Skip to main content

CWE archive

CWE-770 CVEs

Programmatic archive

2,165 CVEs tagged with CWE-77032 Critical, 989 High, 1,065 Medium, 79 Low, 0 Unrated.

CVE-2026-25800

Published Jul 23, 2026

Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and prior to version 0.11.15, the `Assembler` component that a…

CVSS 7.5 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-16756

Published Jul 23, 2026

Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attacker…

CVSS 8.7 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-8287

Published Jul 23, 2026

Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive Alloca…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-14257

Published Jul 23, 2026

brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but…

CVSS 7.5 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-13076

Published Jul 22, 2026

An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data type conversion operation within…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-13075

Published Jul 22, 2026

An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusion aggregation stages. The issu…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-13074

Published Jul 22, 2026

An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in exhaust…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-13069

Published Jul 22, 2026

An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an unva…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-65650

Published Jul 22, 2026

Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-11622

Published Jul 22, 2026

A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queri…

CVSS 7.5 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-47013

Published Jul 21, 2026

Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Easily exploitable vulnerability allows unauthenticated att…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42397

Published Jul 21, 2026

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a s…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-15957

Published Jul 21, 2026

Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom servi…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-55831

Published Jul 21, 2026

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-dec…

CVSS 7.5 · High
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-53596

Published Jul 20, 2026

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeScout helpdesk application does not enforce rate limiting on t…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-48824

Published Jul 20, 2026

Mailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2026-45710, "Mailpit: Set a default 50MB p/m limit to preven…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-45713

Published Jul 20, 2026

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field that controls the maximum allowed DATA pay…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-45712

Published Jul 20, 2026

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?data=…) maintains a package-level assets map[string]MessageAss…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-63750

Published Jul 20, 2026

SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket connections, allowing attackers to buffer unbounded frames i…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-15588

Published Jul 20, 2026

A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limi…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
33.8

CVE-2025-71396

Published Jul 18, 2026

SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on embedded JavaScript scripting functions when the scripting ca…

CVSS 2.3 · Low
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-54490

Published Jul 17, 2026

websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, if this library is used with the permessage-deflate extension, a WebSocket server or client ca…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-50274

Published Jul 17, 2026

Datadog dd-trace-go is a Go client library for Datadog application performance monitoring, profiling, and security monitoring. Prior to 2.8.1, Datadog tracing libraries that imple…

CVSS 7.5 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-50272

Published Jul 17, 2026

dd-trace is the Datadog APM client for Node.js. Prior to 5.100.0, W3C baggage propagation in packages/dd-trace/src/baggage.js and packages/dd-trace/src/opentracing/propagation/tex…

CVSS 7.5 · High
evidence mentions
4
Buzz score
21.1
Showing 126-150 of 2,165 CVEsPage 6 of 87