CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,128 vulnerabilities with CWE-400
CVE-2025-3602 HIGH
Liferay Portal 7.4.0-7.4.3.97 and Liferay DXP 2023.Q3.1-2023.Q3.2 - Denial of Service via GraphQL Query Depth
CVSS 7.5
CVE-2025-22242 MEDIUM
Salt 3006.x < 3006.12 and 3007.x < 3007.4 - Denial of Service via File Read Operation
CVSS 5.6
CVE-2025-33068 HIGH
Windows Standards-Based Storage Management Service - DoS
CVSS 7.5
CVE-2025-32724 HIGH
Windows 10/11, Server 2008 - LSASS DoS via Resource Consumption
CVSS 7.5
CVE-2025-3112 MEDIUM
Schneider Electric Modicon M241/M251 < 5.3.12.51 - DoS via HTTPS Content-Length
CVSS 6.5
CVE-2025-5897 MEDIUM
Vuejs vue-cli <5.0.8 - Info Disclosure
CVSS 4.3
CVE-2025-5896 MEDIUM
tarojs taro <4.1.1 - Info Disclosure
CVSS 4.3
CVE-2025-5895 MEDIUM
Metabase 54.10 - Denial of Service via Inefficient Regular Expression in parseDataUri
CVSS 4.3
CVE-2025-5892 MEDIUM
RocketChat <7.6.1 - Info Disclosure
CVSS 4.3
CVE-2025-5891 MEDIUM
Unitech pm2 <6.0.6 - Info Disclosure
CVSS 4.3
CVE-2025-5890 MEDIUM
actions toolkit <0.5.0 - Info Disclosure
CVSS 4.3
CVE-2025-5889 LOW
juliangruber brace-expansion <1.1.11/2.0.1/3.0.0/4.0.0 - Inefficien...
CVSS 3.1
CVE-2025-48053 HIGH
Discourse < 3.4.4 and < 3.5.0 - Denial of Service via Malicious URL in Private Message
CVSS 7.5
CVE-2025-25208 MEDIUM
Authorino - Uncontrolled Resource Consumption via AuthPolicy Evaluation
CVSS 5.7
CVE-2025-41361 HIGH
IDF v0.10.0-0C03-03 & ZLF v0.10.0-0C03-04 - DoS
CVE-2025-41360 HIGH
ZIV IDF and ZLF < 1.1.0 - Denial of Service via Packet Flooding
CVE-2025-49000 LOW
InvenTree < 0.17.13 - Authenticated Denial of Service via Label-Sheet Plugin Skip Field
CVSS 3.5
CVE-2025-5024 HIGH
Red Hat Enterprise Linux gnome-remote-desktop - Unauthenticated Denial of Service via RDP Connection Handling
CVSS 7.4
CVE-2025-5031 LOW
Ackites KillWxapkg <= 2.4.1 - Uncontrolled Resource Consumption in wxapkg File Decompression Handler
CVSS 3.1
CVE-2025-41227 MEDIUM
VMware ESXi, Workstation, and Fusion - DoS
CVSS 5.5
CVE-2025-41226 MEDIUM
VMware ESXi 7.0-8.0 - Denial of Service via Guest Operation
CVSS 6.8
CVE-2025-4727 LOW
Meteor < 3.2.2 - Inefficient Regular Expression Complexity in Object.assign
CVSS 3.7
CVE-2025-30476 MEDIUM
Dell PowerScale InsightIQ <5.2 - DoS
CVSS 5.3
CVE-2025-26481 HIGH
Dell PowerScale OneFS 9.4.0-9.9.0 - Unauthenticated Denial of Service via Uncontrolled Resource Consumption
CVSS 7.5
CVE-2025-26783 HIGH
Samsung Exynos Modem DoS via RRC Undefined Value Handling
CVSS 7.5
Details
Vulnerabilities 3,128
Exploit Likelihood High