An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits
GeoGebra CAS Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the applicat
Filetto 1.0 FTP server contains a denial of service vulnerability in the FEAT command processing that allows attackers t
In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address.
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can
openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared a
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the ma
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, u
Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's
A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) So
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-
DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Stor
QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handle
Odin Secure FTP Expert 7.6.3 contains a local denial of service vulnerability that allows attackers to crash the applica
Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits o
libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous
Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 1.8-rc
Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are
SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause
Capgo before 12.128.2 contains a rate limit bypass vulnerability in the channel_self endpoint that allows attackers to c
NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could c
In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also a
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: strictly check for maximum nu
Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 hav
Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular us
RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP
Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13
Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bo
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a reques
Aerohive HiveOS contains a denial of service vulnerability in the NetConfig UI that allows unauthenticated attackers to
CoreDNS is a DNS server that chains plugins. Prior to version 1.14.0, multiple CoreDNS server implementations (gRPC, HTT
An issue in Technitium DNS Server v.13.5 allows a remote attacker to cause a denial of service via the rate-limiting com
LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vuln
A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device processing a specia
Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through
AWebServer GhostBuilding 18 contains a denial of service vulnerability that allows remote attackers to overwhelm the ser
Cyberfox Web Browser 52.9.1 contains a denial of service vulnerability that allows attackers to crash the application by
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. From 2.49.0 to 2.49.4,
SmartFTP Client 10.0.2909.0 contains multiple denial of service vulnerabilities that allow attackers to crash the applic
Telegram Desktop 2.9.2 contains a denial of service vulnerability that allows attackers to crash the application by send
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to mem
ProFTPD 1.3.7a contains a denial of service vulnerability that allows attackers to overwhelm the server by creating mult
GeoGebra Classic 5.0.631.0-d contains a denial of service vulnerability in the input field that allows attackers to cras
GeoGebra Graphing Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the app
seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versio
Mastodon is a free, open-source social network server based on ActivityPub. Mastodon versions before v4.3.18, v4.4.12, a
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versio
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.9 before 18.6.4, 18.7 before 18.7.2, and 1
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 865 CVE records associated with CWE-770 in our database. Of these, 9 are critical severity, 381 are high severity, and 344 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started