CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

2,071 vulnerabilities with CWE-770
CVE-2025-36122 MEDIUM
IBM® Db2® is vulnerable to a denial of service with a specially crafted query when stmtheap is set to automatic
CVSS 6.5
CVE-2025-51846 HIGH
CryptPad unbounded WebSocket frame flood
CVSS 7.5
CVE-2025-6016 MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2025-3922 MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2025-0186 MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2025-66487 LOW
IBM Aspera Shares 1.9.9-1.11.0 - Email Rate Limit Denial of Service
CVSS 2.7
CVE-2025-13436 MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2025-13929 HIGH
GitLab 10.0-18.7.5, 18.8-18.8.5, 18.9-18.9.1 - Unauthenticated Denial of Service via Repository Archive Endpoint
CVSS 7.5
CVE-2025-13690 MEDIUM
GitLab 16.11-18.7.5, 18.8-18.8.5, 18.9-18.9.1 - Authenticated Denial of Service via Webhook Custom Header Input
CVSS 6.5
CVE-2025-12576 MEDIUM
GitLab 9.3-18.7.5, 18.8-18.8.5, 18.9-18.9.1 - Authenticated Denial of Service via Webhook Response Handling
CVSS 6.5
CVE-2025-3525 MEDIUM
GitLab 9.0-18.7.4, 18.8-18.8.4, 18.9-18.9.0 - Authenticated Denial of Service via CI Trigger API
CVSS 6.5
CVE-2025-14876 MEDIUM
Red Hat Enterprise Linux 6-9 and OpenShift Container Platform 4 - Denial of Service via virtio-crypto AKCIPHER Path
CVSS 5.5
CVE-2025-58471 MEDIUM
Qsync Central 5.0.0.0-5.0.0.3 - Authenticated Denial of Service via Resource Exhaustion
CVSS 4.9
CVE-2025-57711 MEDIUM
Qsync Central 5.0.0.0-5.0.0.3 - Authenticated Denial of Service via Resource Exhaustion
CVSS 4.9
CVE-2025-57710 MEDIUM
Qsync Central 5.0.0.0-5.0.0.3 - Authenticated Denial of Service via Resource Exhaustion
CVSS 4.9
CVE-2025-57708 MEDIUM
Qsync Central 5.0.0.0-5.0.0.3 - Authenticated Denial of Service via Resource Exhaustion
CVSS 6.5
CVE-2025-54161 MEDIUM
QNAP File Station 5.5.6.4691-5.5.6.5067 - Authenticated Denial of Service via Resource Exhaustion
CVSS 4.9
CVE-2025-54155 MEDIUM
QNAP File Station 5.5.6.4691-5.5.6.5017 - Authenticated Denial of Service
CVSS 4.9
CVE-2025-54151 MEDIUM
Qsync Central 5.0.0.0-5.0.0.3 - Denial of Service via Uncontrolled Resource Consumption
CVSS 5.5
CVE-2025-54150 MEDIUM
Qsync Central 5.0.0.0-5.0.0.3 - Authenticated Denial of Service via Uncontrolled Resource Consumption
CVSS 5.5
CVE-2025-54149 MEDIUM
Qsync Central 5.0.0.0-5.0.0.3 - Authenticated Denial of Service via Uncontrolled Resource Consumption
CVSS 5.5
CVE-2025-8099 HIGH
GitLab 10.8-18.6.5, 18.7-18.7.3, 18.8-18.8.3 - Unauthenticated Denial of Service via GraphQL Query Flooding
CVSS 7.5
CVE-2025-15317 MEDIUM
Tanium Server 7.4.6-7.4.6.1154 - Uncontrolled Resource Consumption
CVSS 6.5
CVE-2025-31990 MEDIUM
HCL DevOps Velocity < 5.1.7 - Denial of Service via Unenforced API Rate Limiting
CVSS 6.8
CVE-2025-32393 MEDIUM
AutoGPT <autogpt-platform-beta-v0.6.32 - DoS
CVSS 6.5
Details
Vulnerabilities 2,071
Exploit Likelihood High