CWE-770: CWE-770

508
Total CVEs
6
Critical
278
High
6.8
Avg CVSS

Yearly Trend

2026
99
2025
213
2024
98
2023
51
2022
18

Top Affected Vendors

1 Gitlab 33
2 Ibm 25
3 Oracle 15
4 Qnap 14
5 Linux 13
6 F5 10
7 Cisco 9
8 Apple 9
9 Samsung 9
10 Debian 9

All CWE-770 CVEs (508)

CVE-2025-12748
5.5

A vulnerability in libvirt's XML processing allows authenticated users with limited permissions to cause denial-of-service through memory exhaustion. ...

Nov 11, 2025
CVE-2025-59459
5.5

An attacker with SSH access to an unprivileged account can disrupt services including SSH itself, causing persistent denial of service. This affects s...

Oct 27, 2025
CVE-2025-55079
5.5

This vulnerability in Eclipse ThreadX allows threads to be created with higher priority than configured maximum, potentially causing denial of service...

Oct 15, 2025
CVE-2025-48074
5.5

OpenEXR 3.3.2 has a vulnerability where it trusts unvalidated dataWindow size values from file headers, allowing malicious EXR files to trigger excess...

Aug 1, 2025
CVE-2025-5683
5.5

This vulnerability allows an attacker to cause a denial-of-service crash by loading a specially crafted ICNS image file in Qt's QImage component. It a...

Jun 5, 2025
CVE-2025-37805
5.5

A race condition vulnerability in the Linux kernel's virtio sound driver where uninitialized work_struct structures can trigger kernel warnings during...

May 8, 2025
CVE-2025-21866
5.5

A memory management vulnerability in the Linux kernel's PowerPC code patching subsystem incorrectly marks a text patching area as VM_ALLOC when it's n...

Mar 12, 2025
CVE-2024-58089
5.5

A race condition in the Linux kernel's Btrfs filesystem can cause double accounting of ordered extents when btrfs_run_delalloc_range() fails, leading ...

Mar 12, 2025
CVE-2025-21690
5.5

A vulnerability in the Linux kernel's storvsc SCSI driver allows hypervisor errors to trigger excessive warning logs, consuming CPU resources and caus...

Feb 10, 2025
CVE-2025-24127
5.5

This vulnerability in Apple operating systems allows an attacker to cause unexpected app termination (denial of service) by tricking a user into openi...

Jan 27, 2025
CVE-2025-24112
5.5

A vulnerability in macOS file parsing can cause unexpected application termination when processing malicious files. This affects users running macOS v...

Jan 27, 2025
CVE-2022-22491
5.5

This vulnerability in IBM App Connect Enterprise Certified Container allows attackers to write unlimited data to the local filesystem, potentially exh...

Jan 9, 2025
CVE-2024-54501
5.5

This vulnerability allows an attacker to cause a denial of service (DoS) by tricking a user into processing a maliciously crafted file on affected App...

Dec 12, 2024
CVE-2024-50271
5.5

A Linux kernel vulnerability where the RLIMIT_SIGPENDING resource limit is incorrectly enforced even when override_rlimit is set, preventing proper si...

Nov 19, 2024
CVE-2024-46745
5.5

The Linux kernel's uinput subsystem fails to properly validate the number of multitouch slots requested during device creation, allowing attackers to ...

Sep 18, 2024
CVE-2024-41175
5.5

CVE-2024-41175 is a local denial-of-service vulnerability in the IPC-Diagnostics package of TwinCAT/BSD that allows low-privileged local users to cras...

Aug 27, 2024
CVE-2024-43856
5.5

A race condition vulnerability in the Linux kernel's DMA memory management subsystem allows a use-after-free scenario when freeing DMA-allocated memor...

Aug 17, 2024
CVE-2024-42242
5.5

This Linux kernel vulnerability in the SDHCI driver incorrectly sets maximum segment size for memory pages, causing a kernel warning and potential sys...

Aug 7, 2024
CVE-2024-39477
5.5

A memory management vulnerability in the Linux kernel's hugetlb subsystem where failure to allocate memory for reservation structures can cause improp...

Jul 5, 2024
CVE-2024-35969
5.5

A race condition in the Linux kernel's IPv6 implementation allows a use-after-free vulnerability when ipv6_get_ifaddr and ipv6_del_addr execute concur...

May 20, 2024
CVE-2024-27804
5.5

This memory handling vulnerability in Apple operating systems allows malicious apps to execute arbitrary code with kernel privileges, potentially gain...

May 14, 2024
CVE-2024-0026
5.5

This vulnerability in Android's SnoozeHelper component allows local attackers to cause persistent denial of service through resource exhaustion. It af...

May 7, 2024
CVE-2024-26798
5.5

A memory management vulnerability in the Linux kernel's framebuffer console (fbcon) font handling can lead to a kernel panic or system crash. When fbc...

Apr 4, 2024
CVE-2026-0398
5.3

This vulnerability in PowerDNS Recursor allows attackers to cause denial of service through resource exhaustion or perform DNS cache poisoning attacks...

Feb 9, 2026
CVE-2024-39724
5.3

This vulnerability in IBM Db2 Big SQL on Cloud Pak for Data allows authenticated users with internal knowledge to cause a denial of service by exploit...

Feb 4, 2026
CVE-2026-1102
5.3

This vulnerability in GitLab allows unauthenticated attackers to cause denial of service by sending repeated malformed SSH authentication requests. It...

Jan 22, 2026
CVE-2025-69229
5.3

AIOHTTP versions 3.13.2 and below contain a vulnerability where handling chunked HTTP messages can cause excessive blocking CPU usage. Attackers can e...

Jan 6, 2026
CVE-2025-68388
5.3

This vulnerability in Packetbeat allows unauthenticated remote attackers to send malicious IPv4 fragments that trigger excessive memory and CPU alloca...

Dec 18, 2025
CVE-2025-14466
5.3

An unauthenticated attacker can send specially-crafted HTTP requests to the web interface of GΓΌralp Fortimus, Minimus, and Certimus series devices, c...

Dec 16, 2025
CVE-2025-64702
5.3

quic-go versions 0.56.0 and below are vulnerable to memory exhaustion attacks through HTTP/3 QPACK header decoding. Attackers can send specially craft...

Dec 11, 2025
CVE-2025-58181
5.3

This vulnerability in SSH servers allows attackers to cause denial of service through memory exhaustion by sending malformed GSSAPI authentication req...

Nov 19, 2025
CVE-2025-58185
5.3

This vulnerability in Go's DER parsing allows an attacker to cause memory exhaustion by sending maliciously crafted DER payloads. It affects applicati...

Oct 29, 2025
CVE-2025-58474
5.3

This vulnerability affects BIG-IP Advanced WAF with SSRF protection or NGINX with App Protect Bot Defense, where undisclosed requests can disrupt new ...

Oct 15, 2025
CVE-2025-58582
5.3

This vulnerability allows attackers to send excessively large payloads during failed login attempts, which are then logged without validation. This co...

Oct 6, 2025
CVE-2025-58058
5.3

This vulnerability in the xz Go package allows attackers to prepend arbitrary data before LZMA-encoded streams, causing excessive memory allocation du...

Aug 28, 2025
CVE-2025-4225
5.3

This vulnerability allows unauthenticated attackers to send specially crafted GraphQL requests to GitLab instances, causing denial-of-service conditio...

Aug 27, 2025
CVE-2025-36047
5.3

IBM WebSphere Application Server Liberty versions 18.0.0.2 through 25.0.0.8 are vulnerable to a denial of service attack where a remote attacker can s...

Aug 14, 2025
CVE-2025-54500
5.3

This CVE describes an HTTP/2 implementation flaw that allows attackers to send malformed HTTP/2 control frames to bypass the max concurrent streams li...

Aug 13, 2025
CVE-2025-54879
5.3

This vulnerability allows attackers to bypass email confirmation rate limits in Mastodon by rotating IP addresses, enabling them to send unlimited con...

Aug 6, 2025
CVE-2025-54939
5.3

CVE-2025-54939 is a memory leak vulnerability in LiteSpeed's LSQUIC library that occurs when processing QUIC packets before handshake completion. This...

Aug 1, 2025
CVE-2025-54121
5.3

A denial-of-service vulnerability in Starlette's file upload handling allows attackers to block the main event loop by sending large multipart form fi...

Jul 21, 2025
CVE-2025-4820
5.3

This vulnerability in Cloudflare's quiche QUIC library allows attackers to manipulate congestion control, causing affected systems to send data faster...

Jun 18, 2025
CVE-2025-3050
5.3

This vulnerability in IBM Db2 allows authenticated users to cause denial of service through CPU resource exhaustion when using Q replication. It affec...

May 29, 2025
CVE-2025-4432
5.3

A vulnerability in Rust's Ring cryptography library allows attackers to trigger a panic (crash) by sending specially crafted QUIC packets when overflo...

May 9, 2025
CVE-2025-32873
5.3

This vulnerability in Django's strip_tags() function and striptags template filter allows attackers to cause denial-of-service through slow performanc...

May 8, 2025
CVE-2025-0915
5.3

This vulnerability in IBM Db2 allows authenticated users to cause denial of service by exhausting memory resources under specific configurations. It a...

May 5, 2025
CVE-2025-26480
5.3

Dell PowerScale OneFS versions 9.5.0.0 through 9.10.0.0 contain an uncontrolled resource consumption vulnerability. An unauthenticated remote attacker...

Apr 10, 2025
CVE-2025-24317
5.3

This vulnerability allows remote unauthenticated attackers to cause denial-of-service conditions in affected HMI devices by exploiting resource alloca...

Apr 4, 2025
CVE-2025-30225
5.3

This vulnerability in Directus's S3 storage driver allows attackers to cause denial of service for all assets by sending multiple malformed transforma...

Mar 26, 2025
CVE-2023-51334
5.3

This vulnerability allows attackers to send excessive password reset emails to legitimate users by exploiting missing rate limiting in the 'Forgot Pas...

Feb 20, 2025

About CWE-770 (CWE-770)

Our database tracks 508 CVEs classified as CWE-770, with 6 rated critical and 278 rated high severity. The average CVSS score for CWE-770 vulnerabilities is 6.8.

External reference: View CWE-770 on MITRE CWE →

Monitor CWE-770 Vulnerabilities

Get alerted when new CWE-770 CVEs affect your infrastructure.

Start Monitoring Free