Skip to main content

CWE archive

CWE-770 CVEs

Programmatic archive

2,059 CVEs tagged with CWE-77029 Critical, 924 High, 1,029 Medium, 77 Low, 0 Unrated.

CVE-2026-54638

Published Jul 28, 2026

gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauth…

CVSS 7.5 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-54609

Published Jul 28, 2026

QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-54345

Published Jul 28, 2026

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed header size from…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-54332

Published Jul 28, 2026

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads an attacker-controlled 32-bit…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-61609

Published Jul 28, 2026

Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter defined in RouteServiceProvider::configureRateLimiting()…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-47483

Published Jul 28, 2026

NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concur…

CVSS 8.2 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-65624

Published Jul 28, 2026

Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote attacker to exhaust connection process memory over HTTP/1.1…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-59248

Published Jul 28, 2026

Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on the vulnerable server (or clie…

CVSS 8.7 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-64646

Published Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, requests targeting Next.js applications using…

CVSS 6.3 · Medium
evidence mentions
5
Buzz score
22.9

CVE-2026-59251

Published Jul 27, 2026

Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial of service by sending a crafte…

CVSS 8.7 · High
evidence mentions
6
Buzz score
32.5

CVE-2026-42792

Published Jul 27, 2026

Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote attacker to permanently terminate the Erlang Port Mapper Daemo…

CVSS 6.3 · Medium
evidence mentions
5
Buzz score
30.9

CVE-2026-10600

Published Jul 27, 2026

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extra…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-58389

Published Jul 27, 2026

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgr…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-55968

Published Jul 27, 2026

Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-45112

Published Jul 27, 2026

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recomme…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-17501

Published Jul 27, 2026

A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-t…

CVSS 6.9 · Medium
evidence mentions
7
Buzz score
27.3

CVE-2026-66037

Published Jul 24, 2026

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause mul…

CVSS 7.1 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-25800

Published Jul 23, 2026

Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and prior to version 0.11.15, the `Assembler` component that a…

CVSS 7.5 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-16756

Published Jul 23, 2026

Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attacker…

CVSS 8.7 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-8287

Published Jul 23, 2026

Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive Alloca…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-14257

Published Jul 23, 2026

brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but…

CVSS 7.5 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-13076

Published Jul 22, 2026

An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data type conversion operation within…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-13075

Published Jul 22, 2026

An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusion aggregation stages. The issu…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-13074

Published Jul 22, 2026

An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in exhaust…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-13069

Published Jul 22, 2026

An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an unva…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 2,059 CVEsPage 1 of 83