CWE-754: Improper Check for Unusual or Exceptional Conditions
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
379 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-11925 — Incorrect Content-Type Header
- CVE-2026-79073 — Improper state validation in Parser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially exe
- CVE-2026-30960 — RSSN has Arbitrary Code Execution via Unvalidated JIT Instruction Generation in C-FFI Interface
- CVE-2025-0129 — Prisma Access Browser: Inappropriate control behavior in Prisma Access Browser
- CVE-2026-79072 — Improper state validation in Performance in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentiall
- CVE-2026-24054 — Kata Containers Runtime: Host block device can be hotplugged to the VM if the container image is malformed or contains no layers
- CVE-2026-21693 — iccDEV has Type Confusion in CIccSegmentedCurveXml::ToXml() at IccXML/IccLibXML/IccMpeXml.cpp
- CVE-2025-24303 — Improper check for unusual or exceptional conditions in the Linux kernel-mode driver for some Intel(R) 800 Series Ethern
- CVE-2025-69420 — Missing ASN1_TYPE validation in TS_RESP_verify_response() function
- CVE-2026-33151 — socket.io allows an unbounded number of binary attachments
- CVE-2025-61976 — CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper check for unusual or exceptional conditions. If a rem
- CVE-2025-61668 — @plone/volto vulnerable to potential DoS by invoking specific URL by anonymous user
- CVE-2025-60004 — Junos OS and Junos OS Evolved: Specific BGP EVPN update message causes rpd crash
- CVE-2025-52981 — Junos OS: SRX Series: Sequence of specific PIM packets causes a flowd crash
- CVE-2025-30660 — Junos OS: MX Series: Decapsulation of specific GRE packets leads to PFE reset
- CVE-2025-21594 — Junos OS: MX Series: In DS-lite and NAT scenario receipt of crafted IPv6 traffic causes port block
- CVE-2024-52504 — A vulnerability has been identified in SIPROTEC 4 6MD61 (All versions), SIPROTEC 4 6MD63 (All versions), SIPROTEC 4 6MD6
- CVE-2024-47499 — Junos OS and Junos OS Evolved: In a BMP scenario receipt of a malformed AS PATH attribute can cause an RPD crash
- CVE-2024-39545 — Junos OS: SRX Series, MX Series with SPC3 and NFX350: When VPN tunnels parameters are not configured in specific way the iked process will crash
- CVE-2024-39540 — Junos OS: SRX Series, and MX Series with SPC3: Specific valid TCP traffic can cause a pfe crash
Recently published
- CVE-2026-87656 — Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass sy
- CVE-2026-87532 — Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass sy
- CVE-2026-87548 — Improper state validation in Installer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass syste
- CVE-2026-87645 — Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass sy
- CVE-2026-73314 — XenForo < 2.3.13 Signature Verification Bypass via PayPal REST Webhook
- CVE-2026-85014 — undici vulnerable to Denial of Service via WebSocketStream unclean close
- CVE-2026-55484 — ALOS HTTP: Unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server
- CVE-2026-79073 — Improper state validation in Parser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially exe
- CVE-2026-79072 — Improper state validation in Performance in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentiall
- CVE-2026-75595 — Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext
- CVE-2026-11970 — This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DL
- CVE-2026-19481 — @fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header
- CVE-2026-73430 — Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
- CVE-2026-73429 — Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
- CVE-2026-73288 — RustFS: Object Lock (WORM) protections are treated as absent when bucket metadata cannot be read, allowing retained objects to be deleted
- CVE-2026-20783 — Improper conditions check in the firmware for the Intel(R) NPU Driver for all versions within Ring 1: Device Drivers may
- CVE-2026-20776 — Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a deni
- CVE-2026-20769 — Improper conditions check for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a deni
- CVE-2026-20747 — Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a deni
- CVE-2026-20739 — Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may