CWE-400

High likelihood

Uncontrolled Resource Consumption

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly control the allocation and maintenance of a limited resource.

3,128 vulnerabilities with CWE-400
CVE-2025-3986 MEDIUM
Apereo CAS 5.2.6 - Inefficient Regular Expression Complexity
CVSS 4.3
CVE-2025-3985 LOW
Apereo CAS 5.2.6 - Inefficient Regular Expression Complexity in Query Parameter
CVSS 2.7
CVE-2025-46580 HIGH
ZTE ZXCloud GoldenDB 6.1.03-6.1.03.10 - Uncontrolled Resource Consumption via System Table Access
CVSS 7.7
CVE-2025-2811 MEDIUM
GL.iNet Various - Path Traversal
CVSS 5.7
CVE-2025-27087 MEDIUM
HPE Cray Operating System (COS) < cos-base-3.2 - Local Denial of Service via Kernel Resource Consumption
CVSS 5.5
CVE-2025-31118 HIGH
NamelessMC < 2.2.0 - Authenticated Uncontrolled Resource Consumption via Forum Quick Reply
CVSS 7.1
CVE-2025-30158 HIGH
NamelessMC < 2.2.0 - Authenticated Denial of Service via Oversized Iframe Injection
CVSS 7.1
CVE-2025-30730 HIGH
Oracle Application Object Library 12.2.5-12.2.14 - Unauthenticated Denial of Service via HTTP
CVSS 7.5
CVE-2025-30725 MEDIUM
Oracle VM VirtualBox 7.1.6 - Authenticated Denial of Service and Data Manipulation
CVSS 6.7
CVE-2025-30715 MEDIUM
MySQL Server 8.0.0-8.0.41, 8.4.0-8.4.4, 9.0.0-9.2.0 - Authenticated Denial of Service
CVSS 4.9
CVE-2025-30705 MEDIUM
MySQL Server 8.0.0-8.0.41, 8.4.0-8.4.4, 9.0.0-9.2.0 - Authenticated Denial of Service in Server: PS
CVSS 4.9
CVE-2025-30704 MEDIUM
MySQL Server 8.0.0-8.0.41, 8.4.0-8.4.4, 9.0.0-9.2.0 - Authenticated Denial of Service via Components Services
CVSS 4.4
CVE-2025-30681 LOW
MySQL Server 8.0.0-8.0.41, 8.4.0-8.4.4, 9.0.0-9.2.0 - Authenticated Partial Denial of Service in Replication
CVSS 2.7
CVE-2025-21577 MEDIUM
MySQL Server 8.0.0-8.0.41, 8.4.0-8.4.4, 9.0.0-9.2.0 - Denial of Service in InnoDB
CVSS 6.5
CVE-2025-21575 MEDIUM
MySQL Server 8.0.0-8.0.41, 8.4.0-8.4.4, 9.0.0-9.2.0 - Denial of Service in Server Parser
CVSS 6.5
CVE-2025-21574 MEDIUM
Oracle MySQL Server 8.0.0-8.0.41, 8.4.0-8.4.4, 9.0.0-9.2.0 - Denial of Service in Parser
CVSS 6.5
CVE-2025-27081 MEDIUM
HPE NonStop OSM Service Connection Suite - DoS
CVSS 6.8
CVE-2025-27486 HIGH
Windows Standards-Based Storage Management Service - DoS
CVSS 7.5
CVE-2025-27485 HIGH
Windows Standards-Based Storage Management Service - DoS
CVSS 7.5
CVE-2025-27473 HIGH
Windows HTTP.sys - Unauthenticated Denial of Service via Uncontrolled Resource Consumption
CVSS 7.5
CVE-2025-27470 HIGH
Windows Standards-Based Storage Management Service - DoS
CVSS 7.5
CVE-2025-27469 HIGH
Windows LDAP - Lightweight Directory Access Protocol - DoS
CVSS 7.5
CVE-2025-26680 HIGH
Windows Server 2012, 2016, 2019, 2022, 2025 - Unauthenticated DoS via Storage Management Service
CVSS 7.5
CVE-2025-26673 HIGH
Windows 10 1507-24H2 and Windows Server 2008 - Unauthenticated Denial of Service via LDAP Resource Consumption
CVSS 7.5
CVE-2025-26652 HIGH
Windows Server 2012-2025 Unauthenticated DoS via Storage Management Service
CVSS 7.5
Details
Vulnerabilities 3,128
Exploit Likelihood High