CWE-770: CWE-770

504
Total CVEs
6
Critical
274
High
6.8
Avg CVSS

Yearly Trend

2026
99
2025
213
2024
98
2023
51
2022
18

Top Affected Vendors

1 Gitlab 33
2 Ibm 25
3 Qnap 14
4 Oracle 14
5 Linux 13
6 F5 10
7 Cisco 9
8 Apple 9
9 Debian 9
10 Samsung 9

All CWE-770 CVEs (504)

CVE-2025-25032
7.5

This vulnerability in IBM Cognos Analytics allows authenticated users to send specially crafted requests that exhaust memory resources, causing denial...

Jun 11, 2025
CVE-2025-29872
7.5

This vulnerability in QNAP File Station 5 allows authenticated attackers to exhaust system resources through uncontrolled resource allocation. Attacke...

Jun 6, 2025
CVE-2018-25112
7.5

CVE-2018-25112 allows unauthenticated remote attackers to cause denial-of-service on affected industrial control systems by flooding them with network...

Jun 4, 2025
CVE-2025-0993
7.5

This vulnerability in GitLab CE/EE allows authenticated attackers to trigger a denial of service by exhausting server resources. All GitLab instances ...

May 22, 2025
CVE-2025-4416
7.5

This vulnerability in Drupal Events Log Track module allows attackers to cause excessive resource allocation without limits, potentially leading to de...

May 21, 2025
CVE-2025-36504
7.5

This vulnerability affects F5 BIG-IP systems with HTTP/2 httprouter profiles configured on virtual servers. Undisclosed HTTP/2 responses can cause mem...

May 7, 2025
CVE-2025-30202
7.5

CVE-2025-30202 exposes vLLM's internal state data and enables denial of service attacks in multi-node deployments. The vulnerability allows unauthoriz...

Apr 30, 2025
CVE-2025-21605
7.5

CVE-2025-21605 is a memory exhaustion vulnerability in Redis where unauthenticated clients can cause unlimited growth of output buffers, leading to se...

Apr 23, 2025
CVE-2025-32380
7.5

A denial-of-service vulnerability in Apollo Router Core allows attackers to craft GraphQL queries with deeply nested and reused named fragments that c...

Apr 9, 2025
CVE-2025-26682
EPSS 49.1% 7.5

This CVE describes a resource exhaustion vulnerability in ASP.NET Core where an attacker can send specially crafted requests to consume excessive serv...

Apr 8, 2025
CVE-2025-32030
7.5

A denial-of-service vulnerability in Apollo Gateway allows attackers to craft GraphQL queries with deeply nested and reused named fragments that cause...

Apr 7, 2025
CVE-2025-32032
7.5

A denial-of-service vulnerability in Apollo Router allows attackers to craft GraphQL queries with deeply nested and reused named fragments that bypass...

Apr 7, 2025
CVE-2025-32034
7.5

A denial-of-service vulnerability in Apollo Router Core allows attackers to craft GraphQL queries with deeply nested and reused named fragments that c...

Apr 7, 2025
CVE-2025-31496
7.5

A vulnerability in Apollo Compiler versions before 1.27.0 allows attackers to craft GraphQL queries with deeply nested and reused named fragments that...

Apr 7, 2025
CVE-2025-1451
7.5

This vulnerability in parisneo/lollms-webui allows attackers to cause denial of service by sending specially crafted file upload requests with excessi...

Mar 20, 2025
CVE-2025-0315
7.5

A memory exhaustion vulnerability in Ollama allows attackers to upload specially crafted GGUF model files that cause unlimited memory allocation, lead...

Mar 20, 2025
CVE-2025-0189
7.5

This vulnerability allows attackers to cause denial of service in aimhubio/aim tracking servers by sending oversized websocket messages containing lar...

Mar 20, 2025
CVE-2025-0182
7.5

This vulnerability in danswer-ai/danswer version 0.9.0 allows attackers to cause denial of service through memory exhaustion by sending multiple reque...

Mar 20, 2025
CVE-2024-9437
7.5

SuperAGI v0.0.14 is vulnerable to an unauthenticated Denial of Service attack where attackers can crash the service by sending specially crafted HTTP ...

Mar 20, 2025
CVE-2024-9229
7.5

This vulnerability allows unauthenticated attackers to cause a Denial of Service (DoS) by sending specially crafted HTTP requests with manipulated mul...

Mar 20, 2025
CVE-2024-8984
7.5

This vulnerability allows unauthenticated attackers to cause a Denial of Service (DoS) by sending specially crafted HTTP requests with appended charac...

Mar 20, 2025
CVE-2024-8028
7.5

A vulnerability in Danswer AI v0.3.94 allows attackers to cause Denial of Service (DoS) by uploading files with malformed multipart boundaries contain...

Mar 20, 2025
CVE-2024-7983
7.5

This vulnerability in open-webui version 0.3.8 exposes an unauthenticated markdown-to-HTML conversion endpoint. Attackers can send specially crafted m...

Mar 20, 2025
CVE-2024-7768
7.5

A denial-of-service vulnerability in h2o-3's ImportFiles endpoint allows attackers to recursively call the endpoint via the 'path' parameter, filling ...

Mar 20, 2025
CVE-2024-12778
7.5

This vulnerability allows attackers to cause denial of service (DoS) by making API requests for large numbers of tracked metrics simultaneously. The A...

Mar 20, 2025
CVE-2024-12537
7.5

This vulnerability in open-webui version 0.3.32 allows unauthenticated attackers to send large POST requests to the /api/v1/utils/code/format endpoint...

Mar 20, 2025
CVE-2024-11171
7.5

This vulnerability allows unauthenticated attackers to crash LibreChat servers by uploading large files, causing denial of service through out-of-memo...

Mar 20, 2025
CVE-2024-10935
7.5

CVE-2024-10935 is a denial-of-service vulnerability in automatic1111/stable-diffusion-webui where malformed multipart requests with excessive boundary...

Mar 20, 2025
CVE-2025-29786
7.5

CVE-2025-29786 is a denial-of-service vulnerability in the Expr expression language for Go where unbounded input strings can cause excessive memory co...

Mar 17, 2025
CVE-2025-20209
7.5

An unauthenticated remote attacker can send malformed IKEv2 packets to Cisco IOS XR devices, causing them to stop processing all control plane UDP pac...

Mar 12, 2025
CVE-2025-27513
7.5

A vulnerability in OpenTelemetry.Api for .NET versions 1.10.0 to 1.11.1 causes Denial of Service when processing HTTP requests containing tracestate a...

Mar 5, 2025
CVE-2025-27419
7.5

CVE-2025-27419 is a denial-of-service vulnerability in WeGIA web management software that allows unauthenticated attackers to crash servers through ag...

Mar 3, 2025
CVE-2025-22869
7.5

SSH servers implementing file transfer protocols (like SFTP/SCP) are vulnerable to a resource exhaustion denial-of-service attack. Malicious clients c...

Feb 26, 2025
CVE-2025-1059
7.5

A resource allocation vulnerability in Schneider Electric devices allows attackers to send malicious packets to the webserver, causing denial of servi...

Feb 13, 2025
CVE-2025-24312
7.5

This vulnerability in BIG-IP AFM with IPS module enabled allows undisclosed traffic to cause excessive CPU utilization, potentially leading to denial ...

Feb 5, 2025
CVE-2024-2878
7.5

This vulnerability in GitLab CE/EE allows attackers to cause denial of service by crafting malicious search terms for branch names. The attack exploit...

Feb 5, 2025
CVE-2024-12705
7.5

This vulnerability allows attackers to cause denial-of-service (DoS) against DNS resolvers by flooding them with crafted HTTP/2 traffic over DNS-over-...

Jan 29, 2025
CVE-2024-56316
7.5

This vulnerability allows remote unauthenticated attackers to send crafted TR069 requests to AXESS ACS servers, causing permanent Denial of Service th...

Jan 27, 2025
CVE-2024-55195
7.5

CVE-2024-55195 is an allocation-size-too-big vulnerability in OpenImageIO's image buffer component that can cause denial of service through excessive ...

Jan 23, 2025
CVE-2025-24033
7.5

This vulnerability in @fastify/multipart plugin causes temporary uploaded files to persist on disk when users cancel multipart requests, leading to di...

Jan 23, 2025
CVE-2025-0635
7.5

CVE-2025-0635 is a denial-of-service vulnerability in M-Files Server that allows unauthenticated attackers to consume computing resources, potentially...

Jan 23, 2025
CVE-2024-57722
7.5

Lunasvg v3.0.0 contains an allocation-size-too-big vulnerability in the plutovg_surface_create component that can lead to denial of service or potenti...

Jan 23, 2025
CVE-2025-21521
7.5

This vulnerability in MySQL Server's thread pooling component allows unauthenticated attackers with network access to cause a denial of service by cra...

Jan 21, 2025
CVE-2024-41743
7.5

This vulnerability in IBM TXSeries for Multiplatforms 10.1 allows remote attackers to cause denial of service by exploiting improper resource allocati...

Jan 19, 2025
CVE-2024-45662
7.5

This vulnerability in IBM Safer Payments allows remote attackers to cause denial of service by exploiting improper resource allocation. It affects IBM...

Jan 18, 2025
CVE-2018-25108
7.5

CVE-2018-25108 allows unauthenticated remote attackers to cause a denial-of-service (DoS) in affected controllers by exhausting system resources. This...

Jan 16, 2025
CVE-2024-46667
7.5

This vulnerability in Fortinet FortiSIEM allows attackers to cause denial of service by consuming all available TLS connections through resource alloc...

Jan 14, 2025
CVE-2024-46668
7.5

This CVE describes a resource exhaustion vulnerability in FortiOS where an unauthenticated remote attacker can cause a denial-of-service by uploading ...

Jan 14, 2025
CVE-2024-57662
7.5

This vulnerability in the sqlg_hash_source component of OpenLink Virtuoso OpenSource allows attackers to cause Denial of Service (DoS) by sending spec...

Jan 14, 2025
CVE-2024-57663
7.5

A vulnerability in the sqlg_place_dpipes component of OpenLink Virtuoso OpenSource allows attackers to cause Denial of Service (DoS) through specially...

Jan 14, 2025

About CWE-770 (CWE-770)

Our database tracks 504 CVEs classified as CWE-770, with 6 rated critical and 274 rated high severity. The average CVSS score for CWE-770 vulnerabilities is 6.8.

External reference: View CWE-770 on MITRE CWE →

Monitor CWE-770 Vulnerabilities

Get alerted when new CWE-770 CVEs affect your infrastructure.

Start Monitoring Free