CWE-770: CWE-770

508
Total CVEs
6
Critical
278
High
6.8
Avg CVSS

Yearly Trend

2026
99
2025
213
2024
98
2023
51
2022
18

Top Affected Vendors

1 Gitlab 33
2 Ibm 25
3 Oracle 15
4 Qnap 14
5 Linux 13
6 F5 10
7 Cisco 9
8 Apple 9
9 Samsung 9
10 Debian 9

All CWE-770 CVEs (508)

CVE-2025-1072
6.5

A denial-of-service vulnerability in GitLab CE/EE allows attackers to crash the service by importing maliciously crafted content via the Fogbugz impor...

Feb 7, 2025
CVE-2024-54497
6.5

This vulnerability in Apple operating systems allows processing malicious web content to cause denial-of-service conditions. It affects users of iOS, ...

Jan 27, 2025
CVE-2024-43708
6.5

This vulnerability allows authenticated users with read access to Kibana to send specially crafted payloads that cause resource exhaustion, leading to...

Jan 23, 2025
CVE-2025-21522
6.5

A vulnerability in MySQL Server's parser component allows authenticated attackers with network access to cause denial of service by crashing or hangin...

Jan 21, 2025
CVE-2025-21509
6.5

This vulnerability allows authenticated attackers with low privileges to cause a denial of service (DoS) in Oracle JD Edwards EnterpriseOne Tools by s...

Jan 21, 2025
CVE-2025-21501
6.5

This vulnerability in MySQL Server's optimizer component allows authenticated attackers with low privileges to cause denial of service by crashing or ...

Jan 21, 2025
CVE-2024-43709
6.5

This vulnerability in Elasticsearch allows attackers to cause a denial of service by sending specially crafted SQL queries that trigger excessive memo...

Jan 21, 2025
CVE-2024-52918
6.5

This vulnerability in Bitcoin Core's Bitcoin-Qt client allows remote attackers to cause denial of service by exploiting the BIP21 URI scheme. Attacker...

Nov 18, 2024
CVE-2024-6826
6.5

This vulnerability in GitLab allows attackers to cause denial of service by importing malicious XML manifest files. It affects all GitLab Community Ed...

Oct 24, 2024
CVE-2024-50311
6.5

This CVE describes a denial-of-service vulnerability in OpenShift's GraphQL batching functionality. Attackers can send requests containing thousands o...

Oct 22, 2024
CVE-2024-47508
6.5

This CVE describes a resource exhaustion vulnerability in Juniper Junos OS Evolved where authenticated attackers can cause FPC crashes through specifi...

Oct 11, 2024
CVE-2024-5210
6.5

An unauthenticated denial-of-service vulnerability in certain Lenovo printers allows attackers on the same network to make printer services unreachabl...

Aug 16, 2024
CVE-2024-4782
6.5

An unauthenticated denial-of-service vulnerability in some Lenovo printers allows attackers on the same network to disrupt printer functionality until...

Aug 16, 2024
CVE-2024-6598
6.5

This vulnerability allows authenticated attackers with job execution privileges to trigger a denial-of-service condition in KNIME Business Hub. By exe...

Jul 9, 2024
CVE-2024-37681
6.5

This vulnerability in Shanxi Internet Chuangxiang Technology Co., Ltd's background management system v1.0.1 allows remote attackers to cause denial of...

Jun 24, 2024
CVE-2024-5208
6.5

An uncontrolled resource consumption vulnerability in the 'upload-link' endpoint of mintplex-labs/anything-llm allows authenticated users with Manager...

Jun 19, 2024
CVE-2024-31881
6.5

This vulnerability allows an authenticated user to crash IBM Db2 servers by executing a specially crafted query against certain columnar tables. It af...

Jun 12, 2024
CVE-2024-33495
6.5

This vulnerability in SIMATIC RTLS Locating Manager allows unauthenticated remote attackers to cause denial of service by flooding the system with exc...

May 14, 2024
CVE-2025-14525
6.4

A vulnerability in kubevirt allows authenticated VM users with guest agent access to cause a denial of service by overwhelming the system with excessi...

Jan 26, 2026
CVE-2024-6600
6.3

This vulnerability in Angle's GLSL shader memory allocation on macOS allows out-of-bounds memory access when allocating large amounts of private shade...

Jul 9, 2024
CVE-2025-58340
6.2

This vulnerability in Samsung Exynos Wi-Fi drivers allows attackers to cause kernel memory exhaustion through unbounded memory allocation. Attackers c...

Feb 3, 2026
CVE-2025-58341
6.2

This vulnerability in Samsung Exynos Wi-Fi drivers allows attackers to cause kernel memory exhaustion through unbounded memory allocation. Attackers c...

Feb 3, 2026
CVE-2025-58342
6.2

This vulnerability in Samsung Exynos Wi-Fi drivers allows attackers to cause kernel memory exhaustion through unbounded memory allocation. Attackers c...

Feb 3, 2026
CVE-2025-58344
6.2

This vulnerability allows attackers to cause kernel memory exhaustion through unbounded memory allocation in the Wi-Fi driver's /proc/driver/unifi0/co...

Feb 3, 2026
CVE-2025-36123
6.2

This vulnerability in IBM Db2 allows a local user to cause a denial of service by copying large tables containing XML data, due to improper system res...

Jan 30, 2026
CVE-2025-29917
6.2

Suricata's decode_base64 keyword has insufficient memory allocation limits, allowing attackers to trigger excessive memory consumption up to 4GB per t...

Apr 10, 2025
CVE-2024-25969
6.2

Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contain a resource allocation vulnerability where an attacker can cause denial of service by exha...

May 14, 2024
CVE-2026-27729
5.9

This vulnerability in Astro web framework allows unauthenticated attackers to cause denial of service through memory exhaustion. By sending oversized ...

Feb 24, 2026
CVE-2026-22045
5.9

This vulnerability allows unauthenticated attackers to cause denial of service in Traefik reverse proxy by exploiting the ACME TLS-ALPN challenge mech...

Jan 15, 2026
CVE-2026-22036
5.9

This vulnerability in Undici HTTP client allows a malicious server to send specially crafted compressed responses that force the client to perform exc...

Jan 14, 2026
CVE-2025-66560
5.9

A thread exhaustion vulnerability in Quarkus REST HTTP layer causes worker threads to become permanently blocked when client connections drop during r...

Jan 7, 2026
CVE-2025-59089
5.9

This vulnerability in kdcproxy allows denial-of-service attacks when an attacker can redirect connections to a malicious KDC server. Attackers can sen...

Nov 12, 2025
CVE-2024-36378
5.9

JetBrains TeamCity servers before version 2024.03.2 are vulnerable to denial-of-service attacks when receiving malformed authentication tokens. This v...

May 29, 2024
CVE-2024-56374
5.8

This vulnerability in Django allows attackers to cause denial-of-service by sending specially crafted IPv6 addresses to vulnerable validation function...

Jan 14, 2025
CVE-2025-4437
5.7

This CVE describes a denial-of-service vulnerability in CRI-O where launching a container with a non-existent runAsUser causes CRI-O to read the entir...

Aug 20, 2025
CVE-2025-25207
5.7

CVE-2025-25207 is a denial-of-service vulnerability in Red Hat Connectivity Link's Authorino service where attackers with developer access can overloa...

Jun 9, 2025
CVE-2026-29612
5.5

OpenClaw versions before 2026.2.14 have a memory allocation vulnerability where base64-encoded media files are fully decoded before size limits are en...

Mar 5, 2026
CVE-2026-28452
5.5

OpenClaw versions before 2026.2.14 contain a denial of service vulnerability where attackers can send malicious ZIP or TAR archives during install/upd...

Mar 5, 2026
CVE-2025-14876
5.5

A vulnerability in QEMU's virtio-crypto device allows malicious guest operating systems to trigger uncontrolled memory allocation via the AKCIPHER pat...

Feb 18, 2026
CVE-2026-20608
5.5

This CVE describes a memory management vulnerability in Apple's WebKit browser engine that could cause unexpected process crashes when processing mali...

Feb 11, 2026
CVE-2025-58345
5.5

This vulnerability in Samsung Exynos Wi-Fi drivers allows attackers to cause kernel memory exhaustion through unbounded memory allocation when writing...

Feb 3, 2026
CVE-2025-58346
5.5

This vulnerability allows attackers to cause kernel memory exhaustion through unbounded memory allocation in the Wi-Fi driver of affected Samsung Exyn...

Feb 3, 2026
CVE-2025-58347
5.5

This vulnerability allows attackers to cause kernel memory exhaustion through unbounded memory allocation in the Wi-Fi driver of affected Samsung Exyn...

Feb 3, 2026
CVE-2025-58348
5.5

This vulnerability in Samsung Exynos Wi-Fi drivers allows attackers to cause kernel memory exhaustion through unbounded memory allocation. Attackers c...

Feb 3, 2026
CVE-2025-58343
5.5

This vulnerability in Samsung Exynos Wi-Fi drivers allows attackers to trigger unbounded memory allocation through a /proc filesystem operation, poten...

Feb 3, 2026
CVE-2021-47771
5.5

CVE-2021-47771 is a denial of service vulnerability in RDP Manager 4.9.9.3 where local attackers can crash the application by entering oversized text ...

Jan 15, 2026
CVE-2025-48569
5.5

This vulnerability allows local attackers to cause permanent denial of service through resource exhaustion without requiring elevated privileges or us...

Dec 8, 2025
CVE-2025-48603
5.5

This vulnerability in Android's InputMethodInfo component allows local resource exhaustion leading to permanent denial of service. It affects Android ...

Dec 8, 2025
CVE-2025-63402
5.5

This vulnerability in HCLTech GRAGON allows remote attackers to execute arbitrary code by exploiting APIs that lack proper request size or number limi...

Dec 3, 2025
CVE-2025-13751
5.5

A local denial-of-service vulnerability in OpenVPN's Windows interactive service agent allows authenticated local users to crash the service by trigge...

Dec 3, 2025

About CWE-770 (CWE-770)

Our database tracks 508 CVEs classified as CWE-770, with 6 rated critical and 278 rated high severity. The average CVSS score for CWE-770 vulnerabilities is 6.8.

External reference: View CWE-770 on MITRE CWE →

Monitor CWE-770 Vulnerabilities

Get alerted when new CWE-770 CVEs affect your infrastructure.

Start Monitoring Free