Successful exploitation of the vulnerability could allow an attacker to cause repeated reboots, potentially leading to r
An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18
Allocation of Resources Without Limits or Throttling vulnerability in Kron Technologies Kron PAM allows HTTP DoS. This
Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacker to deny service ov
An issue has been discovered in GitLab CE/EE affecting all versions from 8.14 before 18.0.6, 18.1 before 18.1.4, and 18.
An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 18.0.6, 18.1 before 18.1.4, and 18.
Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, it is possible to craft a JSON Schema file
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.7, 2024.Q
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q
An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 before 18.1.5, 18.2 before 18.2.5, and 18.
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r
An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re
IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a remote user to cause a denial of
An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.1.6, 18.2 before 18.2.6, and 18.
An issue has been discovered in GitLab CE/EE affecting all versions from 7.8 before 18.1.6, 18.2 before 18.2.6, and 18.3
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re
An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains
On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause th
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JWE zip=DEF
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18.4 before 18.4.3, and 1
Consul and Consul Enterprise’s (“Consul”) key/value endpoint is vulnerable to denial of service (DoS) due to incorrect C
Consul and Consul Enterprise’s (“Consul”) event endpoint is vulnerable to denial of service (DoS) due to lack of maximum
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.27.1 and below allow attackers to permanently
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could
SpiceDB is an open source database system for creating and managing security-critical application permissions. In versio
vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, the /v1/c
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 - #164, an authorization bypass vulnerabi
IBM watsonx.data 2.2 through 2.2.1 could allow an authenticated user to cause a denial of service through ingestion pods
A low privileged remote attacker can run the webshell with an empty command containing whitespace. The server will then
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can allow a low-privileged authenticated user t
The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer over
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Da
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Th
Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPa
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started