VYPR

CWE-248

Uncaught Exception

BaseDraft

Description

An exception is thrown from a function, but it is not caught.

When an exception is not caught, it may cause the program to crash or expose sensitive information.

Hierarchy (View 1000)

Children

CVEs mapped to this weakness (273)

page 9 of 14
  • CVE-2025-48907MedJun 6, 2025
    risk 0.40cvss 6.2epss 0.00

    Deserialization vulnerability in the IPC module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-32995MedMay 14, 2024
    risk 0.40cvss 6.2epss 0.00

    Denial of service (DoS) vulnerability in the AMS module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-20048MedApr 1, 2024
    risk 0.40cvss 6.2epss 0.00

    In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541769; Issue ID: ALPS08541769.

  • CVE-2025-24851MedFeb 10, 2026
    risk 0.39cvss 6.0epss 0.00

    Uncaught exception in the firmware for some 100GbE Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x within Ring 0: Bare Metal OS may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable denial…

  • CVE-2022-41940HigNov 22, 2022
    risk 0.39cvss 7.1epss 0.02

    Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process. This impacts all the…

  • CVE-2026-61666higJul 21, 2026
    risk 0.38cvss epss

    ### Impact If this library is used to implement a WebSocket server on top of a TCP server, by using the `WebSocket::Driver.server()` method, then a client can cause the server to crash by sending a `Host` header that is not a valid `host[:port]` string. When this happens, a…

  • CVE-2026-20068MedMar 4, 2026
    risk 0.38cvss 5.8epss 0.00

    Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. This vulnerability is due to…

  • CVE-2019-6830MedSep 17, 2019
    risk 0.38cvss 5.9epss 0.01

    A CWE-248: Uncaught Exception vulnerability exists IN Modicon M580 all versions prior to V2.80, which could cause a possible denial of service when sending an appropriately timed HTTP request to the controller.

  • CVE-2026-65834MedJul 30, 2026
    risk 0.37cvss 6.8epss 0.00

    Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMetadata.ForbiddenLabels.Regex and CapsuleConfiguration.Spec.NodeMetadata.ForbiddenAnnotations.Regex were not validated by the configuration admission webhook,…

  • CVE-2026-58208MedJul 8, 2026
    risk 0.37cvss 6.8epss 0.00

    NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener could route requests for the MQTT-over-WebSocket path into MQTT handling even when MQTT was not configured, allowing an…

  • CVE-2023-5310MedDec 15, 2023
    risk 0.37cvss 5.7epss 0.00

    A denial of service vulnerability exists in all Silicon Labs Z-Wave controller and endpoint devices running Z-Wave SDK v7.20.3 (Gecko SDK v4.3.3) and earlier. This attack can be carried out only by devices on the network sending a stream of packets to the device.

  • CVE-2026-5937MedApr 27, 2026
    risk 0.36cvss 5.5epss 0.00

    Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "std::invalid_argument" exception, ultimately causing the program to terminate.

  • CVE-2026-35348MedApr 22, 2026
    risk 0.36cvss 5.5epss 0.00

    The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs containing non-UTF-8 filenames. The implementation enforces UTF-8 encoding and utilizes expect(), causing an immediate crash when encountering valid but…

  • CVE-2025-48430MedOct 23, 2025
    risk 0.36cvss 5.5epss 0.00

    Uncaught Exception (CWE-248) in the Command Centre Server allows an Authorized and Privileged Operator to crash the Command Centre Server at will. This issue affects Command Centre Server: 9.30 prior to vEL9.30.2482 (MR2), 9.20 prior to vEL9.20.2819 (MR4), 9.10 prior to…

  • CVE-2025-59229MedOct 14, 2025
    risk 0.36cvss 5.5epss 0.00

    Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally.

  • CVE-2025-0158MedFeb 6, 2025
    risk 0.36cvss 5.5epss 0.00

    IBM EntireX 11.1 could allow a local user to cause a denial of service due to an unhandled error and fault isolation.

  • CVE-2024-29076MedNov 13, 2024
    risk 0.36cvss 5.5epss 0.00

    Uncaught exception for some Intel(R) CST software before version 8.7.10803 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2023-21087MedApr 19, 2023
    risk 0.36cvss 5.5epss 0.00

    In PreferencesHelper.java, an uncaught exception may cause the device to get stuck in a boot loop. This could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-24615MedFeb 24, 2022
    risk 0.36cvss 5.5epss 0.01

    zip4j up to v2.10.0 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result in an application crash. This could be used to mount a denial of service attack against services that use zip4j library.

  • CVE-2021-3038MedApr 20, 2021
    risk 0.36cvss 5.5epss 0.00

    A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect app on Windows systems allows a limited Windows user to send specifically-crafted input to the GlobalProtect app that results in a Windows blue screen of death (BSOD) error. This issue impacts:…