An exception is thrown from a function, but it is not caught.
Volume of CVEs assigned to CWE-248 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
239 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-10065HIGH A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A specially crafted SSH key exchange packet can trigger a crash in the service, resu | Aug 5, 2025 | 7.5 | 40 | NO | YES |
CVE-2026-58208HIGH NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener could route requests for the MQT | Jul 8, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-14181HIGH @fastify/middie versions 9.1.0 through 9.3.2 fail to guard the URL normalization step used by the standalone engine when incoming request paths contain malformed percent-encoded se | Jul 1, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-59162HIGH Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses shared-string cell values with strconv.Atoi and checks only | Jul 10, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-9509HIGH An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated remote attacker to cause a denial of service (DoS) by sendi | May 29, 2026 | 8.7 | 35 | NO | NO |
CVE-2026-44001HIGH vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox escape vulnerability in vm2 v3.10.5 allows any sandboxed code to crash the host Node.js process via a singl | May 13, 2026 | 8.6 | 35 | NO | NO |
CVE-2026-34986HIGH Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS) | Apr 6, 2026 | 7.5 | 35 | NO | NO |
CVE-2024-58368HIGH SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing special characters. Unauthenticated attackers can send crafte | Jul 18, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-64612HIGH A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image fil | Jul 20, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-63747HIGH SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is set without a namespace. Unauthenticated attackers can send | Jul 20, 2026 | 7.5 | 33 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.