VulnSea

CWE-770

CVEs classified under CWE-770, newest first.

588 CVEsRSS

CVE-2026-88012Medium· 5.3
2w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 2.8.2 until 2.11.56 and 3.7.12, HTTP/3 entrypoints do not apply entryPoints..transport.respondingTimeouts.readTimeout because the timeout is enforced on a TCP connectio…

▾ Sunlittraefik · traefikEPSS 0.52%via NVD
CVE-2026-45768High· 7.5
2w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, LDAP transaction state could store an unbounded number of respons…

▾ Twilightoisf · suricataEPSS 0.70%via NVD
CVE-2026-45765High· 7.5
2w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, DNP3 reassembly could buffer data without sufficient parser-level bounds. Crafted D…

▾ Twilightoisf · suricataEPSS 0.62%via NVD
CVE-2026-45766High· 7.5
2w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, certain NFS parser state structures were insufficiently bounded. Crafted NFS traffi…

▾ Twilightoisf · suricataEPSS 0.62%via NVD
CVE-2026-45769High· 7.5PoC
2w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5,IKEv2 parser state could grow without bounds while storing client transforms. Repeat…

▾ Midnightoisf · suricataEPSS 1.8%via NVD
CVE-2026-88878Medium· 5.3⚖ disputed
2w ago

Traefik is an HTTP reverse proxy and load balancer

Traefik is an HTTP reverse proxy and load balancer. In versions >= v2.8.2 through <= v2.11.55 and >= v3.0.0 through <= v3.7.11, the entryPoints.<name>.transport.respondingTimeouts settings — notably readTimeout, which is enabled by defau…

▾ Sunlittraefik · traefikEPSS 0.42%via NVD
CVE-2026-87011High· 7.5PoC
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, the unauthenticated POST /oauth/backchannel-logout handler in backend/open_webui/utils/oauth.py fetched the OIDC discovery doc…

▾ Midnightopenwebui · open_webuiEPSS 0.64%via NVD
CVE-2023-54394Medium· 4.3
2w ago

PocketMine-MP before 4.18.0-ALPHA2 fails to rate-limit mismatch type InventoryTransactionPacket requests, allowing attackers to trigger excessive inventory synchronization

PocketMine-MP before 4.18.0-ALPHA2 fails to rate-limit mismatch type InventoryTransactionPacket requests, allowing attackers to trigger excessive inventory synchronization. Attackers can send numerous mismatch transactions to force the s…

▾ Sunlitpmmp · PocketMine-MPEPSS 0.38%via NVD
CVE-2026-53937Medium· 6.2PoC
2w ago

MCP Kotlin SDK is the Kotlin Multiplatform software development kit for the Model Context Protocol

MCP Kotlin SDK is the Kotlin Multiplatform software development kit for the Model Context Protocol. In versions 0.7.0 through 0.12.0, `ReadBuffer.append` in `kotlin-sdk-core/src/commonMain/kotlin/io/modelcontextprotocol/kotlin/sdk/shared…

▾ Twilightmodelcontextprotocol · io.modelcontextprotocol:kotlin-sdkEPSS 0.19%via NVD
CVE-2026-86075High· 7.5
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the OAuth Dynamic Client Registration endpoint bounded redirect_uris but accepted arbitrarily large client_name and grant_types values. An unauthenticated re…

▾ Twilightn8n · n8nEPSS 0.61%via NVD
CVE-2026-28633Medium· 5.5
2w ago

In initForUserNoTracing of VoiceInteractionManagerService.java, there is a possible persistent denial of service due to resource exhaustion

In initForUserNoTracing of VoiceInteractionManagerService.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User …

▾ Sunlitgoogle · androidEPSS 0.09%via NVD
CVE-2026-72978Medium· 5.9
2w ago

Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.98%via NVD
CVE-2026-69374Medium· 6.5
2w ago

Allocation of resources without limits or throttling in Windows SMB Server allows an authorized attacker to deny service over a network.

Allocation of resources without limits or throttling in Windows SMB Server allows an authorized attacker to deny service over a network.

▾ Sunlitmicrosoft · windows_10_21h2EPSS 1.1%via NVD
CVE-2026-57099High· 7.5
2w ago

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · AspNetCore.ODataEPSS 1.2%via NVD
CVE-2026-82054Medium· 6.5
2w ago

A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing

A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without enforcing …

▾ Sunlitmongodb · mongodbEPSS 0.40%via NVD
CVE-2026-82075High· 7.5
2w ago

An uncontrolled resource consumption weakness exists in the request-handling path of the MongoDB sharded-cluster router process

An uncontrolled resource consumption weakness exists in the request-handling path of the MongoDB sharded-cluster router process. A client that has network access to a router port and has not authenticated can supply connection-monitoring…

▾ Twilightmongodb · mongodbEPSS 0.52%via NVD
CVE-2026-86513Medium· 5.3PoC
2w ago

A security flaw has been discovered in java-json-tools jackson-coreutils 2.0

A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePointer.tokensFromInput of the file src/main/java/com/github/fge/jackson/jsonpointer/TreePointer.java of the compon…

▾ Twilightjava-json-tools · jackson-coreutilsEPSS 0.70%via NVD
CVE-2026-62649High· 7.5
2w ago

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70)

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The web server does not properly limit or manage system resources when processing a high volume of concurrent HTTP requests. This could allow an unauthenticated…

▾ TwilightSiemens · Reyrolle 7SR5EPSS 0.57%via NVD
CVE-2026-48888High· 7.5
2w ago

Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0.

Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0.

▾ TwilightAutomattic · woocommerceEPSS 0.46%via NVD
CVE-2026-75808Medium· 5.7
2w ago

Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by bypassing driver authentication and allocating an unrestricted amou…

Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by bypassing driver authentication and allocating an unrestricted amou…

▾ SunlitASUS · Armoury CrateEPSS 0.14%via NVD
CVE-2026-82753High· 8.2
2w ago

Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to exhaust database storage and memory. The /authorize endpoint is unauthenticated by …

Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to exhaust database storage and memory. The /authorize endpoint is unauthenticated by …

▾ Twilightash-project · ash_authentication_oauth2_serverEPSS 0.66%via NVD
CVE-2026-86452High· 7.5
2w ago

Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/forgot password-reset endpoint accepted an attacker-controlled em…

Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/forgot password-reset endpoint accepted an attacker-controlled em…

▾ Twilightmisp-project · mispEPSS 0.54%via NVD
CVE-2026-19204High· 8.7
2w ago

A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. This occurs when auto-fragmentation is enab…

A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. This occurs when auto-fragmentation is enab…

▾ TwilightEclipse Foundation · Eclipse JettyEPSS 0.31%via NVD
CVE-2025-52657Low· 3.5
2w ago

HCL MyXalytics was affected by Potential DOS Vulnerability

HCL MyXalytics was affected by Potential DOS Vulnerability. It allows users to input data without any restriction on the number of characters which can impact system performance or availability.

▾ SunlitHCL Software · MyXalyticsEPSS 0.16%via NVD
CVE-2022-51008Medium· 5.3
3w ago

PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions without sending LoginPacket

PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions without sending LoginPacket. Attackers can flood the server with unauthenticated connections that occupy…

▾ Sunlitpmmp · PocketMine-MPEPSS 0.29%via NVD
CVE-2026-85664High· 7.5
3w ago

Chroma 1.5.9 fails to validate maximum bounds on HNSW index parameters max_neighbors, ef_construction, and ef_search in collection-create requests

Chroma 1.5.9 fails to validate maximum bounds on HNSW index parameters max_neighbors, ef_construction, and ef_search in collection-create requests. Unauthenticated attackers can supply arbitrarily large parameter values to exhaust server…

▾ Twilightchroma-core · chromaEPSS 0.66%via NVD
CVE-2026-85582Medium· 6.5
3w ago

SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-service Basic Auth handler that allows authenticated attackers to exhaust memory

SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-service Basic Auth handler that allows authenticated attackers to exhaust memory. Attackers can repeatedly authenticate with valid credentia…

▾ SunlitEPSS 0.44%via NVD
CVE-2026-85581High· 7.5
3w ago

SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process identifiers without size limits or authentication

SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process identifiers without size limits or authentication. Attackers can send…

▾ Twilightsiyuan-note · siyuanEPSS 0.57%via NVD
CVE-2026-84890Medium· 5.9
3w ago

undici's decompress interceptor decompresses response bodies according to the untrusted Content-Encoding header

undici's decompress interceptor decompresses response bodies according to the untrusted Content-Encoding header. While the number of content-encoding layers is capped, the total decompressed output size is unbounded and there is no confi…

▾ Sunlitnodejs · undiciEPSS 0.41%via NVD
CVE-2026-85703Medium· 6.5PoC
3w ago

A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc

A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/backend.py of the component Jailbreak Mode. Executing a manipulati…

▾ Twilightramon-victor · freegpt-webuiEPSS 0.55%via NVD
CWE-770 vulnerabilities (CVEs) — page 6 · VulnSea