iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized attacker to elevate pri
Smart contract Marginal v1 performs unsafe downcast, allowing attackers to settle a large debt position for a negligible
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below ha
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between n
In the Linux kernel, the following vulnerability has been resolved: RDMA/umem: Fix truncation for block sizes >= 4G Wh
dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the
Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local att
su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t an
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to hand
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malfor
vLLM is an inference and serving engine for large language models (LLMs). From 0.5.5 until 0.23.1rc0, integer truncation
A floating-point exception (FPE) in the flow.column_stack component of OneFlow v0.9.0 allows attackers to cause a Denial
Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler conta
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and inclu
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, t
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, t
The leancrypto library is a cryptographic library that exclusively contains only PQC-resistant cryptographic algorithms.
FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packetizer (libavformat/r
A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method p
A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size
There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in Co
GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the b
Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code loca
Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to ele
CoreDNS is a DNS server that chains plugins. Starting in version 1.2.0 and prior to version 1.12.4, the CoreDNS etcd plu
In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library,
Microsoft ODBC Driver Remote Code Execution Vulnerability
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This
DHCP Server Service Remote Code Execution Vulnerability
Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin
The Wallet for WooCommerce plugin for WordPress is vulnerable to incorrect conversion between numeric types in all versi
Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. Starting in version 0.3.8 and prior to ver
Windows Bluetooth Driver Elevation of Privilege Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Soft
Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Reques
An integer conversion vulnerability exists in the SORBAx64.dll RecvPacket functionality of WellinTech KingHistorian 35.0
Microsoft Office Visio Remote Code Execution Vulnerability
Windows Media Remote Code Execution Vulnerability
NTFS Elevation of Privilege Vulnerability
Two potential signed to unsigned conversion errors and buffer overflow vulnerabilities at the following locations in the
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where sign conversion issuescasti
Frequently Asked Questions
What is CWE-681?
CWE-681 (CWE-681) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-681?
There are 147 CVE records associated with CWE-681 in our database. Of these, 8 are critical severity, 71 are high severity, and 38 are medium severity.
How can I protect against CWE-681 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-681 using AI-powered security agents.
Detect CWE-681 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-681 vulnerabilities across your infrastructure.
Get Started