230 vulnerabilities classified as CWE-248 (未捕获的异常). AI Chinese analysis included.
CWE-248, Uncaught Exception, represents a critical software weakness where a function throws an error that the calling code fails to handle. This oversight typically allows attackers to exploit the vulnerability by triggering specific conditions that force the application to crash, resulting in a denial of service. Alternatively, the unhandled exception may cause the system to dump detailed stack traces or internal state information to the user interface, inadvertently exposing sensitive data such as database credentials or server architecture. To mitigate this risk, developers must implement robust error handling mechanisms, ensuring that all potential exceptions are explicitly caught and managed. By using try-catch blocks and providing generic, non-revealing error messages, programmers can maintain application stability and prevent information leakage, thereby securing the software against both availability attacks and data exposure.
protected void doPost (HttpServletRequest req, HttpServletResponse res) throws IOException { String ip = req.getRemoteAddr(); InetAddress addr = InetAddress.getByName(ip); ... out.println("hello " + addr.getHostName()); }
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-2229 | undici is vulnerable to Unhandled Exception in undici WebSocket Client Due to Invalid server_max_window_bits Validation — undici | 7.5 | High | 2026-03-12 |
| CVE-2026-1528 | undici is vulnerable to Malicious WebSocket 64-bit length overflows undici parser and crashes the client — undici | 7.5 | High | 2026-03-12 |
| CVE-2026-31870 | cpp-httplib Affected by Remote Process Crash via Malformed Content-Length Response Header — cpp-httplib | 7.5 | High | 2026-03-11 |
| CVE-2026-31812 | Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing — quinn | 8.7 | High | 2026-03-10 |
| CVE-2026-20068 | Multiple Cisco Products Snort 3 TBD Denial of Service Vulnerability — Cisco Cyber Vision | 5.8 | Medium | 2026-03-04 |
| CVE-2026-20031 | ClamAV CSS Image Parsing Error Handling Denial of Service Vulnerability — Cisco Secure Endpoint | 5.3 | Medium | 2026-03-04 |
| CVE-2026-27631 | Exiv2: Uncaught exception - cannot create std::vector larger than max_size() — exiv2 | 5.5AI | Medium AI | 2026-03-02 |
| CVE-2026-1507 | Uncaught Exception vulnerability in AVEVA PI Data Archive — PI Data Archive PI Server | 7.5 | High | 2026-02-10 |
| CVE-2026-25577 | Emmett has an Unhandled CookieError Exception Causing Denial of Service — core | 7.5 | High | 2026-02-10 |
| CVE-2025-13064 | AXIS Camera Station Pro 安全漏洞 — AXIS Camera Station Pro | 4.5 | Medium | 2026-02-10 |
| CVE-2025-67647 | SvelteKit Denial of service and possible SSRF when using prerendering — kit | 7.5AI | High AI | 2026-01-15 |
| CVE-2025-66578 | robrichards/xmlseclibs has an Libxml2 Canonicalization error which can bypass Digest/Signature validation — xmlseclibs | 6.0 | Medium | 2025-12-09 |
| CVE-2025-20758 | MediaTek Chipsets 安全漏洞 — MT2735, MT2737, MT6813, MT6833, MT6833P, MT6835, MT6835T, MT6853, MT6853T, MT6855, MT6855T, MT6873, MT6875, MT6875T, MT6877, MT6877T, MT6877TT, MT6878, MT6878M, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6895TT, MT6896, MT6897, MT6899, MT6980, MT6980D, MT6983, MT6983T, MT6985, MT6985T, MT6989, MT6989T, MT6990, MT6991, MT8673, MT8675, MT8676, MT8678, MT8755, MT8771, MT8791, MT8791T, MT8792, MT8793, MT8795T, MT8797, MT8798, MT8863, MT8873, MT8883, MT8893 | 7.5AI | High AI | 2025-12-02 |
| CVE-2025-20754 | MediaTek Chipsets 安全漏洞 — MT2735, MT2737, MT6813, MT6833, MT6833P, MT6835, MT6835T, MT6853, MT6853T, MT6855, MT6855T, MT6873, MT6875, MT6875T, MT6877, MT6877T, MT6877TT, MT6878, MT6878M, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6895TT, MT6896, MT6897, MT6899, MT6980, MT6980D, MT6983, MT6983T, MT6985, MT6985T, MT6989, MT6989T, MT6990, MT6991, MT8673, MT8675, MT8676, MT8678, MT8755, MT8771, MT8791, MT8791T, MT8792, MT8793, MT8795T, MT8797, MT8798, MT8863, MT8873, MT8883, MT8893 | 7.5AI | High AI | 2025-12-02 |
| CVE-2025-20753 | MediaTek Chipsets 安全漏洞 — MT2735, MT2737, MT6833, MT6833P, MT6853, MT6853T, MT6855, MT6855T, MT6873, MT6875, MT6875T, MT6877, MT6877T, MT6877TT, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6895TT, MT6896, MT6980, MT6980D, MT6983, MT6983T, MT6985, MT6985T, MT6989, MT6989T, MT6990, MT8675, MT8771, MT8791, MT8791T, MT8797 | 7.5AI | High AI | 2025-12-02 |
| CVE-2025-66305 | Grav vulnerable to Denial of Service via Improper Input Handling in 'Supported' Parameter — grav | 4.9AI | Medium AI | 2025-12-01 |
| CVE-2025-8870 | On affected platforms running Arista EOS, certain serial console input might result in an unexpected reload of the device. — EOS | 4.9 | Medium | 2025-11-14 |
| CVE-2025-12423 | Denial of Service - Protocol Manipulation — BLU-IC2 | 7.5AI | High AI | 2025-10-28 |
| CVE-2025-59462 | Denial-of-service (DoS) via delayed or missing client response — TLOC100-100 all Firmware versions | 6.5 | Medium | 2025-10-27 |
| CVE-2025-48430 | Gallagher Command Centre Server 安全漏洞 — Command Centre Server | 5.5 | Medium | 2025-10-23 |
| CVE-2025-62370 | Alloy Core has a DoS vulnerability on `alloy_dyn_abi::TypedData` hashing — core | 7.5 | High | 2025-10-15 |
| CVE-2025-59229 | Microsoft Office Denial of Service Vulnerability — Microsoft 365 Apps for Enterprise | 5.5 | Medium | 2025-10-14 |
| CVE-2025-9124 | Rockwell Automation Compact GuardLogix® 5370 Denial-Of-Service Vulnerability — Compact GuardLogix® 5370 | 7.5AI | High AI | 2025-10-14 |
| CVE-2025-59538 | Argo CD is Vulnerable to Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook — argo-cd | 7.5 | High | 2025-10-01 |
| CVE-2025-35436 | CISA Thorium account verification email error handling — Thorium | 5.3 | Medium | 2025-09-17 |
| CVE-2025-59014 | Denial of Service in TYPO3 Bookmark Toolbar — TYPO3 CMS | 4.9AI | Medium AI | 2025-09-09 |
| CVE-2025-54777 | Konica Minolta bizhub 安全漏洞 — Multiple products in bizhub series | 7.5 | - | 2025-08-29 |
| CVE-2025-55194 | Part-DB Persistent Denial of Service via Uncaught Exception from Misleading File Extension in Avatar Upload — Part-DB-server | 5.7 | Medium | 2025-08-13 |
| CVE-2013-10065 | Sysax Multi-Server <= 6.10 SSHD Key Exchange DoS — Multi-Server | 7.5AI | High AI | 2025-08-05 |
| CVE-2025-7338 | Multer vulnerable to Denial of Service via unhandled exception from malformed request — multer | 7.5 | High | 2025-07-17 |
Vulnerabilities classified as CWE-248 (未捕获的异常) represent 230 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.