Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Feathers socke
The json2xml package through 3.12.0 for Python allows an error in typecode decoding enabling a remote attack that can le
When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then
Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.sta
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper
The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that us
Vulnerability of uncaught exceptions in the NFC module. Successful exploitation of this vulnerability can affect NFC ava
Vulnerability of data verification errors in the kernel module. Successful exploitation of this vulnerability may cause
An Improper Check for Unusual or Exceptional Conditions vulnerability in the bbe-smgd of Juniper Networks Junos OS allow
socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol
A lack of exception handling in the Volkswagen Discover Media Infotainment System Software Version 0876 allows attackers
Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS Thre
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected software does not correctl
msgpackr is a fast MessagePack NodeJS/JavaScript implementation. Prior to 1.10.1, when decoding user supplied MessagePac
Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS Thre
An issue was discovered in arch/x86/kvm/vmx/nested.c in the Linux kernel before 6.2.8. nVMX on x86_64 lacks consistency
An Improper Check or Handling of Exceptional Conditions within the storm control feature of Juniper Networks Junos OS al
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of servi
In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, an
A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src head
Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network Intercoms when communicatin
An Improper Check for Unusual or Exceptional Conditions in the Packet Forwarding Engine (pfe) of Juniper Networks Junos
Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable denial of servic
An improper check for an exceptional condition in the Insider Threat Management (ITM) Server could be used by an attacke
Improper condition check in some Intel(R) SPS firmware before version SPS_E3_06.00.03.300.0 may allow a privileged user
Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electro
go-bitfield is a simple bitfield package for the go language aiming to be more performant that the standard library. Whe
Improper conditions check in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to pote
An Improper Check for Unusual or Exceptional Conditions vulnerability in the SIP ALG of Juniper Networks Junos OS on SR
In several methods of JobStore.java, uncaught exceptions in job map parsing could lead to local persistent denial of ser
In onAccessPointChanged of AccessPointPreference.java, there is a possible way for unprivileged apps to receive a broadc
Unchecked Error Condition in GitHub repository froxlor/froxlor prior to 2.0.10.
Improper Input Validation vulnerability in ABB AC500 V2 PM5xx allows Client-Server Protocol Manipulation.This issue affe
ink! is an embedded domain specific language to write smart contracts in Rust for blockchains built on the Substrate fra
Shopware is an open source e-commerce software. The mail validation in the registration process had some flaws, so it wa
In OpenBGPD before 8.1, incorrect handling of BGP update data (length of path attributes) set by a potentially distant r
Parameter verification vulnerability in the window module.Successful exploitation of this vulnerability may cause the si
Issue summary: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected vers
An Improper Check for Unusual or Exceptional Conditions vulnerability in the kernel of Juniper Networks Junos OS allows
An Unexpected Status Code or Return Value vulnerability in the kernel of Juniper Networks Junos OS allows an unauthentic
An improper check for unusual conditions in Zyxel NWA110AX firmware verisons prior to 6.50(ABTG.0)C0, which could allow
Mattermost fails to properly validate requests to the Calls plugin, allowing an attacker sending a request without a Use
Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of serv
Mattermost fails to validate the type of the "reminder" body request parameter allowing an attacker to crash the Playboo
The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS se
Improper conditions check in the Open CAS software maintained by Intel(R) before version 22.3.1 may allow an authenticat
In JetBrains IntelliJ IDEA before 2023.1.4 license dialog could be suppressed in certain cases
In ShortcutInfo of ShortcutInfo.java, there is a possible way for an app to retain notification listening access due to
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The Web UI of affected devices does
Frequently Asked Questions
What is CWE-754?
CWE-754 (CWE-754) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-754?
There are 772 CVE records associated with CWE-754 in our database. Of these, 20 are critical severity, 245 are high severity, and 287 are medium severity.
How can I protect against CWE-754 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-754 using AI-powered security agents.
Detect CWE-754 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-754 vulnerabilities across your infrastructure.
Get Started