Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-770

MITRE ↗

CWE-770

9
CRITICAL
381
HIGH
344
MEDIUM
23
LOW
824 CVEs · Page 1/17
9.9
CVE-2026-63299

An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits

9.8
CVE-2021-47875

GeoGebra CAS Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the applicat

9.8
CVE-2020-37067

Filetto 1.0 FTP server contains a denial of service vulnerability in the FEAT command processing that allows attackers t

9.8
CVE-2026-31283

In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address.

9.8
CVE-2026-40498

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can

9.8
CVE-2026-74878

openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared a

9.8
CVE-2026-47891

A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the ma

9.1
CVE-2025-68456

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, u

9.1
CVE-2026-25804

Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's

8.6
CVE-2026-20103

A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) So

8.6
CVE-2026-44697

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-

8.6
CVE-2025-7737

DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Stor

8.6
CVE-2026-54609

QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handle

8.4
CVE-2020-37139

Odin Secure FTP Expert 7.6.3 contains a local denial of service vulnerability that allows attackers to crash the applica

8.3
CVE-2025-14341

Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits o

8.2
CVE-2026-35457

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous

8.2
CVE-2026-34045

Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP

8.2
CVE-2026-40104

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 1.8-rc

8.2
CVE-2026-41309

Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are

8.2
CVE-2026-28299

SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause

8.2
CVE-2026-56324

Capgo before 12.128.2 contains a rate limit bypass vulnerability in the channel_self endpoint that allows attackers to c

8.2
CVE-2026-47483

NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could c

8.2
CVE-2026-15055

In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also a

7.8
CVE-2026-43329

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: strictly check for maximum nu

7.7
CVE-2026-23881

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 hav

7.7
CVE-2026-23689

Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular us

7.7
CVE-2026-57212

RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP

7.7
CVE-2026-61617

Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13

7.5
CVE-2025-68272

Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in

7.5
CVE-2025-69223

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bo

7.5
CVE-2025-69228

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a reques

7.5
CVE-2020-36907

Aerohive HiveOS contains a denial of service vulnerability in the NetConfig UI that allows unauthenticated attackers to

7.5
CVE-2025-68151

CoreDNS is a DNS server that chains plugins. Prior to version 1.14.0, multiple CoreDNS server implementations (gRPC, HTT

7.5
CVE-2025-50334

An issue in Technitium DNS Server v.13.5 allows a remote attacker to cause a denial of service via the rate-limiting com

7.5
CVE-2024-58339

LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vuln

7.5
CVE-2025-37166

A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device processing a specia

7.5
CVE-2026-0897

Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through

7.5
CVE-2021-47752

AWebServer GhostBuilding 18 contains a denial of service vulnerability that allows remote attackers to overwhelm the ser

7.5
CVE-2021-47784

Cyberfox Web Browser 52.9.1 contains a denial of service vulnerability that allows attackers to crash the application by

7.5
CVE-2026-22803

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. From 2.49.0 to 2.49.4,

7.5
CVE-2021-47791

SmartFTP Client 10.0.2909.0 contains multiple denial of service vulnerabilities that allow attackers to crash the applic

7.5
CVE-2021-47793

Telegram Desktop 2.9.2 contains a denial of service vulnerability that allows attackers to crash the application by send

7.5
CVE-2026-23490

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to mem

7.5
CVE-2021-47865

ProFTPD 1.3.7a contains a denial of service vulnerability that allows attackers to overwhelm the server by creating mult

7.5
CVE-2021-47876

GeoGebra Classic 5.0.631.0-d contains a denial of service vulnerability in the input field that allows attackers to cras

7.5
CVE-2021-47877

GeoGebra Graphing Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the app

7.5
CVE-2026-23957

seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versio

7.5
CVE-2026-23962

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon versions before v4.3.18, v4.4.12, a

7.5
CVE-2026-24006

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versio

7.5
CVE-2025-13927

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.9 before 18.6.4, 18.7 before 18.7.2, and 1

Frequently Asked Questions

What is CWE-770?

CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-770?

There are 865 CVE records associated with CWE-770 in our database. Of these, 9 are critical severity, 381 are high severity, and 344 are medium severity.

How can I protect against CWE-770 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.

Detect CWE-770 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.

Get Started