CWE-770: CWE-770

504
Total CVEs
6
Critical
274
High
6.8
Avg CVSS

Yearly Trend

2026
99
2025
213
2024
98
2023
51
2022
18

Top Affected Vendors

1 Gitlab 33
2 Ibm 25
3 Qnap 14
4 Oracle 14
5 Linux 13
6 F5 10
7 Cisco 9
8 Apple 9
9 Debian 9
10 Samsung 9

All CWE-770 CVEs (504)

CVE-2024-57664
7.5

This vulnerability in OpenLink Virtuoso Open-Source allows attackers to cause Denial of Service (DoS) by sending specially crafted SQL statements to t...

Jan 14, 2025
CVE-2024-54538
7.5

This CVE describes a denial-of-service vulnerability in multiple Apple operating systems where improper input validation allows a remote attacker to c...

Dec 20, 2024
CVE-2024-53907
7.5

This vulnerability in Django's strip_tags() method and striptags template filter allows attackers to cause denial-of-service by sending specially craf...

Dec 6, 2024
CVE-2024-53857
7.5

CVE-2024-53857 is a resource exhaustion vulnerability in rPGP, a pure Rust OpenPGP implementation. Attackers can craft malicious messages to cause den...

Dec 5, 2024
CVE-2024-11316
7.5

This CVE describes a file size check vulnerability in ABB ASPECT, NEXUS, and MATRIX series products that allows attackers to bypass file size limits. ...

Dec 5, 2024
CVE-2024-48080
7.5

A denial-of-service vulnerability in aedes MQTT broker v0.51.2 allows attackers to crash the service via specially crafted requests. The vulnerability...

Dec 3, 2024
CVE-2024-52805
7.5

Synapse Matrix homeserver versions before 1.120.1 have a vulnerability where multipart/form-data requests can cause excessive memory consumption in ce...

Dec 3, 2024
CVE-2024-37302
7.5

Synapse Matrix homeserver versions before 1.106 are vulnerable to a disk fill attack where unauthenticated attackers can force the server to download ...

Dec 3, 2024
CVE-2024-53981
7.5

CVE-2024-53981 is a denial-of-service vulnerability in python-multipart where attackers can send malicious multipart requests with excessive data befo...

Dec 2, 2024
CVE-2024-31669
7.5

Rizin versions before v0.6.3 contain a vulnerability in the PE binary parsing functions that allows attackers to cause uncontrolled resource consumpti...

Dec 2, 2024
CVE-2024-52581
7.5

Litestar multipart form parser versions before 2.13.0 have no default limit for request body size, allowing attackers to upload arbitrarily large file...

Nov 20, 2024
CVE-2024-48530
7.5

This vulnerability in eSoft Planner's Instructor Appointment Availability module allows attackers to cause a Denial of Service (DoS) by sending specia...

Nov 20, 2024
CVE-2024-52914
7.5

This vulnerability allows an attacker to stall Bitcoin Core nodes for hours by sending a specially crafted unconfirmed transaction that creates orphan...

Nov 18, 2024
CVE-2024-52916
7.5

Bitcoin Core versions before 0.15.0 are vulnerable to a denial-of-service attack where an attacker can flood the node with minimum difficulty headers,...

Nov 18, 2024
CVE-2024-52920
7.5

Bitcoin Core versions before 0.20.0 contain a vulnerability where remote attackers can send specially crafted GETDATA messages that cause the software...

Nov 18, 2024
CVE-2024-51428
7.5

This vulnerability in Espressif's ESP-IDF framework allows attackers to send specially crafted data channel packets that cause a denial of service con...

Nov 7, 2024
CVE-2024-48809
7.5

A remote attacker can cause denial of service in Open Networking Foundation's sdran-in-a-box and onos-a1t components by exploiting the DeleteWatcher f...

Nov 4, 2024
CVE-2024-45797
7.5

CVE-2024-45797 is a resource exhaustion vulnerability in LibHTP, a widely-used HTTP parser library. Attackers can send specially crafted HTTP requests...

Oct 16, 2024
CVE-2024-47502
7.5

An unauthenticated network attacker can cause a denial of service (DoS) on Juniper Junos OS Evolved by exploiting a resource exhaustion vulnerability ...

Oct 11, 2024
CVE-2024-43567
7.5

This vulnerability in Windows Hyper-V allows an authenticated attacker on a guest virtual machine to cause a denial of service condition on the Hyper-...

Oct 8, 2024
CVE-2024-47614
7.5

async-graphql before version 7.0.10 does not limit the number of directives that can be applied to a single GraphQL field. This allows attackers to cr...

Oct 3, 2024
CVE-2024-23185
7.5

This vulnerability in Dovecot allows attackers to cause resource exhaustion by sending emails with extremely large headers. The message-header-parser ...

Sep 10, 2024
CVE-2024-8391
7.5

This vulnerability allows attackers to send unlimited size payloads to Vert.x gRPC servers, potentially causing resource exhaustion and denial of serv...

Sep 4, 2024
CVE-2024-44083
7.5

IDA Pro versions through 8.4 contain a denial-of-service vulnerability in the ida64.dll component. When analyzing binaries with sections containing ma...

Aug 19, 2024
CVE-2024-39944
7.5

This vulnerability in Dahua products allows attackers to send specially crafted data packets to vulnerable interfaces, causing denial of service throu...

Jul 31, 2024
CVE-2024-0760
7.5

CVE-2024-0760 is a denial-of-service vulnerability in BIND DNS servers where malicious clients can send excessive TCP DNS queries, causing server inst...

Jul 23, 2024
CVE-2024-1975
7.5

This vulnerability allows attackers to cause denial of service by exhausting DNS resolver CPU resources through crafted SIG(0) signed requests targeti...

Jul 23, 2024
CVE-2024-38534
7.5

CVE-2024-38534 is a denial-of-service vulnerability in Suricata where specially crafted Modbus traffic can cause unlimited resource accumulation withi...

Jul 11, 2024
CVE-2024-33862
7.5

A memory exhaustion vulnerability in OPC Foundation's OPC UA .NET Standard library allows remote attackers to cause denial of service by sending exces...

Jul 5, 2024
CVE-2024-37298
7.5

This vulnerability in gorilla/schema allows attackers to cause memory exhaustion by exploiting sparse slice functionality when decoding structs contai...

Jul 1, 2024
CVE-2024-38528
7.5

CVE-2024-38528 is a denial-of-service vulnerability in ntpd-rs where an unauthenticated remote attacker can crash the service by exploiting missing co...

Jun 28, 2024
CVE-2024-3382
7.5

A memory leak vulnerability in Palo Alto Networks PAN-OS software allows attackers to send crafted packets that eventually cause the firewall to stop ...

Apr 10, 2024
CVE-2024-27316
7.5

This vulnerability in nghttp2's HTTP/2 implementation allows memory exhaustion attacks when clients send excessive headers. Attackers can cause denial...

Apr 4, 2024
CVE-2024-28871
7.5

CVE-2024-28871 is a denial-of-service vulnerability in LibHTP's HTTP parser where malformed request traffic causes excessive CPU usage. This affects a...

Apr 4, 2024
CVE-2024-22189
7.5

This vulnerability allows attackers to cause memory exhaustion in quic-go implementations by sending excessive NEW_CONNECTION_ID frames while manipula...

Apr 4, 2024
CVE-2024-28870
7.5

Suricata versions before 6.0.17 and 7.0.4 are vulnerable to a denial-of-service attack when processing excessively long SSH banners. Attackers can cau...

Apr 3, 2024
CVE-2023-43768
7.5

Unauthenticated attackers can send large commands to Couchbase Server's memcached component, causing memory exhaustion and denial of service. This aff...

Mar 27, 2024
CVE-2024-30156
7.5

This vulnerability allows attackers to exhaust HTTP/2 connection flow control windows in Varnish Cache, causing denial of service. It affects Varnish ...

Mar 24, 2024
CVE-2024-26461
7.5

CVE-2024-26461 is a memory leak vulnerability in Kerberos 5's GSSAPI sealing implementation that can lead to denial of service through resource exhaus...

Feb 29, 2024
CVE-2024-23836
7.5

CVE-2024-23836 is a resource exhaustion vulnerability in Suricata where attackers can craft malicious network traffic to cause excessive CPU and memor...

Feb 26, 2024
CVE-2024-23979
7.5

This vulnerability affects F5 BIG-IP systems configured with SSL Client Certificate LDAP or CRLDP authentication profiles. When exploited, it causes e...

Feb 14, 2024
CVE-2024-21771
7.5

This vulnerability in F5 BIG-IP AFM IPS engine causes denial of service when processing specific traffic patterns. The IPS engine spends excessive tim...

Feb 14, 2024
CVE-2023-50387
7.5

CVE-2023-50387 (KeyTrap) is a DNSSEC protocol vulnerability that allows remote attackers to cause denial of service by exhausting CPU resources throug...

Feb 14, 2024
CVE-2023-6516
7.5

This vulnerability in BIND 9 DNS resolver allows attackers to cause uncontrolled memory growth by triggering specific query patterns that overwhelm ca...

Feb 13, 2024
CVE-2023-52427
7.5

OpenDDS versions through 3.27 contain a vulnerability where configuring a DataWriter with an excessively large resource_limits.max_samples value cause...

Feb 11, 2024
CVE-2024-21604
7.5

An unauthenticated network attacker can cause a complete and persistent system outage on Juniper Junos OS Evolved by sending a high rate of specific v...

Jan 12, 2024
CVE-2024-21634
7.5

CVE-2024-21634 is a denial-of-service vulnerability in Amazon Ion's Java library (ion-java) where specially crafted Ion data can cause a StackOverflow...

Jan 3, 2024
CVE-2023-50455
7.5

This vulnerability in Zammad allows attackers to send excessive email verification requests to known addresses, causing denial of service through emai...

Dec 10, 2023
CVE-2023-6337
7.5

HashiCorp Vault versions 1.12.0 and newer are vulnerable to denial of service through memory exhaustion when processing large HTTP requests. Attackers...

Dec 8, 2023
CVE-2023-20155
7.5

This vulnerability in Cisco Firepower Management Center allows unauthenticated attackers to cause denial of service by overwhelming a logging API, pot...

Nov 1, 2023

About CWE-770 (CWE-770)

Our database tracks 504 CVEs classified as CWE-770, with 6 rated critical and 274 rated high severity. The average CVSS score for CWE-770 vulnerabilities is 6.8.

External reference: View CWE-770 on MITRE CWE →

Monitor CWE-770 Vulnerabilities

Get alerted when new CWE-770 CVEs affect your infrastructure.

Start Monitoring Free