VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and ha
Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon version 4.4, support for verifia
In http-proxy-middleware before 2.0.9 and 3.x before 3.0.5, fixRequestBody proceeds even if bodyParser has failed.
Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regardin
Improper conditions check for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticat
Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore Technology 4 allows Input Data
Improper conditions check for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications
Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker
In EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web interface. NOTE: the Supp
In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid bac
7-Zip 22.01 does not report an error for certain invalid xz files, involving block flags and reserved bits. Some later v
7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later
Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix S
Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix S
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with W
A Denial of Service (DoS) vulnerability in Palo Alto Networks PAN-OS software causes the firewall to unexpectedly reboot
A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authentication feature of P
An improper exception check in Palo Alto Networks Prisma Access Browser allows a low privileged user to prevent Prisma A
ethereum is a common ethereum structs for Rust. Prior to ethereum crate v0.18.0, signature malleability (according to EI
Solady is software that provides Solidity snippets with APIs. Starting in version 0.0.125 and prior to version 0.1.24, w
Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. The extrinsic note_min_gas_pric
The sequence of packets received by a Networking server are not correctly checked. An attacker could exploit this vulne
In Content Management versions 20.4- 25.3 authenticated attackers may exploit a complex cache poisoning technique to dow
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th
Volto is a ReactJS-based frontend for the Plone Content Management System. Versions 16.34.0 and below, 17.0.0 through 17
A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reb
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. When the ESP32 is in advertising mode, if it re
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to improper missing encryption exception handling o
Improper Check for Unusual or Exceptional Conditions vulnerability in Webroot SecureAnywhere - Web Shield on Windows, AR
Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication
In the Linux kernel, the following vulnerability has been resolved: tipc: Return non-zero value from tipc_udp_addr2str(
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins contr
go-spacemesh is a Go implementation of the Spacemesh protocol full node. Nodes can publish activations transactions (ATX
Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate emai
The AppPresser plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'decrypt_valu
LNbits is a Lightning wallet and accounts system. Paying invoices in Eclair that do not get settled within the internal
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix wild memory access when clea
In the Linux kernel, the following vulnerability has been resolved: tee: optee: Fix kernel panic caused by incorrect er
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Confirm list is non-empty before utiliz
Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26), As the communication buffer size hasn’t been properly validated to b
In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Sanitise num_phys Information is sto
In the Linux kernel, the following vulnerability has been resolved: f2fs: check validation of fault attrs in f2fs_build
In the Linux kernel, the following vulnerability has been resolved: gve: Account for stopped queues when reading NIC st
In the Linux kernel, the following vulnerability has been resolved: x86/tdx: Fix "in-kernel MMIO" check TDX only suppo
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on node blkaddr in tru
An Improper Check for Unusual or Exceptional Conditions vulnerability in Routing Protocol Daemon (RPD) of Juniper Netwo
AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated us
AnythingLLM is an application that turns any document, resource, or piece of content into context that any LLM can use a
Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number
Frequently Asked Questions
What is CWE-754?
CWE-754 (CWE-754) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-754?
There are 772 CVE records associated with CWE-754 in our database. Of these, 20 are critical severity, 245 are high severity, and 287 are medium severity.
How can I protect against CWE-754 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-754 using AI-powered security agents.
Detect CWE-754 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-754 vulnerabilities across your infrastructure.
Get Started