VYPR

CWE-248

Uncaught Exception

BaseDraft

Description

An exception is thrown from a function, but it is not caught.

When an exception is not caught, it may cause the program to crash or expose sensitive information.

Hierarchy (View 1000)

Children

CVEs mapped to this weakness (309)

page 15 of 16
  • CVE-2026-55244MedSep 14, 2026
    risk 0.26cvss 5.0epss 0.00

    ASTEVAL is an evaluator of Python expressions and statements. Prior to 1.0.9, FROM_PY in asteval/astutils.py exposes BaseException, SystemExit, KeyboardInterrupt, and GeneratorExit to expressions evaluated by asteval.Interpreter.eval(), while run() and eval() in…

  • CVE-2024-51750MedNov 12, 2024
    risk 0.26cvss 5.0epss 0.01

    Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over federation which can prevent Element Web and Desktop from rendering single messages or the entire room containing them. This was patched in Element Web and…

  • CVE-2022-3500MedNov 22, 2022
    risk 0.26cvss 5.1epss 0.00

    A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the possibility that a rogue agent could create errors on the verifier that stopped attestation attempts for that host leaving it in…

  • CVE-2024-58358MedJul 18, 2026
    risk 0.25cvss 4.9epss 0.00

    SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owner users to define users with nonexistent roles. Attackers can trigger an uncaught panic by signing in with a user assigned an invalid role, crashing the server.

  • CVE-2025-66305MedDec 1, 2025
    risk 0.25cvss 4.9epss 0.00

    Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Denial of Service (DoS) vulnerability was identified in the "Languages" submenu of the Grav admin configuration panel (/admin/config/system). Specifically, the Supported parameter fails to properly validate user input.…

  • CVE-2018-11464LowDec 12, 2018
    risk 0.24cvss 3.7epss 0.02

    A vulnerability has been identified in SINUMERIK 828D V4.7 (All versions < V4.7 SP6 HF1), SINUMERIK 840D sl V4.7 (All versions < V4.7 SP6 HF5), SINUMERIK 840D sl V4.8 (All versions < V4.8 SP3). The integrated VNC server on port 5900/tcp of the affected products could allow a…

  • CVE-2026-55517MedJun 23, 2026
    risk 0.21cvss 4.3epss 0.00

    Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.5, a Deno program that opens a client WebSocket connection could be crashed by the remote server. While handling the WebSocket handshake response, Deno parsed the Sec-WebSocket-Protocol and…

  • CVE-2024-23449MedMar 29, 2024
    risk 0.21cvss 4.3epss 0.01

    An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. The Elasticsearch ingest node that attempts to parse the PDF file will crash. This does not happen with password-protected PDF…

  • CVE-2021-25971MedOct 20, 2021
    risk 0.21cvss 4.3epss 0.01

    In Camaleon CMS, versions 2.0.1 to 2.6.0 are vulnerable to an Uncaught Exception. The app's media upload feature crashes permanently when an attacker with a low privileged access uploads a specially crafted .svg file

  • CVE-2026-27844LowJul 7, 2026
    risk 0.18cvss 2.7epss 0.00

    Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by sending specific requests, resulting in a temporary denial of service.  Version of Command Centre…

  • CVE-2026-27790LowJul 7, 2026
    risk 0.18cvss 2.7epss 0.00

    Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by sending specific requests, resulting in a temporary denial of service. Version of Command Centre affected: * 9.50 prior to vCR9.50.260616a…

  • CVE-2026-54541LowSep 14, 2026
    risk 0.17cvss 3.7epss 0.00

    Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to 1.6.0, a malicious state-sync peer can crash a syncing node by sending a crafted TrieChunk proof containing two TrieProofNode values with identical keys.…

  • CVE-2026-84947LowSep 4, 2026
    risk 0.17cvss 3.7epss 0.00

    undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a response declares a Content-Length that exceeds the maximum, the interceptor aborts cleanly, but when a response has no Content-Length and is chunked, the interceptor instead…

  • CVE-2025-59014LowSep 9, 2025
    risk 0.11cvss 2.7epss 0.00

    An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 lets administrator‑level backend users trigger a denial‑of‑service condition in the backend user interface by saving manipulated data in the…

  • CVE-2026-61799Aug 20, 2026
    risk 0.00cvss —epss —

    ## Summary `io.netty.incubator:netty-incubator-codec-bhttp` uses attacker-controlled Binary HTTP variable-length integers as `long` values but accumulates them into `int` offsets. Large valid varint lengths wrap the internal offset negative, leading to unchecked…

  • CVE-2026-63747HigJul 20, 2026
    risk 0.00cvss 7.5epss 0.01

    SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is set without a namespace. Unauthenticated attackers can send a malformed WebSocket message to the /rpc endpoint to crash the server process.

  • CVE-2026-62994LowJul 16, 2026
    risk 0.00cvss 3.7epss 0.00

    CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreDNS zone can trigger a panic when CoreDNS is configured with k8s_external headless-service zone transfers and Kubernetes contains a headless service endpoint…

  • CVE-2026-47480HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2026-50328HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.

  • CVE-2026-55780LowJul 10, 2026
    risk 0.00cvss —epss 0.00

    NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's .NET single-file bundle handler in NanaZip.Codecs.Archive.DotNetSingleFile.cpp sizes its extraction buffer from the bundle entry Size field, which is only checked for sign…