Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-681

MITRE ↗

CWE-681

8
CRITICAL
71
HIGH
38
MEDIUM
4
LOW
122 CVEs · Page 1/3
8.8
CVE-2026-21688

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio

8.8
CVE-2026-21693

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio

8.8
CVE-2026-26178

Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized attacker to elevate pri

8.6
CVE-2026-4931

Smart contract Marginal v1 performs unsafe downcast, allowing attackers to settle a large debt position for a negligible

7.8
CVE-2026-21673

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below ha

7.8
CVE-2026-24856

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color

7.8
CVE-2026-24192

NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between n

7.8
CVE-2026-53133

In the Linux kernel, the following vulnerability has been resolved: RDMA/umem: Fix truncation for block sizes >= 4G Wh

7.8
CVE-2026-45258

dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the

7.8
CVE-2026-50402

Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-55123

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-21069

Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local att

7.8
CVE-2026-82457

su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t an

7.5
CVE-2026-25989

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1

7.5
CVE-2026-4602

Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to hand

7.5
CVE-2026-24174

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malfor

7.5
CVE-2026-53923

vLLM is an inference and serving engine for large language models (LLMs). From 0.5.5 until 0.23.1rc0, integer truncation

6.5
CVE-2025-71002

A floating-point exception (FPE) in the flow.column_stack component of OneFlow v0.9.0 allows attackers to cause a Denial

6.5
CVE-2026-34945

Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler conta

6.5
CVE-2026-53466

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-

6.2
CVE-2026-27691

iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and inclu

6.2
CVE-2026-34548

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, t

6.2
CVE-2026-34550

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, t

5.9
CVE-2026-34610

The leancrypto library is a cryptographic library that exclusively contains only PQC-resistant cryptographic algorithms.

5.8
CVE-2026-75145

FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packetizer (libavformat/r

5.3
CVE-2026-19879

A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method p

4.4
CVE-2026-6426

A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size

3.7
CVE-2026-9143

There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in Co

CVE-2026-55768

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the b

8.4
CVE-2025-53733

Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code loca

7.8
CVE-2025-24059

Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to ele

7.1
CVE-2025-58063

CoreDNS is a DNS server that chains plugins. Starting in version 1.2.0 and prior to version 1.12.4, the CoreDNS etcd plu

5.3
CVE-2025-10543

In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library,

8.8
CVE-2024-26162

Microsoft ODBC Driver Remote Code Execution Vulnerability

8.8
CVE-2024-49093

Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

7.5
CVE-2024-1552

Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This

7.2
CVE-2024-38044

DHCP Server Service Remote Code Execution Vulnerability

6.7
CVE-2023-28063

Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin

6.5
CVE-2024-7747

The Wallet for WooCommerce plugin for WordPress is vulnerable to incorrect conversion between numeric types in all versi

5.3
CVE-2024-32481

Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. Starting in version 0.3.8 and prior to ver

8.8
CVE-2023-23388

Windows Bluetooth Driver Elevation of Privilege Vulnerability

8.8
CVE-2023-24884

Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability

8.6
CVE-2023-20006

A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Soft

8.6
CVE-2023-46848

Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Reques

8.1
CVE-2022-43663

An integer conversion vulnerability exists in the SORBAx64.dll RecvPacket functionality of WellinTech KingHistorian 35.0

7.8
CVE-2023-21736

Microsoft Office Visio Remote Code Execution Vulnerability

7.8
CVE-2023-23401

Windows Media Remote Code Execution Vulnerability

7.8
CVE-2023-29346

NTFS Elevation of Privilege Vulnerability

7.0
CVE-2023-5184

Two potential signed to unsigned conversion errors and buffer overflow vulnerabilities at the following locations in the

6.7
CVE-2023-0185

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where sign conversion issuescasti

Frequently Asked Questions

What is CWE-681?

CWE-681 (CWE-681) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-681?

There are 147 CVE records associated with CWE-681 in our database. Of these, 8 are critical severity, 71 are high severity, and 38 are medium severity.

How can I protect against CWE-681 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-681 using AI-powered security agents.

Detect CWE-681 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-681 vulnerabilities across your infrastructure.

Get Started