The product does not handle or incorrectly handles inputs that are related to complex structures.
Volume of CVEs assigned to CWE-237 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-45411CRITICAL vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the generator is | May 13, 2026 | 9.8 | 40 | NO | NO |
CVE-2023-34429HIGH
Weintek Weincloud v0.13.6
could allow an attacker to cause a denial-of-service condition for Weincloud by sending a forged JWT token.
| Jul 19, 2023 | 7.5 | 21 | NO | NO |
CVE-2023-6110MEDIUM A flaw was found in OpenStack. When a user tries to delete a non-existing access rule in it's scope, it deletes other existing access rules which are not associated with any applic | Nov 17, 2024 | 5.5 | 19 | NO | NO |
SXF Common Library handles input data improperly. If a product using the library reads a crafted file, the product may be crashed. | Jan 31, 2025 | 3.3 | 12 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.