) 1.0.x before 1.0.4 allows man-in-the-middle attackers to conduct spoofing attacks by le
main/java/org/apache/directory/groovyldap/LDAP.java in the Groovy LDAP API in Apache allows attackers to conduct LDAP en
An issue was discovered on the D-Link DWR-932B router. A secure_mode=no line exists in /var/miniupnpd.conf.
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Mail" component,
Detection bypass vulnerability in Intel Security Advanced Threat Defense (ATD) 3.4.6 and earlier allows malware samples
Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node di
OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 does not use SSL pinning.
OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 does not use SSL pinning.
Blue Coat Advanced Secure Gateway 6.6, CacheFlow 3.4, ProxySG 6.5 and 6.6 allows remote attackers to bypass blocked requ
IBM QRadar 7.2 and 7.3 does not require that users should have strong passwords by default, which makes it easier for at
NetApp Data ONTAP 8.1 and 8.2, when operating in 7-Mode, allows man-in-the-middle attackers to obtain sensitive informat
NetApp Clustered Data ONTAP allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or caus
Alcatel-Lucent Home Device Manager before 4.1.10, 4.2.x before 4.2.2 allows remote attackers to spoof and make calls as
OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used u
networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent
The Script Security plugin before 1.18.1 in Jenkins might allow remote attackers to bypass a Groovy sandbox protection m
An issue was discovered in Sauter NovaWeb web HMI. The application uses a protection mechanism that relies on the existe
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "SpringBoard" com
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Local Authentica
Huawei UAP2105 before V300R012C00SPC160(BootRom) does not require authentication to the serial port or the VxWorks shell
The mcollective-puppet-agent plugin before 1.11.1 for Puppet allows remote attackers to execute arbitrary code via vecto
NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to con
Yandex Browser for desktop before 17.1.1.227 does not show Protect (similar to Safebrowsing in Chromium) warnings in web
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI). Supported versions tha
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent
Frequently Asked Questions
What is CWE-254?
CWE-254 (CWE-254) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-254?
There are 414 CVE records associated with CWE-254 in our database. Of these, 17 are critical severity, 49 are high severity, and 63 are medium severity.
How can I protect against CWE-254 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-254 using AI-powered security agents.
Detect CWE-254 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-254 vulnerabilities across your infrastructure.
Get Started