Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets w
Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session wi
Russh is a Rust SSH client & server library. Prior to 0.62.4, an unauthenticated SSH client can cause a denial of servic
Admidio is an open-source user management solution. Prior to version 5.0.9, Role::stopMembership() does not verify wheth
Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denia
A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to b
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper N
DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element originates from a diffe
Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allow
Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025
The printenv utility in uutils coreutils fails to display environment variables containing invalid UTF-8 byte sequences.
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to prevent rendering
Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-
ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to validate the response body of proxie
nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and prior, network
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vuln
Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View Permissions allows Forceful Brows
SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this
Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from closing an underlying
Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 3: User Applications may allow an e
Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Improper Check for Unusual or Exceptional Condi
A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This imp
A security issue was discovered in ingress-nginx where the protection afforded by the `auth-url` Ingress annotation may
HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restric
Improper conditions check in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Devic
Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 m
Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 m
Mattermost Plugins versions <=11.4 10.11.11.0 fail to validate webhook request timestamps which allows an attacker to co
A vulnerability in the Pix-Link LV-WR21Q router's language module allows remote attackers to trigger a denial of service
A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® softwa
rssn is a scientific computing library for Rust, combining a high-performance symbolic computation engine with numerical
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator t
An unauthenticated remote attacker is able to exhaust all available TCP connections in the CODESYS EtherNet/IP adapter s
Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denia
Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is an unauthenticated denial-of
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the PayPalEmail payment
CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, d
Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability
Improper conditions check for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a deni
Improper conditions check in the firmware for the Intel(R) NPU Driver for all versions within Ring 1: Device Drivers may
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crat
This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DL
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.h
In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix handling of server side tls alerts Sco
In VerifyNoOverlapInSessions of apexd.cpp, there is a possible way to block security updates due to a logic error in the
Improper check for unusual or exceptional conditions in the Linux kernel-mode driver for some Intel(R) 800 Series Ethern
Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM dur
A specific flaw exists within the Bluetooth stack of the MIB3 infotainment system. The issue results from the disabled a
Frequently Asked Questions
What is CWE-754?
CWE-754 (CWE-754) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-754?
There are 772 CVE records associated with CWE-754 in our database. Of these, 20 are critical severity, 245 are high severity, and 287 are medium severity.
How can I protect against CWE-754 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-754 using AI-powered security agents.
Detect CWE-754 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-754 vulnerabilities across your infrastructure.
Get Started