CWE-703: Improper Check or Handling of Exceptional Conditions
The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.
117 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-39815 — Vonets WiFi Bridges Improper Check or Handling of Exceptional Conditions
- CVE-2025-65017 — Decidim's private data exports can lead to data leaks
- CVE-2025-61602 — BigBlueButton vulnerable to Chat DoS via invalid reactionEmojiId
- CVE-2025-61601 — BigBlueButton vulnerable to DoS via PollSubmitVote GraphQL mutation
- CVE-2025-59538 — Argo CD is Vulnerable to Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook
- CVE-2025-59531 — Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload
- CVE-2025-14874 — Nodemailer: nodemailer: denial of service via crafted email address header
- CVE-2026-20280 — Cisco IOS XR Software Security Hardening Release: September 2026
- CVE-2026-57445 — Gardens v2: Approve-side dispute resolution drains active streaming escrow reserve
- CVE-2025-54134 — HAX CMS NodeJs's Improper Error Handling Leads to Denial of Service
- CVE-2025-24371 — Malicious peer can make node stuck in blocksync in github.com/cometbft/cometbft
- CVE-2024-39514 — Junos OS and Junos OS Evolved: Receiving specific traffic on devices with EVPN-VPWS with IGMP-snooping enabled will cause the rpd to crash
- CVE-2026-28407 — malcontent's nested archive extraction failure can drop content from scan inputs
- CVE-2026-1996 — Certain HP OfficeJet Pro Printers – Denial of Service
- CVE-2025-11594 — ywxbear PHP-Bookstore-Website-Example Quantity index.php improper validation of specified quantity in input
- CVE-2024-4611 — AppPresser <= 4.3.2 - Improper Missing Encryption Exception Handling to Authentication Bypass
- CVE-2026-34388 — Fleet vulnerable to Denial of Service via unhandled gRPC log type in launcher endpoint
- CVE-2026-21493 — iccDEV has Type Confusion during XML Curve Serialization
- CVE-2024-38482 — CloudLink, versions 7.1.x and 8.x, contain an Improper check or handling of Exceptional Conditions Vulnerability in Clus
- CVE-2025-68135 — EVerest's inadequate exception handling leads to denial of service
Recently published
- CVE-2026-80135 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-57445 — Gardens v2: Approve-side dispute resolution drains active streaming escrow reserve
- CVE-2026-20280 — Cisco IOS XR Software Security Hardening Release: September 2026
- CVE-2026-82417 — qs.stringify throws TypeError on objects with a non-callable constructor.isBuffer property
- CVE-2026-18638 — Velociraptor server crash via the SetPassword API
- CVE-2026-56818 — Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
- CVE-2026-16218 — hunvreus devpush Storage Reset Failure storage.py reset_storage improper check or handling of exceptional conditions
- CVE-2026-20187 — Cisco RoomOS Security Hardening Release - Exceptional Conditions Handling Vulnerabilities
- CVE-2026-13753 — Certain HP DeskJet All in One – Potential Information Disclosure
- CVE-2026-56338 — Capgo - Denial of Service in 2FA Email Verification via /auth/v1/otp Endpoint
- CVE-2026-44893 — Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length
- CVE-2026-47316 — Improper Check or Handling of Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Man
- CVE-2026-34388 — Fleet vulnerable to Denial of Service via unhandled gRPC log type in launcher endpoint
- CVE-2026-31794 — iccDEV has a SEGV in CIccCLUT::Interp3d()
- CVE-2026-31793 — iccDEV has a SEGV in CIccCalculatorFunc::ApplySequence()
- CVE-2025-59787 — HTTP 5XX Internal Server Errors
- CVE-2026-28407 — malcontent's nested archive extraction failure can drop content from scan inputs
- CVE-2026-1996 — Certain HP OfficeJet Pro Printers – Denial of Service
- CVE-2025-65017 — Decidim's private data exports can lead to data leaks
- CVE-2025-68135 — EVerest's inadequate exception handling leads to denial of service