Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Groupfolders app provides admin-configured fo
The Yealink RPS API before 2025-05-26 lacks rate limiting, potentially enabling information disclosure via excessive req
A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulner
py-libp2p before 0.2.3 allows a peer to cause a denial of service (resource consumption) via a large RSA key.
A Denial Of Service via File Upload (DOS) vulnerability in the Liferay Portal 7.4.3.0 through 7.4.3.132, and Liferay DXP
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, an
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email
A low privileged remote attacker can use the ssh feature to execute commands directly after login. The process stays ope
FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny
Successful exploitation of the vulnerability could allow an attacker to consume all available session slots and block ot
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions
Resource allocation control failure vulnerability in the ArkUI framework Impact: Successful exploitation of this vulnera
A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST r
A vulnerability, which was classified as problematic, was found in Axiomatic Bento4 up to 1.6.0-641. Affected is the fun
InvenTree is an Open Source Inventory Management System. Prior to version 0.17.13, the skip field in the built-in `label
An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.2.7, 18.3 before 18.3.3, and 18.
Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus vers
A vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternRe
A denial of service (DoS) vulnerability has been identified in the JavaScript library microlight version 0.0.7. This lib
VictoriaMetrics is a scalable solution for monitoring and managing time series data. In versions from 1.0.0 to before 1.
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V10.0), SIPROTEC 5 6MD85 (CP300) (All ve
Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including sup
Application does not limit the number or frequency of user interactions, such as the number of incoming requests. At the
An Allocation of Resources Without Limits or Throttling vulnerability in the operating system network configuration used
bep/imagemeta is a Go library for reading EXIF, IPTC and XMP image meta data from JPEG, TIFF, PNG, and WebP files. The E
bep/imagemeta is a Go library for reading EXIF, IPTC and XMP image meta data from JPEG, TIFF, PNG, and WebP files. The b
A denial-of-service (DoS) vulnerability in Palo Alto Networks Prisma® SD-WAN ION devices enables an unauthenticated atta
Volcano is a Kubernetes-native batch scheduling system. Prior to versions 1.11.2, 1.10.2, 1.9.1, 1.11.0-network-topology
An e-mail flooding vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, an
A Allocation of Resources Without Limits or Throttling vulnerability in sslh allows attackers to easily exhaust the file
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r
NeKernal is a free and open-source operating system stack. Prior to version 0.0.3, there are several memory safety issue
Letmein is an authenticating port knocker. Prior to version 10.2.1, The connection limiter is implemented incorrectly. I
The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denia
FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as template
Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and be
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on
Stalwart is a mail and collaboration server. Starting in version 0.12.0 and prior to version 0.13.3, a memory exhaustion
Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive
Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive
Uncontrolled Resource Consumption vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Floodi
Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive
Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server o
Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-
MANTRA is a purpose-built RWA Layer 1 Blockchain, capable of adherence to real world regulatory requirements. Versions 4
Vickey is a Misskey-based microblogging platform. A vulnerability exists in Vickey prior to version 2025.10.0 where unex
A denial-of-service security issue exists in the affected product and version. The security issue stems from a high numb
Allocation of Resources Without Limits or Throttling vulnerability in The Wikimedia Foundation Mediawiki - CirrusSearch
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started