CWE-770: CWE-770

503
Total CVEs
6
Critical
273
High
6.8
Avg CVSS

Yearly Trend

2026
98
2025
213
2024
98
2023
51
2022
18

Top Affected Vendors

1 Gitlab 33
2 Ibm 25
3 Qnap 14
4 Oracle 14
5 Linux 13
6 F5 10
7 Cisco 9
8 Apple 9
9 Debian 9
10 Samsung 9

All CWE-770 CVEs (503)

CVE-2026-24006
7.5

Seroval versions 1.4.0 and below have a stack overflow vulnerability when serializing deeply nested objects, causing denial of service. This affects a...

Jan 22, 2026
CVE-2026-23962
7.5

Mastodon servers running vulnerable versions allow attackers to create remote posts with unlimited poll options, causing excessive resource consumptio...

Jan 22, 2026
CVE-2026-23957
7.5

CVE-2026-23957 is a denial-of-service vulnerability in seroval library versions 1.4.0 and below. Attackers can craft malicious serialized data with ma...

Jan 22, 2026
CVE-2021-47876
7.5

GeoGebra Classic 5.0.631.0-d contains a denial of service vulnerability where attackers can crash the application by pasting extremely large content (...

Jan 21, 2026
CVE-2021-47877
7.5

GeoGebra Graphing Calculator 6.0.631.0 contains a denial of service vulnerability where attackers can crash the application by inputting an oversized ...

Jan 21, 2026
CVE-2021-47865
7.5

CVE-2021-47865 is a denial of service vulnerability in ProFTPD that allows attackers to overwhelm FTP servers by creating multiple simultaneous connec...

Jan 21, 2026
CVE-2026-23490
7.5

This vulnerability in pyasn1 allows attackers to cause denial-of-service through memory exhaustion by sending malformed RELATIVE-OID data with excessi...

Jan 16, 2026
CVE-2021-47784
7.5

CVE-2021-47784 is a denial of service vulnerability in Cyberfox Web Browser where attackers can crash the application by pasting an excessively large ...

Jan 15, 2026
CVE-2021-47752
7.5

CVE-2021-47752 is a denial of service vulnerability in AWebServer GhostBuilding 18 that allows remote attackers to crash or render the server unrespon...

Jan 15, 2026
CVE-2026-0897
7.5

This vulnerability allows remote attackers to cause Denial of Service (DoS) by sending a specially crafted .keras archive with an extremely large data...

Jan 15, 2026
CVE-2025-37166
7.5

A vulnerability in HPE Networking Instant On Access Points allows attackers to send specially crafted packets that cause devices to become unresponsiv...

Jan 13, 2026
CVE-2025-50334
7.5

A vulnerability in Technitium DNS Server v13.5 allows remote attackers to trigger a denial of service condition by exploiting the rate-limiting compon...

Jan 8, 2026
CVE-2025-68151
7.5

CoreDNS servers running gRPC, HTTPS, or HTTP/3 protocols are vulnerable to denial-of-service attacks due to missing resource limits. Unauthenticated a...

Jan 8, 2026
CVE-2025-69228
7.5

This vulnerability in AIOHTTP allows attackers to craft malicious requests that cause uncontrolled memory consumption in servers using Request.post() ...

Jan 6, 2026
CVE-2022-50799
7.5

CVE-2022-50799 is a denial of service vulnerability in Fetch FTP Client 5.8.2 where attackers can send specially crafted FTP server responses exceedin...

Dec 30, 2025
CVE-2022-50695
7.5

This vulnerability allows unauthenticated attackers to abuse network diagnostic scripts (ping.php, traceroute.php, dns.php) in SOUND4 products to laun...

Dec 30, 2025
CVE-2021-47713
7.5

CVE-2021-47713 is a denial of service vulnerability in Hasura GraphQL Engine where attackers can craft malicious GraphQL queries with excessive nested...

Dec 22, 2025
CVE-2025-68156
7.5

This vulnerability in Expr for Go allows denial-of-service attacks through stack overflow panics. Attackers can crash applications by providing deeply...

Dec 16, 2025
CVE-2025-12562
7.5

This vulnerability allows unauthenticated attackers to send specially crafted GraphQL queries that bypass complexity limits, causing denial of service...

Dec 11, 2025
CVE-2025-66473
7.5

XWiki REST API lacks request size limits, allowing attackers to request all wiki pages in a single call. This can cause excessive memory consumption l...

Dec 10, 2025
CVE-2025-66418
7.5

This vulnerability in urllib3 allows a malicious HTTP server to send specially crafted compressed responses that cause excessive CPU usage and memory ...

Dec 5, 2025
CVE-2025-64334
7.5

This vulnerability in Suricata allows an attacker to cause unbounded memory growth by sending specially crafted compressed HTTP data, potentially lead...

Nov 26, 2025
CVE-2025-12571
7.5

This vulnerability allows unauthenticated attackers to cause Denial of Service (DoS) in GitLab by sending specially crafted JSON payloads. It affects ...

Nov 26, 2025
CVE-2025-65015
7.5

This vulnerability in the joserfc Python library allows attackers to cause denial-of-service through memory exhaustion by sending extremely large JWT ...

Nov 18, 2025
CVE-2025-13165
7.5

EasyFlow GP developed by Digiwin has an unauthenticated remote denial-of-service vulnerability. Attackers can send specific requests to crash the web ...

Nov 17, 2025
CVE-2025-64508
7.5

Bugsink versions before 2.0.5 are vulnerable to denial-of-service attacks via brotli compression bombs. Attackers can send specially crafted highly co...

Nov 10, 2025
CVE-2025-64509
7.5

This vulnerability allows attackers to cause denial of service in Bugsink error tracking systems by sending specially crafted Brotli-compressed envelo...

Nov 10, 2025
CVE-2025-11447
7.5

This vulnerability allows unauthenticated attackers to cause denial of service in GitLab instances by sending specially crafted GraphQL requests with ...

Oct 27, 2025
CVE-2025-12044
7.5

Vault and Vault Enterprise are vulnerable to unauthenticated denial of service attacks when processing JSON payloads due to a regression in rate limit...

Oct 23, 2025
CVE-2025-56223
7.5

CVE-2025-56223 is a denial-of-service vulnerability in SigningHub v8.6.8 where attackers can upload excessive files to the /Home/UploadStreamDocument ...

Oct 20, 2025
CVE-2025-59778
7.5

This vulnerability in F5OS-C partition control plane allows undisclosed traffic to cause multiple container terminations when the Allowed IP Addresses...

Oct 15, 2025
CVE-2025-53521
7.5

This vulnerability in BIG-IP APM allows undisclosed traffic to cause TMM (Traffic Management Microkernel) to terminate when an Access Policy is config...

Oct 15, 2025
CVE-2025-41430
7.5

This vulnerability in BIG-IP SSL Orchestrator allows undisclosed traffic to cause the Traffic Management Microkernel (TMM) to terminate, resulting in ...

Oct 15, 2025
CVE-2025-10004
7.5

This vulnerability allows attackers to send specially crafted GraphQL queries that request large repository blobs, causing GitLab instances to become ...

Oct 9, 2025
CVE-2025-11362
7.5

This vulnerability in pdfmake allows attackers to cause denial of service by embedding malicious URLs that trigger repeated redirects, consuming exces...

Oct 7, 2025
CVE-2025-8014
7.5

This CVE describes a GraphQL query complexity bypass vulnerability in GitLab EE/CE that allows unauthenticated attackers to send specially crafted que...

Sep 27, 2025
CVE-2025-10858
7.5

This vulnerability allows unauthenticated attackers to cause a Denial of Service (DoS) condition in GitLab by uploading specially crafted large JSON f...

Sep 26, 2025
CVE-2025-58446
7.5

A denial-of-service vulnerability in xgrammar library versions 0.1.23 allows attackers to cause resource exhaustion by processing large grammars (>100...

Sep 6, 2025
CVE-2025-9784
7.5

This vulnerability in Undertow allows malicious clients to send malformed requests that trigger server-side stream resets without incrementing abuse c...

Sep 2, 2025
CVE-2025-6203
7.5

CVE-2025-6203 is a denial-of-service vulnerability in HashiCorp Vault where specially crafted JSON payloads can cause excessive memory and CPU consump...

Aug 28, 2025
CVE-2025-2813
7.5

This vulnerability allows unauthenticated remote attackers to cause Denial of Service by flooding an HTTP service on port 80 with excessive requests. ...

Jul 31, 2025
CVE-2025-53629
7.5

This vulnerability in cpp-httplib allows attackers to send specially crafted HTTP requests with Transfer-Encoding: chunked headers that cause uncontro...

Jul 10, 2025
CVE-2025-53634
7.5

CVE-2025-53634 is a denial-of-service vulnerability in Chall-Manager's HTTP Gateway that allows unauthenticated attackers to perform slow loris attack...

Jul 10, 2025
CVE-2025-53530
7.5

WeGIA web manager for charitable institutions has a vulnerability where excessively long HTTP GET requests to a specific URL can cause high resource c...

Jul 7, 2025
CVE-2025-48367
7.5

This CVE describes a denial-of-service vulnerability in Redis where unauthenticated connections can cause repeated IP protocol errors, leading to clie...

Jul 7, 2025
CVE-2025-2403
7.5

A denial-of-service vulnerability in Hitachi Energy Relion 670/650 and SAM600-IO series devices allows attackers to disrupt network traffic prioritiza...

Jun 24, 2025
CVE-2025-3221
7.5

IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6 contain a resource exhaustion vulnerability due to insufficient validation of inc...

Jun 21, 2025
CVE-2025-4821
7.5

CVE-2025-4821 is a vulnerability in Cloudflare's quiche QUIC library that allows unauthenticated remote attackers to manipulate congestion control, po...

Jun 18, 2025
CVE-2025-48988
7.5

This CVE describes an allocation of resources without limits or throttling vulnerability in Apache Tomcat. Attackers can exploit this to cause denial ...

Jun 16, 2025
CVE-2025-25032
7.5

This vulnerability in IBM Cognos Analytics allows authenticated users to send specially crafted requests that exhaust memory resources, causing denial...

Jun 11, 2025

About CWE-770 (CWE-770)

Our database tracks 503 CVEs classified as CWE-770, with 6 rated critical and 273 rated high severity. The average CVSS score for CWE-770 vulnerabilities is 6.8.

External reference: View CWE-770 on MITRE CWE →

Monitor CWE-770 Vulnerabilities

Get alerted when new CWE-770 CVEs affect your infrastructure.

Start Monitoring Free