CWE-400
High likelihoodUncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
3,367 vulnerabilities with CWE-400
CVE-2026-58627
HIGH
Microsoft Windows 10 Version 1607 - Windows DHCP Server Denial of Service Vulnerability
CVSS 7.5
CVE-2026-45756
HIGH
Symfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
CVSS 7.5
CVE-2026-59886
HIGH
pyasn1: Uncontrolled resource consumption when converting decoded REAL values
CVSS 7.5
CVE-2026-59885
HIGH
pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
CVSS 7.5
CVE-2026-59884
HIGH
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
CVSS 7.5
CVE-2026-59200
HIGH
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
CVSS 7.5
CVE-2026-50653
HIGH
Azure Active Directory Denial of Service Vulnerability
CVSS 7.5
CVE-2026-49799
MEDIUM
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVSS 6.5
CVE-2026-12523
HIGH
Resource exhaustion in quiche HTTP/3 and QPACK layers
CVSS 7.5
CVE-2026-58486
HIGH
HedgeDoc: Denial-of-service via YAML alias expansion in note frontmatter
CVE-2026-51539
HIGH
libmodbus 3.1.12 - Denial of Service via Improper Timeout Management in Receive Loop
CVSS 7.5
CVE-2026-10668
LOW
Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driver
CVSS 2.4
CVE-2026-59161
HIGH
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
CVSS 7.5
CVE-2026-55782
LOW
NanaZip: Unbounded memory allocation (DoS) in NanaZip WebAssembly parser via attacker-controlled section/name length fields
CVE-2026-55781
LOW
NanaZip: Unbounded memory allocation (DoS) in NanaZip UFS parser via unvalidated fs_bsize/fs_fsize superblock fields
CVE-2026-55780
LOW
NanaZip: Uncaught exception / unbounded allocation in NanaZip .NET single-file Extract() via unvalidated entry Size
CVE-2026-39244
HIGH
adm-zip < 0.5.18 - Denial of Service via Crafted ZIP Uncompressed Size Header
CVSS 7.5
CVE-2026-8609
MEDIUM
Pre-authentication denial of service via the OAuth login route
CVSS 5.3
CVE-2026-33382
HIGH
Grafana OSS - Denial of Service via Unbounded Request Body Size
CVSS 7.5
CVE-2026-40007
HIGH
Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError
CVSS 7.5
CVE-2026-51600
HIGH
Tenda CP3 V31.1.9.91 - Unauthenticated Denial of Service via RTSP Content-Length Header Parsing
CVSS 7.5
CVE-2026-15308
HIGH
Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
CVSS 7.5
CVE-2026-54772
HIGH
CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake
CVSS 7.5
CVE-2026-51535
HIGH
OpENer 2.3.0 - Denial of Service via Network Processing Loop Resource Exhaustion
CVSS 7.5
CVE-2026-59936
HIGH
pypdf: Possible infinite loop for not terminated inline images
CVSS 7.5
Details
Vulnerabilities
3,367
Exploit Likelihood
High