CWE-770
High likelihoodAllocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
1,858 vulnerabilities with CWE-770
CVE-2025-36123
MEDIUM
IBM Db2 11.5.0-11.5.9 and 12.1.0-12.1.3 - Denial of Service via XML Data Table Copy
CVSS 6.2
CVE-2025-36098
MEDIUM
IBM Db2 11.5.0-11.5.9 and 12.1.0-12.1.3 - Authenticated Denial of Service
CVSS 6.5
CVE-2025-36070
MEDIUM
IBM Db2 11.5.0-11.5.9 and 12.1.0-12.1.3 - Denial of Service via Table Selection
CVSS 6.5
CVE-2025-2668
MEDIUM
IBM Db2 11.5.0-11.5.9 - Authenticated Denial of Service via Crafted Query
CVSS 6.5
CVE-2025-68934
MEDIUM
Discourse <3.5.4,2025.11.2,2025.12.1,2026.1.0 - Use After Free
CVSS 6.5
CVE-2025-61728
MEDIUM
GO < 1.24.12 - Resource Allocation Without Limits
CVSS 6.5
CVE-2025-61726
HIGH
GO < 1.24.12 - Resource Allocation Without Limits
CVSS 7.5
CVE-2025-68659
MEDIUM
Discourse <3.5.4,2025.11.2,2025.12.1,2026.1.0 - DoS
CVSS 4.3
CVE-2025-55102
HIGH
Eclipse ThreadX - NetX Duo < 6.4.3 - Denial of Service via IPv6 Packet Too Big Handling
CVSS 7.5
CVE-2025-14525
MEDIUM
kubevirt - Denial of Service via Excessive Network Interface Reporting
CVSS 6.4
CVE-2025-67221
HIGH
orjson < 3.11.4 - Denial of Service via Deeply Nested JSON Documents
CVSS 7.5
CVE-2025-13927
HIGH
GitLab 11.9-18.6.3, 18.7-18.7.1, 18.8-18.8.1 - Unauthenticated Denial of Service via Malformed Authentication Data
CVSS 7.5
CVE-2025-68138
MEDIUM
libocpp < 0.30.1 - Memory Leak via Unfreed strdup Pointers
CVSS 4.7
CVE-2025-68136
HIGH
EVerest < 2025.10.0 - Denial of Service via ISO15118-20 SDP Request Handling
CVSS 7.4
CVE-2025-68133
HIGH
EVerest < 2025.10.0 - Denial of Service via Unlimited TCP Connection Exhaustion
CVSS 7.4
CVE-2025-69199
MEDIUM
Pterodactyl Wings < 1.12.0 - Unauthenticated Uncontrolled Resource Consumption via WebSocket Connections
CVSS 6.5
CVE-2025-11044
MEDIUM
B&R Automation Runtime <6.5 & <R4.93 - DoS
CVSS 6.8
CVE-2025-14435
MEDIUM
Mattermost <10.11.8-11.1.1-11.0.6 - Authenticated DoS
CVSS 6.8
CVE-2025-14822
LOW
Mattermost 10.11.0-10.11.8 - Authenticated Denial of Service via Hashtag Processing
CVSS 3.1
CVE-2025-37166
HIGH
HPE Networking Instant On Access Points - DoS
CVSS 7.5
CVE-2025-10569
MEDIUM
GitLab 8.3-18.5.5, 18.6-18.6.3, 18.7-18.7.1 - Authenticated Denial of Service via External API Response
CVSS 6.5
CVE-2025-50334
HIGH
Technitium DNS Server < 14.0 - Denial of Service via Rate-Limiting Component
CVSS 7.5
CVE-2025-68151
HIGH
CoreDNS < 1.14.0 - Unauthenticated Denial of Service via Resource Exhaustion
CVSS 7.5
CVE-2025-66560
MEDIUM
Quarkus <3.31.0-3.27.2-3.20.5 - Info Disclosure
CVSS 5.9
CVE-2025-66838
MEDIUM
ARIS < 10.0.23.0.3587512 - Resource Exhaustion via Unrestricted File Upload
CVSS 6.5
Details
Vulnerabilities
1,858
Exploit Likelihood
High