Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-843

MITRE ↗

CWE-843

29
CRITICAL
120
HIGH
45
MEDIUM
5
LOW
208 CVEs · Page 3/5
7.8
CVE-2026-20860

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an

7.8
CVE-2026-21330

After Effects versions 25.6 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion')

7.8
CVE-2026-21519 KEV

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to

7.8
CVE-2025-66342

A type confusion vulnerability exists in the EMF functionality of Canva Affinity. A specially crafted EMF file can trigg

7.8
CVE-2026-5496

Labcenter Electronics Proteus PDSPRJ File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability

7.8
CVE-2026-26162

Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized attacker to elevate pr

7.8
CVE-2026-27298

Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confus

7.8
CVE-2026-31502

In the Linux kernel, the following vulnerability has been resolved: team: fix header_ops type confusion with non-Ethern

7.8
CVE-2026-34344

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an

7.8
CVE-2026-35417

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-44817

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker

7.8
CVE-2026-45600

Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows an authorized attack

7.8
CVE-2026-12390

In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using spe

7.8
CVE-2026-57254

There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF,

7.8
CVE-2026-50421

Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows

7.8
CVE-2026-55022

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to exe

7.8
CVE-2026-55024

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker

7.8
CVE-2026-55025

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker

7.8
CVE-2026-58541

Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate pr

7.8
CVE-2026-61932

Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker

7.8
CVE-2026-64904

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to exe

7.8
CVE-2026-68803

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker

7.8
CVE-2026-68811

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker

7.7
CVE-2026-40683

In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean

7.5
CVE-2026-25537

jsonwebtoken is a JWT lib in rust. Prior to version 10.3.0, there is a Type Confusion vulnerability in jsonwebtoken, spe

7.5
CVE-2026-2783

Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed i

7.5
CVE-2026-29079

Lexbor is a web browser engine library. Prior to 2.7.0, a type‑confusion vulnerability exists in Lexbor’s HTML fragment

7.5
CVE-2026-32701

Qwik is a performance-focused JavaScript framework. Versions prior to 1.19.2 improperly inferred arrays from dotted form

7.5
CVE-2026-21710

A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `_

7.5
CVE-2026-28983

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5

7.5
CVE-2026-5946

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`

7.5
CVE-2026-9117

Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had comp

7.5
CVE-2026-44325

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NRF root SBI endpoint POST /o

7.5
CVE-2026-10022

Type Confusion in V8 in Google Chrome prior to 148.0.7778.216 allowed an attacker who convinced a user to install a mali

7.5
CVE-2026-44628

An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called

7.5
CVE-2026-57975

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized

7.5
CVE-2026-58290

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized

7.5
CVE-2026-57108

Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny servi

7.5
CVE-2026-17948

Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malic

7.5
CVE-2026-72766

n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Emai

7.5
CVE-2026-52829

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can deterministically termi

7.4
CVE-2026-66321

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized

7.3
CVE-2026-9334

Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref i

7.3
CVE-2026-11463

A vulnerability was determined in USCiLab Cereal up to 1.3.2. Affected is an unknown function of the component Shared Po

7.1
CVE-2026-25503

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color

7.1
CVE-2026-34379

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the

7.1
CVE-2026-27144

The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented

7.0
CVE-2026-50390

Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate

7.0
CVE-2026-50491

Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.

6.9
CVE-2026-40446

Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Point

Frequently Asked Questions

What is CWE-843?

CWE-843 (CWE-843) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-843?

There are 216 CVE records associated with CWE-843 in our database. Of these, 29 are critical severity, 120 are high severity, and 45 are medium severity.

How can I protect against CWE-843 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-843 using AI-powered security agents.

Detect CWE-843 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-843 vulnerabilities across your infrastructure.

Get Started