The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up t
A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arb
A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arb
An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor
psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file conta
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker wi
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below ha
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.10.0, the STUN/TURN attribute parsing fu
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafte
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0
An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory address can lead to une
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the
A floating-point exception (FPE) in the flow.column_stack component of OneFlow v0.9.0 allows attackers to cause a Denial
An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compo
Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may have unspecified impact.
apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, DiscoverKey
vLLM is an inference and serving engine for large language models (LLMs). From 0.18.0 to before 0.20.0, the extract_hidd
Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer parsing vulnerability th
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's UDR nudr-dr DELETE /subscript
There is an unchecked enum cast vulnerability in NI grpc-device BeginSidebandStream that may allow an attacker to trigge
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate WebSocket command field ty
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 h
cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the proc
unbounded_spsc is an "unbounded" extension of bounded_spsc_queue. In versions 0.2.0 and prior, sender::send pointer-as-v
Logging Redactor is a Python library designed to redact sensitive data in logs based on regex patterns and / or dictiona
When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and lin
Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session wi
rsync before 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that al
The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose ki
Frequently Asked Questions
What is CWE-704?
CWE-704 (CWE-704) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-704?
There are 35 CVE records associated with CWE-704 in our database. Of these, 5 are critical severity, 12 are high severity, and 17 are medium severity.
How can I protect against CWE-704 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-704 using AI-powered security agents.
Detect CWE-704 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-704 vulnerabilities across your infrastructure.
Get Started