better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., B
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1
SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limiting, lockout, or at
Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a C
A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing
Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in con
An uncontrolled allocation of resources without limits or throttling in the e-mail handling in OTRS allows excessive all
OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Produc
RDP Manager 4.9.9.3 contains a denial of service vulnerability in connection input fields that allows local attackers to
An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12
An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12
An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12
An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12
An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12
apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.0
An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains
An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains
An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains
This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18
A flaw was found in the virtio-crypto device of QEMU. A malicious guest operating system can exploit a missing length li
pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can cra
OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the extractArchive function within src
OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget
pypdf is a free and open-source pure-python PDF library. Prior to 6.8.0, an attacker who uses this vulnerability can cra
InputMapper 1.6.10 contains a buffer overflow vulnerability in the username field that allows local attackers to crash t
Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains an unb
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li
A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to th
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Limit BO list entry count to prevent re
tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.6.1
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a specially crafted q
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can cr
Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synaps
Unrestricted resource allocation in AMD uProf may be exploitable to consume excessive system resources, potentially lead
Multiple unbounded alloca() calls in the PulseAudio protocol server.
A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading maliciou
A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration
Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser that allows attackers
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the Vikunja file import endpoint uses th
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
Capgo before 12.128.2 fails to enforce plan/quota restrictions on the /files/upload/attachments endpoint, allowing plan-
RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frame
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling o
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.6.4, 18.7 before 18.7.2, and 1
IBM Db2 Big SQL on Cloud Pak for Data versions 7.6 (on CP4D 4.8), 7.7 (on CP4D 5.0), and 7.8 (on CP4D 5.1) do not proper
Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.
webtransport-go is an implementation of the WebTransport protocol. From 0.3.0 to 0.9.0, an attacker can cause excessive
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started