Skip to main content

CWE archive

CWE-248 CVEs

Programmatic archive

239 CVEs tagged with CWE-2484 Critical, 131 High, 98 Medium, 6 Low, 0 Unrated.

CVE-2025-54134

Published Jul 21, 2025

HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the HAX CMS NodeJS application crashes when an authenticated at…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-7338

Published Jul 17, 2025

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.2 allows an attacker to…

CVSS 7.5 · High

CVE-2025-53620

Published Jul 9, 2025

@builder.io/qwik-city is the meta-framework for Qwik. When a Qwik Server Action QRL is executed it dynamically load the file containing the symbol. When an invalid qfunc is sent,…

CVSS 9.2 · Critical

CVE-2025-53366

Published Jul 4, 2025

The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.9.4, a validation error in the MCP SDK can cause an un…

CVSS 8.7 · High

CVE-2025-53365

Published Jul 4, 2025

The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.10.0, if a client deliberately triggers an exception a…

CVSS 8.7 · High

CVE-2025-44019

Published Jun 12, 2025

AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI Data Archive subsy…

CVSS 7.1 · High

CVE-2025-36539

Published Jun 12, 2025

AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI Data Archive subs…

CVSS 7.1 · High

CVE-2025-48907

Published Jun 6, 2025

Deserialization vulnerability in the IPC module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48997

Published Jun 3, 2025

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.1 allows an attacker to…

CVSS 8.7 · High

CVE-2025-29785

Published Jun 2, 2025

quic-go is an implementation of the QUIC protocol in Go. The loss recovery logic for path probe packets that was added in the v0.50.0 release can be used to trigger a nil-pointer…

CVSS 7.5 · High

CVE-2025-48943

Published May 30, 2025

vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a Denial of Service (ReDoS) that causes the vLLM server to c…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48942

Published May 30, 2025

vLLM is an inference and serving engine for large language models (LLMs). In versions 0.8.0 up to but excluding 0.9.0, hitting the /v1/completions API with a invalid json_schema…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47944

Published May 19, 2025

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.0 allows an attacker to…

CVSS 7.5 · High

CVE-2025-23166

Published May 19, 2025

The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Su…

CVSS 7.5 · High

CVE-2025-20054

Published May 13, 2025

Uncaught exception in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.

CVSS 6.8 · Medium

CVE-2025-43855

Published Apr 24, 2025

tRPC allows users to build & consume fully typesafe APIs without schemas or code generation. In versions starting from 11.0.0 to before 11.1.1, an unhandled error is thrown when v…

CVSS 8.7 · High

CVE-2025-32944

Published Apr 15, 2025

The vulnerability allows any authenticated user to cause the PeerTube server to stop functioning in a persistent manner.  If user import is enabled (which is the default setting),…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-49705

Published Apr 14, 2025

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to client-side Denial of Servise (DoS) attacks. An attacker might trick a user into using an URL with a d pa…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-58112

Published Apr 7, 2025

Exception capture failure vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-58111

Published Apr 7, 2025

Exception capture failure vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-3083

Published Apr 1, 2025

Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur without using an authenticated connection. This issue affec…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 101-125 of 239 CVEsPage 5 of 10