Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. From versions 0.4.0 to before
The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming req
A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request b
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.9.7, 18.10 before 18.10.6, and
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, an
A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB wr
When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending r
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a r
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, a
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to be
Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Matterm
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authen
Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.4, the uploadViaURL path in the v1/v2 attach
A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2024-111
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2025-710
Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker read
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A
Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Exces
vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions a
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.33.0 and pr
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.17.0 and pr
sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter ins
OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-rea
Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller
Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.7, DNSCache._async_add inser
Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.12, AsyncListener.handle_que
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on em
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A
An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a c
An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via th
An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by p
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF d
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image
In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adj
Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att
A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error
Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerabilit
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives
Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started