CWE-770: CWE-770

505
Total CVEs
6
Critical
275
High
6.8
Avg CVSS

Yearly Trend

2026
99
2025
213
2024
98
2023
51
2022
18

Top Affected Vendors

1 Gitlab 33
2 Ibm 25
3 Oracle 15
4 Qnap 14
5 Linux 13
6 F5 10
7 Cisco 9
8 Apple 9
9 Debian 9
10 Samsung 9

All CWE-770 CVEs (505)

CVE-2023-45130
7.5

This vulnerability in Frontier (Substrate's Ethereum compatibility layer) allows attackers to craft contracts with excessive storage values and trigge...

Oct 13, 2023
CVE-2023-5072
7.5

CVE-2023-5072 is a denial-of-service vulnerability in JSON-Java library where specially crafted JSON input causes excessive memory consumption, potent...

Oct 12, 2023
CVE-2023-45142
7.5

OpenTelemetry-Go Contrib's otelhttp.NewHandler wrapper has unbound cardinality for HTTP method and User-Agent attributes, allowing attackers to send r...

Oct 12, 2023
CVE-2023-40542
7.5

This vulnerability in F5 BIG-IP systems allows attackers to cause memory exhaustion through specially crafted TCP requests when TCP Verified Accept is...

Oct 10, 2023
CVE-2023-45371
7.5

This vulnerability allows attackers to perform unlimited item merging operations in Wikibase, potentially disrupting data integrity and availability. ...

Oct 9, 2023
CVE-2023-43642
7.5

The snappy-java library is vulnerable to denial of service attacks when processing compressed data with maliciously large chunk sizes. This affects al...

Sep 25, 2023
CVE-2023-37279
7.5

This vulnerability allows denial of service attacks against Faktory web dashboard instances by sending crafted malicious URL query parameters. Attacke...

Sep 20, 2023
CVE-2023-38039
7.5

CVE-2023-38039 is a memory exhaustion vulnerability in curl/libcurl where a malicious server can send unlimited HTTP headers, causing curl to consume ...

Sep 15, 2023
CVE-2023-39322
7.5

This vulnerability in QUIC implementations allows malicious connections to cause unbounded memory growth by sending excessively large post-handshake m...

Sep 8, 2023
CVE-2023-39533
7.5

This vulnerability allows malicious peers to perform resource exhaustion attacks by sending large RSA keys during Noise handshake or x509 extension ve...

Aug 8, 2023
CVE-2023-39269
7.5

A denial-of-service vulnerability in the web server of multiple Siemens RUGGEDCOM industrial networking devices allows attackers to crash the web inte...

Aug 8, 2023
CVE-2023-36461
7.5

This vulnerability in Mastodon allows malicious servers to perform slowloris-type attacks by extending HTTP response durations indefinitely. This can ...

Jul 6, 2023
CVE-2023-36814
7.5

CVE-2023-36814 is a vulnerability in Products.CMFCore that allows unauthenticated attackers to cause denial of service and crashes by exploiting unsaf...

Jul 3, 2023
CVE-2023-36370
7.5

This vulnerability in MonetDB Server's gc_col component allows attackers to execute crafted SQL statements that cause a Denial of Service (DoS) by cra...

Jun 22, 2023
CVE-2023-36366
7.5

A vulnerability in MonetDB Server's log_create_delta component allows attackers to cause Denial of Service (DoS) by sending crafted SQL statements. Th...

Jun 22, 2023
CVE-2023-36368
7.5

A vulnerability in MonetDB Server's cs_bind_ubat component allows attackers to cause Denial of Service (DoS) by sending specially crafted SQL statemen...

Jun 22, 2023
CVE-2022-48498
7.5

This vulnerability involves configuration defects in the secure OS module of certain Huawei devices, allowing attackers to cause denial-of-service con...

Jun 19, 2023
CVE-2023-21144
7.5

This vulnerability in Android's notification system allows remote attackers to cause temporary denial of service by sending specially crafted notifica...

Jun 15, 2023
CVE-2023-2666
7.5

CVE-2023-2666 is an allocation of resources without limits vulnerability in Froxlor server management panel. Attackers can cause resource exhaustion (...

May 12, 2023
CVE-2023-31472
7.5

This CVE describes a command injection vulnerability in GL.iNet devices that allows attackers to create empty files anywhere on the filesystem. The vu...

May 9, 2023
CVE-2023-30455
7.5

This vulnerability allows attackers to cause a Denial-of-Service condition in ebankIT banking platforms by sending specially crafted requests with exc...

Apr 28, 2023
CVE-2023-0383
7.5

This vulnerability in M-Files Server allows attackers to cause denial of service through uncontrolled memory consumption. By sending specially crafted...

Apr 20, 2023
CVE-2018-15472
7.5

This vulnerability in GitLab allows attackers to cause denial of service by exploiting a timeout issue in the diff formatter using rouge in Sidekiq jo...

Apr 15, 2023
CVE-2023-30636
7.5

This vulnerability in TiKV allows remote attackers to cause denial of service by triggering a fatal error when attempting to start a node while exceed...

Apr 13, 2023
CVE-2023-26964
7.5

This vulnerability in hyper v0.13.7's h2-0.2.4 component causes excessive memory and CPU consumption when processing HTTP/2 RST_STREAM frames, leading...

Apr 11, 2023
CVE-2022-43768
7.5

A denial-of-service vulnerability exists in the webserver of multiple Siemens SIMATIC communication processors. Attackers can crash the webserver comp...

Apr 11, 2023
CVE-2023-28867
7.5

CVE-2023-28867 is a denial-of-service vulnerability in GraphQL Java (graphql-java) where an attacker can send a specially crafted GraphQL query that c...

Mar 27, 2023
CVE-2023-28119
7.5

CVE-2023-28119 is a denial-of-service vulnerability in the crewjam/saml Go library where unlimited decompression of SAML requests can crash the server...

Mar 22, 2023
CVE-2023-28104
7.5

This vulnerability in silverstripe/graphql allows attackers to execute denial-of-service attacks via specially crafted GraphQL queries. It primarily a...

Mar 16, 2023
CVE-2023-27900
7.5

This vulnerability in Jenkins allows attackers to cause denial of service by exploiting improper request handling in the Apache Commons FileUpload lib...

Mar 10, 2023
CVE-2022-31394
7.5

This vulnerability in Hyperium Hyper HTTP libraries allows attackers to perform HTTP/2 attacks by exploiting the inability to customize max_header_lis...

Feb 21, 2023
CVE-2023-26249
7.5

Knot Resolver before version 5.6.0 contains a resource consumption vulnerability where a single DNS query can trigger up to 100 TCP connection attempt...

Feb 21, 2023
CVE-2023-24998
7.5

Apache Commons FileUpload before version 1.5 has a denial-of-service vulnerability where attackers can overwhelm systems by sending unlimited file upl...

Feb 20, 2023
CVE-2023-25156
7.5

Kiwi TCMS versions before 12.0 lack rate limiting on the login page, allowing attackers to perform brute-force attacks against user credentials. This ...

Feb 15, 2023
CVE-2023-25578
7.5

CVE-2023-25578 is a denial-of-service vulnerability in Starlite ASGI framework where unauthenticated attackers can send specially crafted multipart re...

Feb 15, 2023
CVE-2023-25577
7.5

CVE-2023-25577 is a denial-of-service vulnerability in Werkzeug's multipart form data parser that allows attackers to cause high CPU and memory consum...

Feb 14, 2023
CVE-2023-25576
7.5

CVE-2023-25576 is a denial-of-service vulnerability in @fastify/multipart plugin where attackers can send unlimited multipart parts (files, fields, or...

Feb 14, 2023
CVE-2023-25193
7.5

This vulnerability in HarfBuzz text shaping engine allows attackers to cause denial of service through algorithmic complexity attacks. By providing sp...

Feb 4, 2023
CVE-2023-23969
7.5

This vulnerability in Django allows attackers to cause denial-of-service by sending HTTP requests with extremely large Accept-Language headers, which ...

Feb 1, 2023
CVE-2023-23846
7.5

CVE-2023-23846 is a denial-of-service vulnerability in Open5GS GTP library where specially crafted GTPv1-U messages with zero-length extension headers...

Feb 1, 2023
CVE-2022-22212
7.5

This CVE describes an unauthenticated resource exhaustion vulnerability in Juniper Junos OS Evolved's Packet Forwarding Engine. An attacker can send h...

Jul 20, 2022
CVE-2021-31645
7.5

This vulnerability in glFTPd 2.11a allows remote attackers to cause a denial of service by exceeding the connection limit, crashing the FTP server. It...

Jul 7, 2022
CVE-2022-22979
7.5

A caching vulnerability in Spring Cloud Function's Function Catalog component allows attackers to cause denial-of-service conditions by exploiting loo...

Jun 21, 2022
CVE-2021-35096
7.5

This vulnerability in Qualcomm Snapdragon chipsets involves improper memory allocation during counter check DLM handling, which can cause denial of se...

Jun 14, 2022
CVE-2022-22278
7.5

This vulnerability in SonicWall SonicOS CFS allows attackers to cause HTTP Denial of Service (DoS) by triggering large 403 forbidden responses when ac...

Apr 27, 2022
CVE-2021-44502
7.5

This vulnerability in FIS GT.M/YottaDB allows attackers to control the size parameter of a memset function through crafted input to util_format in sr_...

Apr 15, 2022
CVE-2022-21822
7.5

CVE-2022-21822 is a resource exhaustion vulnerability in NVIDIA FLARE's admin interface that allows unauthenticated attackers to cause denial of servi...

Mar 17, 2022
CVE-2021-32476
7.5

This vulnerability in Moodle's draft files area allows attackers to cause denial-of-service by bypassing user file upload limits. It affects Moodle in...

Mar 11, 2022
CVE-2022-24685
7.5

This vulnerability in HashiCorp Nomad allows attackers to submit specially crafted HCL job configurations to the jobs parse endpoint, causing excessiv...

Feb 28, 2022
CVE-2022-23228
7.5

CVE-2022-23228 is an improper WebRTC input validation vulnerability in Pexip Infinity that allows unauthenticated remote attackers to cause denial of ...

Feb 18, 2022

About CWE-770 (CWE-770)

Our database tracks 505 CVEs classified as CWE-770, with 6 rated critical and 275 rated high severity. The average CVSS score for CWE-770 vulnerabilities is 6.8.

External reference: View CWE-770 on MITRE CWE →

Monitor CWE-770 Vulnerabilities

Get alerted when new CWE-770 CVEs affect your infrastructure.

Start Monitoring Free