CWE-770: CWE-770

501
Total CVEs
6
Critical
271
High
6.8
Avg CVSS

Yearly Trend

2026
98
2025
213
2024
98
2023
51
2022
18

Top Affected Vendors

1 Gitlab 33
2 Ibm 25
3 Qnap 14
4 Oracle 14
5 Linux 13
6 F5 10
7 Cisco 9
8 Apple 9
9 Debian 9
10 Samsung 9

All CWE-770 CVEs (501)

CVE-2021-47875
9.8

GeoGebra CAS Calculator 6.0.631.0 contains a buffer overflow vulnerability that allows attackers to crash the application by pasting a specially craft...

Jan 21, 2026
CVE-2025-11832
9.8

This CVE describes a resource allocation vulnerability in Azure Access Technology BLU-IC2 and BLU-IC4 devices that allows attackers to flood the syste...

Oct 15, 2025
CVE-2024-44241
9.8

This vulnerability in DCP firmware allows attackers to execute arbitrary code or cause system crashes through improper bounds checking. It affects iOS...

Dec 12, 2024
CVE-2021-41591
9.4

CVE-2021-41591 is a vulnerability in ACINQ Eclair Lightning Network implementation that allows attackers to exploit dust HTLC (Hashed TimeLock Contrac...

Oct 4, 2021
CVE-2024-38821
9.1

CVE-2024-38821 is an authorization bypass vulnerability in Spring WebFlux applications that allows attackers to access protected static resources with...

Oct 28, 2024
CVE-2023-27958
9.1

This is a high-severity memory corruption vulnerability in macOS kernel that allows remote attackers to cause system crashes or corrupt kernel memory....

May 8, 2023
CVE-2023-5289
8.8

This vulnerability in rdiffweb allows attackers to cause resource exhaustion through unlimited allocation without throttling, potentially leading to d...

Sep 29, 2023
CVE-2021-34710
8.8

This vulnerability in Cisco ATA 190 Series Analog Telephone Adapters allows attackers to execute arbitrary commands on affected devices through comman...

Oct 6, 2021
CVE-2021-34735
8.8

This vulnerability in Cisco ATA 190 Series Analog Telephone Adapters allows attackers to execute arbitrary commands on affected devices through comman...

Oct 6, 2021
CVE-2026-20103
8.6

An unauthenticated remote attacker can send crafted packets to Cisco ASA/FTD Remote Access SSL VPN servers to exhaust device memory, causing denial of...

Mar 4, 2026
CVE-2025-26819
8.6

Monero versions before commit ec74ff4 lack HTTP server connection response limits, allowing attackers to exhaust server resources through unlimited re...

Feb 15, 2025
CVE-2024-37358
8.6

Apache James email servers are vulnerable to denial of service attacks where attackers can abuse IMAP literals to cause unbounded memory allocation an...

Feb 6, 2025
CVE-2024-38286
8.6

This vulnerability in Apache Tomcat allows attackers to cause denial of service by exploiting the TLS handshake process to trigger OutOfMemoryError co...

Nov 7, 2024
CVE-2024-35231
8.6

CVE-2024-35231 is a denial-of-service vulnerability in rack-contrib middleware for Ruby web applications. Attackers can send malicious profiler_runs p...

May 27, 2024
CVE-2024-0081
8.6

This vulnerability in NVIDIA's NeMo framework allows attackers to cause unlimited resource allocation in the ASR web application component, leading to...

Apr 5, 2024
CVE-2024-30249
8.6

This vulnerability in Cloudburst Network allows attackers to use the software as an amplification vector for UDP denial-of-service attacks against thi...

Apr 4, 2024
CVE-2020-11862
8.6

This vulnerability in OpenText NetIQ Privileged Account Manager allows attackers to flood the system with requests, causing resource exhaustion and po...

Mar 13, 2024
CVE-2023-20033
8.6

This vulnerability in Cisco Catalyst 3650 and 3850 Series Switches running IOS XE allows unauthenticated remote attackers to cause a denial of service...

Sep 27, 2023
CVE-2023-36521
8.6

A denial-of-service vulnerability exists in Siemens SIMATIC machine vision systems where an attacker can disrupt all socket-based communication by exp...

Jul 11, 2023
CVE-2022-20751
8.6

This vulnerability in Cisco Firepower Threat Defense (FTD) Software allows an unauthenticated remote attacker to cause a denial of service (DoS) by ex...

May 3, 2022
CVE-2022-20622
8.6

This vulnerability allows unauthenticated remote attackers to cause Cisco Embedded Wireless Controllers with Catalyst Access Points to reload unexpect...

Apr 15, 2022
CVE-2021-28706
8.6

CVE-2021-28706 is an integer overflow vulnerability in Xen hypervisor memory management that allows virtual machine guests to exceed their allocated m...

Nov 24, 2021
CVE-2021-41593
8.6

This vulnerability in Lightning Network Daemon (lnd) allows attackers to exploit dust HTLCs (Hashed Time-Locked Contracts) to force channel closures a...

Oct 4, 2021
CVE-2021-41840
8.2

This vulnerability in Insyde InsydeH2O UEFI firmware allows attackers to execute arbitrary code in System Management Mode (SMM) through an SMM callout...

Feb 3, 2022
CVE-2025-48615
7.8

This vulnerability in Android's MediaButtonReceiverHolder component allows local privilege escalation without user interaction. An attacker could expl...

Dec 8, 2025
CVE-2021-47137
7.8

A memory corruption vulnerability in the Linux kernel's Lantiq network driver allows attackers to corrupt kernel memory when memory allocation or DMA ...

Mar 25, 2024
CVE-2021-29324
7.8

CVE-2021-29324 is a stack overflow vulnerability in Moddable v10.5.0's xsScript.c component that allows attackers to execute arbitrary code or cause d...

Nov 19, 2021
CVE-2024-46933
7.7

BullSequana XH2140 BMC systems were shipped with unconfigured AST2600 hardware, allowing privileged attackers to cause denial-of-service conditions. T...

Feb 20, 2025
CVE-2024-48843
7.7

This CVE describes a Denial of Service vulnerability in ABB's ASPECT, NEXUS, and MATRIX series products. Attackers can exploit this vulnerability to c...

Dec 5, 2024
CVE-2024-31446
7.7

This vulnerability in OpenComputers allows any user who can execute Lua code on mod devices to cause a denial-of-service by getting a Computer thread ...

Apr 16, 2024
CVE-2023-6563
7.7

An unconstrained memory consumption vulnerability in Keycloak allows attackers to cause denial of service by triggering excessive resource usage when ...

Dec 14, 2023
CVE-2023-36357
7.7

This vulnerability in TP-Link router web interface components allows attackers to cause denial of service via specially crafted GET requests. Affected...

Jun 22, 2023
CVE-2021-22246
7.7

This vulnerability allows attackers to abuse GitLab's webhook feature to perform denial-of-service attacks by sending specially crafted payloads that ...

Aug 20, 2021
CVE-2021-22532
7.6

This vulnerability in OpenText eDirectory allows attackers to cause a denial of service via NLDAP requests. It affects eDirectory versions before 9.2....

Sep 12, 2024
CVE-2026-27932
7.5

This vulnerability allows unauthenticated attackers to cause CPU exhaustion denial-of-service by sending specially crafted JWE tokens with extremely h...

Mar 3, 2026
CVE-2026-1662
7.5

An unauthenticated attacker can cause Denial of Service on GitLab instances by sending specially crafted requests to the Jira events endpoint. This af...

Feb 25, 2026
CVE-2026-27572
7.5

This vulnerability in Wasmtime's WASI HTTP implementation causes denial of service when excessive HTTP headers are processed. The runtime panics inste...

Feb 24, 2026
CVE-2026-25985
7.5

ImageMagick versions prior to 7.1.2-15 and 6.9.13-40 contain a memory allocation vulnerability in SVG processing. A malicious SVG file with a crafted ...

Feb 24, 2026
CVE-2019-25342
7.5

CVE-2019-25342 is a denial of service vulnerability in Centova Cast that allows attackers to overwhelm the system by repeatedly calling the database e...

Feb 12, 2026
CVE-2026-26076
7.5

This vulnerability allows remote attackers to cause moderate CPU usage spikes (2-4 times normal) on ntpd-rs servers with NTS enabled by sending malfor...

Feb 12, 2026
CVE-2025-8099
7.5

This vulnerability allows unauthenticated attackers to send repeated GraphQL queries to GitLab instances, causing denial of service by exhausting serv...

Feb 11, 2026
CVE-2026-1848
7.5

This vulnerability in MongoDB allows connections from proxy ports to bypass connection counting, potentially causing server crashes when connection li...

Feb 10, 2026
CVE-2025-61726
7.5

This vulnerability in Go's net/url package allows attackers to cause denial of service through memory exhaustion by sending HTTP requests with an exce...

Jan 28, 2026
CVE-2020-36949
7.5

CVE-2020-36949 is a denial of service vulnerability in TapinRadio 2.13.7 where attackers can crash the application by pasting large buffers (20,000+ c...

Jan 27, 2026
CVE-2021-47894
7.5

Managed Switch Port Mapping Tool 2.85.2 contains a buffer overflow vulnerability that allows attackers to crash the application by inputting oversized...

Jan 23, 2026
CVE-2021-47895
7.5

CVE-2021-47895 is a denial of service vulnerability in Nsauditor 3.2.2.0 where attackers can crash the application by inputting an overly large buffer...

Jan 23, 2026
CVE-2021-47893
7.5

AgataSoft PingMaster Pro 2.1 contains a denial of service vulnerability in its Trace Route feature. Attackers can crash the application by overflowing...

Jan 23, 2026
CVE-2025-67221
7.5

CVE-2025-67221 is a denial-of-service vulnerability in orjson's dumps function that allows attackers to crash applications by providing deeply nested ...

Jan 22, 2026
CVE-2025-13927
7.5

This vulnerability in GitLab allows unauthenticated attackers to cause denial of service by sending specially crafted requests with malformed authenti...

Jan 22, 2026
CVE-2026-24006
7.5

Seroval versions 1.4.0 and below have a stack overflow vulnerability when serializing deeply nested objects, causing denial of service. This affects a...

Jan 22, 2026

About CWE-770 (CWE-770)

Our database tracks 501 CVEs classified as CWE-770, with 6 rated critical and 271 rated high severity. The average CVSS score for CWE-770 vulnerabilities is 6.8.

External reference: View CWE-770 on MITRE CWE →

Monitor CWE-770 Vulnerabilities

Get alerted when new CWE-770 CVEs affect your infrastructure.

Start Monitoring Free