CWE-770: CWE-770

507
Total CVEs
6
Critical
277
High
6.8
Avg CVSS

Yearly Trend

2026
99
2025
213
2024
98
2023
51
2022
18

Top Affected Vendors

1 Gitlab 33
2 Ibm 25
3 Oracle 15
4 Qnap 14
5 Linux 13
6 F5 10
7 Cisco 9
8 Apple 9
9 Samsung 9
10 Debian 9

All CWE-770 CVEs (507)

CVE-2022-23228
7.5

CVE-2022-23228 is an improper WebRTC input validation vulnerability in Pexip Infinity that allows unauthenticated remote attackers to cause denial of ...

Feb 18, 2022
CVE-2021-22050
7.5

CVE-2021-22050 is a slow HTTP POST denial-of-service vulnerability in VMware ESXi's rhttpproxy service. Attackers with network access can overwhelm th...

Feb 16, 2022
CVE-2022-23913
7.5

This vulnerability in Apache ActiveMQ Artemis allows attackers to cause a denial-of-service (DoS) condition by consuming excessive memory resources. S...

Feb 4, 2022
CVE-2021-39480
7.5

Bingrep v0.8.5 contains a memory allocation failure vulnerability that can cause the application to crash, resulting in Denial of Service. This affect...

Jan 21, 2022
CVE-2021-43045
7.5

This vulnerability in Apache Avro's .NET SDK allows attackers to cause denial-of-service by forcing excessive resource allocation. It affects .NET app...

Jan 6, 2022
CVE-2021-37111
7.5

CVE-2021-37111 is a memory leak vulnerability affecting certain Huawei smartphones running HarmonyOS. Successful exploitation could lead to memory exh...

Jan 3, 2022
CVE-2021-45699
7.5

This vulnerability in the ckb crate for Rust allows remote attackers to potentially conduct a 51% attack against the Nervos CKB blockchain by exhausti...

Dec 27, 2021
CVE-2021-41799
7.5

CVE-2021-41799 is a denial-of-service vulnerability in MediaWiki's ApiQueryBacklinks feature that allows attackers to trigger full table scans, consum...

Oct 11, 2021
CVE-2021-32675
7.5

CVE-2021-32675 is a memory allocation vulnerability in Redis where specially crafted RESP protocol requests can cause excessive memory consumption, po...

Oct 4, 2021
CVE-2021-34415
7.5

This vulnerability in Zoom On-Premise Meeting Connector Controller allows attackers to crash the Zone Controller service by sending specially crafted ...

Sep 27, 2021
CVE-2021-22029
7.5

This vulnerability allows attackers with access to the VMware Workspace ONE UEM REST API to cause denial of service by exploiting improper rate limiti...

Aug 31, 2021
CVE-2018-10790
7.5

This vulnerability in Bento4's AP4_CttsAtom class allows remote attackers to cause denial of service through application crashes by triggering memory ...

Aug 25, 2021
CVE-2021-36798
7.5

A Denial-of-Service vulnerability in Cobalt Strike Team Server allows remote attackers to crash the C2 server thread, blocking beacon communications. ...

Aug 9, 2021
CVE-2021-22919
7.5

This vulnerability in Citrix ADC, Gateway, and SD-WAN WANOP appliances allows attackers to consume all available disk space through resource exhaustio...

Aug 5, 2021
CVE-2021-0285
7.5

This vulnerability allows attackers to cause denial of service on Juniper QFX5000 and EX4600 switches by sending large amounts of legitimate traffic t...

Jul 15, 2021
CVE-2021-29725
7.5

This vulnerability in IBM Secure External Authentication Server and IBM Secure Proxy allows remote attackers to cause a denial of service by consuming...

Jul 15, 2021
CVE-2020-28400
7.5

This vulnerability allows unauthenticated attackers to cause denial of service by flooding affected Siemens devices with DCP reset packets. The attack...

Jul 13, 2021
CVE-2021-36155
7.5

CVE-2021-36155 is a denial-of-service vulnerability in gRPC Swift's LengthPrefixedMessageReader that allows remote attackers to cause uncontrolled res...

Jul 9, 2021
CVE-2021-22363
7.5

This vulnerability in Huawei eCNS280_TD devices allows attackers to cause service disruption through improper resource management. Attackers need spec...

Jun 22, 2021
CVE-2021-29061
7.5

This CVE describes a Regular Expression Denial of Service (ReDoS) vulnerability in vfsjfilechooser2 library versions 0.2.9 and below. Attackers can cr...

Jun 21, 2021
CVE-2021-29059
7.5

This vulnerability allows attackers to cause a Denial of Service (DoS) by providing a specially crafted invalid SVG string to the is-svg library. The ...

Jun 21, 2021
CVE-2021-27383
7.5

This vulnerability is a heap allocation leak in the SmartVNC Tight encoder affecting Siemens industrial HMI panels and drives. It allows attackers to ...

May 12, 2021
CVE-2021-28302
7.5

This CVE describes a stack overflow vulnerability in the pupnp library's XML parser that can be triggered by maliciously crafted documents. When explo...

Mar 12, 2021
CVE-2020-28491
7.5

This vulnerability in Jackson CBOR data format library allows attackers to cause denial of service through memory exhaustion by sending specially craf...

Feb 18, 2021
CVE-2020-36049
7.5

This vulnerability in socket.io-parser allows attackers to cause denial of service through memory exhaustion by sending specially crafted large packet...

Jan 8, 2021
CVE-2025-68136
7.4

This vulnerability in EVerest EV charging software allows attackers to cause denial of service through null pointer dereference when handling SDP requ...

Jan 21, 2026
CVE-2025-68133
7.4

This vulnerability in EVerest EV charging software allows attackers to cause denial of service by exhausting system memory through unlimited TCP conne...

Jan 21, 2026
CVE-2025-20141
7.4

An unauthenticated adjacent attacker can send specially crafted packets to Cisco IOS XR devices, causing control plane traffic to stop working. This a...

Mar 12, 2025
CVE-2021-1285
7.4

This vulnerability in Cisco products allows an unauthenticated attacker on the same network to send malicious Ethernet frames that exhaust disk space,...

Nov 18, 2024
CVE-2023-20067
7.4

An unauthenticated attacker on the same network can send crafted traffic through a wireless access point to exploit insufficient input validation in C...

Mar 23, 2023
CVE-2023-38507
7.3

This vulnerability allows attackers to bypass rate limiting on Strapi's admin login function, enabling brute force attacks to guess credentials. It af...

Sep 15, 2023
CVE-2022-28655
7.1

CVE-2022-28655 is a vulnerability in the is_closing_session() function that allows users to create arbitrary TCP D-Bus connections, potentially bypass...

Jun 4, 2024
CVE-2024-34027
7.0

This CVE addresses a race condition in the Linux kernel's F2FS filesystem compression feature where the reserve_compress_blocks() and release_compress...

Jun 24, 2024
CVE-2025-31990
6.8

HCL Velocity lacks rate limiting on certain API calls, allowing attackers to flood the system with requests and cause denial of service. This affects ...

Feb 7, 2026
CVE-2025-11044
6.8

An unauthenticated attacker on the network can exploit a race condition in the ANSL-Server component of B&R Automation Runtime to cause permanent deni...

Jan 19, 2026
CVE-2025-14435
6.8

This vulnerability allows authenticated Mattermost users to trigger infinite component re-render loops when API errors occur, causing application-leve...

Jan 16, 2026
CVE-2024-32874
6.8

CVE-2024-32874 is a denial-of-service vulnerability in Frigate NVR software where attackers can crash the application by uploading files with excessiv...

May 14, 2024
CVE-2025-36035
6.7

This vulnerability in IBM PowerVM Hypervisor allows a local privileged user to cause denial of service through specially crafted IBM i hypervisor call...

Sep 14, 2025
CVE-2026-2845
6.5

This vulnerability allows authenticated users to cause denial of service in GitLab by exploiting a Bitbucket Server import endpoint. Attackers can rep...

Feb 25, 2026
CVE-2026-26312
6.5

A denial-of-service vulnerability in Stalwart Mail Server allows attackers to crash the server by sending specially crafted emails with malformed nest...

Feb 19, 2026
CVE-2025-57708
6.5

This vulnerability in Qsync Central allows authenticated remote attackers to perform resource exhaustion attacks by allocating resources without limit...

Feb 11, 2026
CVE-2026-1387
6.5

This vulnerability allows authenticated GitLab users to cause Denial of Service by uploading malicious files and repeatedly querying them through Grap...

Feb 11, 2026
CVE-2026-1456
6.5

This vulnerability allows unauthenticated attackers to cause denial of service through CPU exhaustion by submitting specially crafted markdown files t...

Feb 11, 2026
CVE-2026-1850
6.5

This vulnerability allows attackers to crash MongoDB servers by sending complex queries that trigger excessive memory usage in the query planner. All ...

Feb 10, 2026
CVE-2025-15317
6.5

CVE-2025-15317 is an uncontrolled resource consumption vulnerability in Tanium Server that allows attackers to cause denial of service by exhausting s...

Feb 9, 2026
CVE-2025-32393
6.5

AutoGPT versions before beta-v0.6.32 contain a denial-of-service vulnerability in the ReadRSSFeedBlock component. Attackers can trigger resource exhau...

Feb 5, 2026
CVE-2026-24514
6.5

This CVE describes a denial-of-service vulnerability in ingress-nginx's validating admission controller. Attackers can send large requests to exhaust ...

Feb 3, 2026
CVE-2026-24133
6.5

This vulnerability in jsPDF allows attackers to cause denial of service by providing malicious BMP files with large width/height values in their heade...

Feb 2, 2026
CVE-2026-20406
6.5

This vulnerability allows remote denial of service attacks against devices with affected MediaTek modems. An attacker can crash the system by connecti...

Feb 2, 2026
CVE-2025-36387
6.5

This vulnerability in IBM Db2 allows authenticated users to cause denial of service by submitting specially crafted queries. It affects Db2 versions 1...

Jan 30, 2026

About CWE-770 (CWE-770)

Our database tracks 507 CVEs classified as CWE-770, with 6 rated critical and 277 rated high severity. The average CVSS score for CWE-770 vulnerabilities is 6.8.

External reference: View CWE-770 on MITRE CWE →

Monitor CWE-770 Vulnerabilities

Get alerted when new CWE-770 CVEs affect your infrastructure.

Start Monitoring Free