Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-843

MITRE ↗

CWE-843

108
CRITICAL
565
HIGH
162
MEDIUM
26
LOW
870 CVEs · Page 7/18
6.5
CVE-2025-7259

An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, whi

6.5
CVE-2025-61911

python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, the san

6.2
CVE-2025-43297

A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26. An app may be

5.9
CVE-2025-21225

Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability

5.5
CVE-2024-54507

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, mac

5.5
CVE-2025-43355

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS

5.4
CVE-2025-24271

An access issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS

5.4
CVE-2025-59717

In the @digitalocean/do-markdownit package through 1.16.1 (in npm), the callout and fence_environment plugins perform .i

5.3
CVE-2024-13275

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Drupal Security Kit allows HTTP DoS.This

5.3
CVE-2022-50590

SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the processing of the ‘module’ parameter

4.8
CVE-2025-32352

A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass au

4.6
CVE-2024-37603

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6. A possible type confusion exists in the user

4.5
CVE-2025-54649

Vulnerability of using incompatible types to access resources in the location service. Impact: Successful exploitation o

4.3
CVE-2025-2197

Browser is affected by type confusion vulnerability, successful exploitation of this vulnerability may affect service av

4.3
CVE-2025-31206

A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPad

4.3
CVE-2025-43541

A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iP

3.7
CVE-2025-22151

Strawberry GraphQL is a library for creating GraphQL APIs. Starting in 0.182.0 and prior to version 0.257.0, a type conf

3.3
CVE-2025-20063

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.

3.3
CVE-2025-21082

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.

3.3
CVE-2025-27536

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through type confusion.

3.1
CVE-2025-11731

A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during sty

2.9
CVE-2024-58253

In the obfstr crate before 0.4.4 for Rust, the obfstr! argument type is not restricted to string slices, leading to inva

2.9
CVE-2025-48756

In group_number in the scsir crate 0.2.0 for Rust, there can be an overflow because a hardware device may expect a small

9.8
CVE-2024-5436

Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution prior to version 12.88.

9.8
CVE-2024-20078

In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege

9.8
CVE-2024-8381

A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as t

9.8
CVE-2024-8385

A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusi

9.8
CVE-2024-7824

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Wi

9.8
CVE-2024-7825

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Wi

9.8
CVE-2024-43498

.NET and Visual Studio Remote Code Execution Vulnerability

9.6
CVE-2024-4947 KEV

Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside

9.6
CVE-2024-5274 KEV

Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside

9.6
CVE-2024-7971 KEV

Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a

8.8
CVE-2023-41060

A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17.

8.8
CVE-2024-0518

Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corr

8.8
CVE-2024-23222 KEV

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.

8.8
CVE-2024-1938

Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object cor

8.8
CVE-2024-1939

Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corru

8.8
CVE-2024-20678

Remote Procedure Call Runtime Remote Code Execution Vulnerability

8.8
CVE-2024-25575

A type confusion vulnerability vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Lock object. A spec

8.8
CVE-2024-4058

Type confusion in ANGLE in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap co

8.8
CVE-2024-5830

Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memor

8.8
CVE-2024-5833

Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform out of bou

8.8
CVE-2024-5837

Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform out of bou

8.8
CVE-2024-5838

Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform out of bounds memory a

8.8
CVE-2024-6100

Type Confusion in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to execute arbitrary code via a

8.8
CVE-2024-7520

A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulner

8.8
CVE-2024-7550

Type Confusion in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corru

8.8
CVE-2024-7969

Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corr

8.8
CVE-2024-8194

Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corr

Frequently Asked Questions

What is CWE-843?

CWE-843 (CWE-843) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-843?

There are 1,092 CVE records associated with CWE-843 in our database. Of these, 108 are critical severity, 565 are high severity, and 162 are medium severity.

How can I protect against CWE-843 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-843 using AI-powered security agents.

Detect CWE-843 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-843 vulnerabilities across your infrastructure.

Get Started