Skip to main content

CWE archive

CWE-770 CVEs

Programmatic archive

2,178 CVEs tagged with CWE-77033 Critical, 999 High, 1,067 Medium, 79 Low, 0 Unrated.

CVE-2026-47683

Published Aug 17, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in lib/setup-sandbox.js does not cover Buffer.concat(list, totalLength) or Buffer.f…

CVSS 8.7 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-71486

Published Aug 17, 2026

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat/completions/derender endpoints accept caller-supplied…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-75050

Published Aug 17, 2026

In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-64868

Published Aug 17, 2026

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, a…

CVSS 7.5 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-74878

Published Aug 17, 2026

openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on server restart. Attackers can…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-74788

Published Aug 16, 2026

Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functions, which pe…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-74786

Published Aug 16, 2026

Scriban before 7.0.0 (affected versions <= 6.6.0) contains a denial-of-service vulnerability in which the LimitToString safety limit (default 1MB) can be bypassed because ObjectTo…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-74784

Published Aug 16, 2026

Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null entries without respecting LoopLimit or LimitToString…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-73062

Published Aug 16, 2026

Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-s…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-73060

Published Aug 16, 2026

Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy se…

CVSS 8.7 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-72888

Published Aug 16, 2026

Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require. smart_require stores results in a process-global h…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
27.6

CVE-2026-19474

Published Aug 15, 2026

@fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can leave completed temporary fil…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-73635

Published Aug 15, 2026

Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from t…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-19830

Published Aug 14, 2026

A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of the file /etc/bftpd.conf of the component bftpd. The manipula…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-72838

Published Aug 14, 2026

FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated users to write arbitrary data to…

CVSS 7.1 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-19617

Published Aug 14, 2026

A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrol…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-56862

Published Aug 13, 2026

Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can k…

CVSS 7.5 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-56859

Published Aug 13, 2026

Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.

CVSS 7.5 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-56853

Published Aug 13, 2026

When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is une…

CVSS 7.5 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-17076

Published Aug 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper processing of DRDA and DDM resynchronization requests.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-72684

Published Aug 13, 2026

A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request containing a crafted user-supplied input. Processing that input…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-72674

Published Aug 13, 2026

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A user-supplied list of document fie…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-72667

Published Aug 13, 2026

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A specially crafted request submitte…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-72659

Published Aug 13, 2026

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A specially crafted, malformed payload…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-72653

Published Aug 13, 2026

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user who is authorize…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 2,178 CVEsPage 1 of 88