VYPR

CWE-754

Improper Check for Unusual or Exceptional Conditions

ClassIncompleteLikelihood: Medium

Description

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

Hierarchy (View 1000)

CVEs mapped to this weakness (632)

page 27 of 32
  • CVE-2024-34664MedOct 8, 2024
    risk 0.27cvss 4.1epss 0.00

    Improper check for exception conditions in Knox Guard prior to SMR Oct-2024 Release 1 allows physical attackers to bypass Knox Guard in a multi-user environment.

  • CVE-2021-29607MedMay 14, 2021
    risk 0.27cvss 5.3epss 0.00

    TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `SparseAdd` results in allowing attackers to exploit undefined behavior (dereferencing null pointers) as well as write outside of bounds of heap allocated data. The…

  • CVE-2026-0230MedMar 11, 2026
    risk 0.26cvss epss 0.00

    A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator to disable the agent. This issue could be leveraged by malware to perform malicious activity without detection.

  • CVE-2025-62783MedOct 27, 2025
    risk 0.26cvss 5.0epss 0.00

    InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions 1.6.1-SNAPSHOT and earlier contain a vulnerability where any plugin using the `GuiStorageElement can allow item duplication when the experimental Bundle item feature is enabled on the server.…

  • CVE-2024-51502MedNov 4, 2024
    risk 0.26cvss epss 0.00

    loona is an experimental, HTTP/1.1 and HTTP/2 implementation in Rust on top of io-uring. `loona-hpack` suffers from the same vulnerability as the original `hpack` as documented in issue #11. All users who try to decode untrusted input using the Decoder are vulnerable to this…

  • CVE-2020-5215MedJan 28, 2020
    risk 0.26cvss 5.0epss 0.01

    In TensorFlow before 1.15.2 and 2.0.1, converting a string (from Python) to a tf.float16 value results in a segmentation fault in eager mode as the format checks for this use case are only in the graph mode. This issue can lead to denial of service in inference/training where a…

  • CVE-2023-38420LowMay 16, 2024
    risk 0.25cvss 3.8epss 0.00

    Improper conditions check in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2023-32726LowDec 18, 2023
    risk 0.25cvss 3.9epss 0.01

    The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server.

  • CVE-2021-22747LowMay 26, 2021
    risk 0.25cvss 3.9epss 0.00

    Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position. This…

  • CVE-2021-22746LowMay 26, 2021
    risk 0.25cvss 3.9epss 0.00

    Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position. This…

  • CVE-2021-22745LowMay 26, 2021
    risk 0.25cvss 3.9epss 0.00

    Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position. This…

  • CVE-2021-22744LowMay 26, 2021
    risk 0.25cvss 3.9epss 0.00

    Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position. This…

  • CVE-2021-22743LowMay 26, 2021
    risk 0.25cvss 3.9epss 0.00

    Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex TCM 4351B installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position.

  • CVE-2021-22742LowMay 26, 2021
    risk 0.25cvss 3.9epss 0.00

    Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position.

  • CVE-2026-66774LowAug 11, 2026
    risk 0.24cvss 3.7epss 0.00

    SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploitation is highly complex, as it depends on conditions outside the attacker's control. This could result in…

  • CVE-2026-65904MedJul 23, 2026
    risk 0.24cvss 4.7epss 0.00

    DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element originates from a different window/realm (e.g., an iframe's contentDocument). A cross-realm instanceof check in the private _isNode() function returns false for foreign-realm nodes,…

  • CVE-2026-8491LowMay 19, 2026
    risk 0.24cvss 3.7epss 0.00

    Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View Permissions allows Forceful Browsing. This issue affects Node View Permissions: from 0.0.0 before 1.7.0, from 2.0.0 before 2.0.1.

  • CVE-2024-24567MedJan 30, 2024
    risk 0.24cvss 4.8epss 0.00

    Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. Vyper compiler allows passing a value in builtin raw_call even if the call is a delegatecall or a staticcall. But in the context of delegatecall and staticcall the handling of value is not possible due…

  • CVE-2023-23931MedFeb 7, 2023
    risk 0.24cvss 4.8epss 0.01

    cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable…

  • CVE-2021-37862LowDec 17, 2021
    risk 0.24cvss 3.7epss 0.01

    Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into signing up using attacker-controlled email addresses via crafted invitation token.