An issue in the Instructor Appointment Availability module of eSoft Planner 3.24.08271-USA allows attackers to cause a D
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.13.0, the multipart form parse
Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in To
rizin before Release v0.6.3 is vulnerable to Uncontrolled Resource Consumption via bin_pe_parse_imports, Pe_r_bin_pe_par
python-multipart is a streaming multipart parser for Python. When parsing form data, python-multipart skips line breaks
Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attack, where a
Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain conf
An issue in aedes v0.51.2 allows attackers to cause a Denial of Service(DoS) via a crafted request. NOTE: the Supplier i
Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the product. Affected produc
rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vul
An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method an
Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signa
In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before e3277eb, unlimited user label appends in a userla
A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.
Multiple Cisco products are affected by a vulnerability in the Ethernet Frame Decoder of the Snort detection engine
In the Linux kernel, the following vulnerability has been resolved: xfs: fix log recovery buffer allocation for the leg
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malic
is_closing_session() allows users to create arbitrary tcp dbus connections
In the Linux kernel, the following vulnerability has been resolved: mm: huge_memory: use !CONFIG_64BIT to relax huge pa
spbu_se_site is the website of the Department of System Programming of St. Petersburg State University. Before 2024.01.2
JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Below 0.13.2 Release, whe
CubeFS is an open-source cloud-native file storage system. A security vulnerability was found in CubeFS HandlerNode in v
A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may all
Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a
The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3
An issue has been discovered in GitLab EE affecting all versions from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and
Allocation of Resources Without Limits or Throttling vulnerability in Badge leading to a denial of service attack.Team H
IBM Cognos Analytics Mobile Server 11.1.7, 11.2.4, and 12.0.0 is vulnerable to Denial of Service due to due to weak or a
An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (application exis
When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, R
node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the
A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a denial of service.
Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-c
Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, an attacker can point the image request to an a
Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse ins
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 prior to 16.9.7, starting from 1
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC
An issue has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17
Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv
An uncontrolled resource consumption vulnerability exists in the `upload-link` endpoint of mintplex-labs/anything-llm. T
An issue the background management system of Shanxi Internet Chuangxiang Technology Co., Ltd v1.0.1 allows a remote atta
A denial-of-service attack is possible through the execution functionality of KNIME Business Hub 1.10.0 and 1.10.1. It a
A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a
A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a
A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a
A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a
A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a
Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API alwaysmulti.cgi was vulnerable for fil
Frequently Asked Questions
What is CWE-770?
CWE-770 (CWE-770) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-770?
There are 2,515 CVE records associated with CWE-770 in our database. Of these, 31 are critical severity, 995 are high severity, and 1035 are medium severity.
How can I protect against CWE-770 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-770 using AI-powered security agents.
Detect CWE-770 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-770 vulnerabilities across your infrastructure.
Get Started