CWE-770
High likelihoodAllocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
2,071 vulnerabilities with CWE-770
CVE-2025-36122
MEDIUM
IBM® Db2® is vulnerable to a denial of service with a specially crafted query when stmtheap is set to automatic
CVSS 6.5
CVE-2025-51846
HIGH
CryptPad unbounded WebSocket frame flood
CVSS 7.5
CVE-2025-6016
MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2025-3922
MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2025-0186
MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2025-66487
LOW
IBM Aspera Shares 1.9.9-1.11.0 - Email Rate Limit Denial of Service
CVSS 2.7
CVE-2025-13436
MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2025-13929
HIGH
GitLab 10.0-18.7.5, 18.8-18.8.5, 18.9-18.9.1 - Unauthenticated Denial of Service via Repository Archive Endpoint
CVSS 7.5
CVE-2025-13690
MEDIUM
GitLab 16.11-18.7.5, 18.8-18.8.5, 18.9-18.9.1 - Authenticated Denial of Service via Webhook Custom Header Input
CVSS 6.5
CVE-2025-12576
MEDIUM
GitLab 9.3-18.7.5, 18.8-18.8.5, 18.9-18.9.1 - Authenticated Denial of Service via Webhook Response Handling
CVSS 6.5
CVE-2025-3525
MEDIUM
GitLab 9.0-18.7.4, 18.8-18.8.4, 18.9-18.9.0 - Authenticated Denial of Service via CI Trigger API
CVSS 6.5
CVE-2025-14876
MEDIUM
Red Hat Enterprise Linux 6-9 and OpenShift Container Platform 4 - Denial of Service via virtio-crypto AKCIPHER Path
CVSS 5.5
CVE-2025-58471
MEDIUM
Qsync Central 5.0.0.0-5.0.0.3 - Authenticated Denial of Service via Resource Exhaustion
CVSS 4.9
CVE-2025-57711
MEDIUM
Qsync Central 5.0.0.0-5.0.0.3 - Authenticated Denial of Service via Resource Exhaustion
CVSS 4.9
CVE-2025-57710
MEDIUM
Qsync Central 5.0.0.0-5.0.0.3 - Authenticated Denial of Service via Resource Exhaustion
CVSS 4.9
CVE-2025-57708
MEDIUM
Qsync Central 5.0.0.0-5.0.0.3 - Authenticated Denial of Service via Resource Exhaustion
CVSS 6.5
CVE-2025-54161
MEDIUM
QNAP File Station 5.5.6.4691-5.5.6.5067 - Authenticated Denial of Service via Resource Exhaustion
CVSS 4.9
CVE-2025-54155
MEDIUM
QNAP File Station 5.5.6.4691-5.5.6.5017 - Authenticated Denial of Service
CVSS 4.9
CVE-2025-54151
MEDIUM
Qsync Central 5.0.0.0-5.0.0.3 - Denial of Service via Uncontrolled Resource Consumption
CVSS 5.5
CVE-2025-54150
MEDIUM
Qsync Central 5.0.0.0-5.0.0.3 - Authenticated Denial of Service via Uncontrolled Resource Consumption
CVSS 5.5
CVE-2025-54149
MEDIUM
Qsync Central 5.0.0.0-5.0.0.3 - Authenticated Denial of Service via Uncontrolled Resource Consumption
CVSS 5.5
CVE-2025-8099
HIGH
GitLab 10.8-18.6.5, 18.7-18.7.3, 18.8-18.8.3 - Unauthenticated Denial of Service via GraphQL Query Flooding
CVSS 7.5
CVE-2025-15317
MEDIUM
Tanium Server 7.4.6-7.4.6.1154 - Uncontrolled Resource Consumption
CVSS 6.5
CVE-2025-31990
MEDIUM
HCL DevOps Velocity < 5.1.7 - Denial of Service via Unenforced API Rate Limiting
CVSS 6.8
CVE-2025-32393
MEDIUM
AutoGPT <autogpt-platform-beta-v0.6.32 - DoS
CVSS 6.5
Details
Vulnerabilities
2,071
Exploit Likelihood
High