CWE-400
High likelihoodUncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
3,371 vulnerabilities with CWE-400
CVE-2026-8187
MEDIUM
Open5GS UPF gtp-path.c _gtpv1_u_recv_cb resource consumption
CVSS 5.3
CVE-2026-42343
MEDIUM
FastGPT: Uncontrolled Resource Consumption leading to Sandbox Exhaustion
CVE-2026-42212
HIGH
SolidCAM-GPPL-IDE: XML External Entity (XXE) and billion-laughs DoS in VMID parser
CVE-2026-38361
HIGH
dash-uploader 0.1.0-0.7.0a2 Upload Handler - Remote Code Execution
CVSS 7.5
CVE-2026-8124
LOW
GPAC box_code_base.c sidx_box_read allocation of resources
CVSS 3.3
CVE-2026-32686
MEDIUM
Unbounded exponent in decimal enables unauthenticated DoS
CVE-2026-41310
MEDIUM
OpenTelemetry .NET Zipkin exporter has unbounded remote endpoint cache leading to memory growth
CVSS 5.3
CVE-2026-34473
HIGH
ZTE Multiple Models - Unauthenticated DoS via Oversized POST Body
CVSS 7.5
CVE-2026-20188
NONE
Cisco Crosswork Network Controller and Cisco Network Services Orchestrator Connection Exhaustion Denial of Service Vulnerability
CVE-2026-32936
HIGH
CoreDNS DoH GET path missing size validation causes CPU and memory amplification
CVSS 7.5
CVE-2026-43870
HIGH
Apache Thrift: Node.js web_server.js multi-vulnerability
CVSS 7.3
CVE-2026-42154
HIGH
Prometheus: remote read endpoint allows denial of service via crafted snappy payload
CVSS 7.5
CVE-2026-37459
HIGH
FRRouting stable/10.0-stable/10.6 - Denial of Service via Crafted BGP UPDATE Message
CVSS 7.5
CVE-2026-42467
HIGH
Open-SAE-J1939 through commit b6caf884df46435e539b1ecbf92b6c29b345bdfe - Denial of Service via Crafted CAN Frame
CVSS 7.5
CVE-2026-42403
HIGH
Apache Neethi: Circular Policy Reference Infinite Loop
CVSS 7.5
CVE-2026-42402
HIGH
Apache Neethi: Policy Normalization Unbounded Resource Allocation DoS
CVSS 7.5
CVE-2026-40951
MEDIUM
Memory corruption in Secure Access Windows clients prior to 14.50
CVSS 5.5
CVE-2026-36958
HIGH
U-SPEED N300 V1.0.0 - Denial of Service via Concurrent HTTP Requests
CVSS 7.5
CVE-2026-36957
HIGH
Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 - DoS
CVSS 7.5
CVE-2026-28221
MEDIUM
Wazuh: Pre-auth stack-based buffer overflow in wazuh-remoted print_hex_string() due to signed char promotion on x86_64
CVSS 6.5
CVE-2026-22745
MEDIUM
CVE-2026-22745 : Denial of service in static resource handling on Windows platforms
CVSS 5.3
CVE-2026-22740
MEDIUM
Spring Framework DoS with Multipart Temp Files in WebFlux
CVSS 6.5
CVE-2026-40980
MEDIUM
Spring AI 1.0.0-1.0.5 - Memory Corruption
CVSS 6.5
CVE-2026-35901
MEDIUM
Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n - Authenticated Denial of Service via RTSP SETUP Request Flood
CVSS 4.4
CVE-2026-30350
HIGH
Agent Protocol server e9a89f - Denial of Service via /store/items/search Endpoint
CVSS 7.5
Details
Vulnerabilities
3,371
Exploit Likelihood
High