CWE-770: Allocation of Resources Without Limits or Throttling — known CVE vulnerabilities
CVEs classified under CWE-770 (Allocation of Resources Without Limits or Throttling), ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-63299 — CVSS 9.9 (critical): An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code…
CVE-2026-74878 — CVSS 9.8 (critical): openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and…
CVE-2026-31283 — CVSS 9.8 (critical): In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address. which can be used…
CVE-2020-37067 — CVSS 9.8 (critical): Filetto 1.0 FTP server contains a denial of service vulnerability in the FEAT command processing that allows attackers to crash the…
CVE-2021-47875 — CVSS 9.8 (critical): GeoGebra CAS Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by generating a…
CVE-2025-11832 — CVSS 9.8 (critical): Allocation of Resources Without Limits or Throttling vulnerability in Azure Access Technology BLU-IC2, Azure Access Technology BLU-IC4…
CVE-2024-44241 — CVSS 9.8 (critical): The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may…
CVE-2021-47137 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: net: lantiq: fix memory corruption in RX ring In a situation where…
CVE-2022-3439 — CVSS 9.8 (critical): Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.
CVE-2022-3456 — CVSS 9.8 (critical): Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.
CVE-2022-29503 — CVSS 9.8 (critical): A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread…
CVE-2019-17067 — CVSS 9.8 (critical): PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal…
CVE-2018-20033 — CVSS 9.8 (critical): A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow…
CVE-2017-6713 — CVSS 9.8 (critical): A vulnerability in the Play Framework of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to gain…
CVE-2017-6640 — CVSS 9.8 (critical): A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attacker to log in to the…
CVE-2026-12818: Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-770) within their…
CVE-2025-22273: Application does not limit the number or frequency of user interactions, such as the number of incoming requests. At the…
CVE-2025-68456 — CVSS 9.1 (critical): Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users…
CVE-2024-38821 — CVSS 9.1 (critical): Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances…
CVE-2024-6037 — CVSS 9.1 (critical): A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the…
CVE-2023-27958 — CVSS 9.1 (critical): The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur…
CVE-2022-46416 — CVSS 9.1 (critical): Parrot Bebop 4.7.1. allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool. To…
CVE-2019-15753 — CVSS 9.1 (critical): In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing…
CVE-2023-43632 — CVSS 9.0 (critical): As noted in the “VTPM.md” file in the eve documentation, “VTPM is a server listening on port 8877 in EVE, exposing limited…
CVE-2024-35969 — CVSS 8.8 (high): In the Linux kernel, the following vulnerability has been resolved: ipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addr…
CVE-2023-5289 — CVSS 8.8 (high): Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.4.
CVE-2021-34735 — CVSS 8.8 (high): Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command…
CVE-2020-24994 — CVSS 8.8 (high): Stack overflow in the parse_tag function in libass/ass_parse.c in libass before 0.15.0 allows remote attackers to cause a denial of service…
CVE-2019-5031 — CVSS 8.8 (high): An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, version 9.4.1.16828. A…
CVE-2019-9291 — CVSS 8.8 (high): In Bluetooth, there is a possible remote code execution due to an improper memory allocation. This could lead to remote code execution in…
CVE-2019-10088 — CVSS 8.8 (high): A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade…
CVE-2019-7582 — CVSS 8.8 (high): The readBytes function in util/read.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a crafted swf file…
CVE-2019-7581 — CVSS 8.8 (high): The parseSWF_ACTIONRECORD function in util/parser.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a…
CVE-2026-74836: Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unauthenticated remote attacker to pin an…
CVE-2026-75956: Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3 - Pagination values were not…
CVE-2026-47683: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in lib/setup-sandbox.js does not cover…
CVE-2026-74784: Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null entries…
CVE-2026-73500: etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker…
CVE-2025-15682: TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server. An unauthenticated remote…
CVE-2026-67585: Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthenticated remote…
CVE-2026-68494: The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the…
CVE-2026-69079: CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint. The endpoint…
CVE-2026-59248: Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust…
CVE-2026-9140: A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network…
CVE-2026-10573: A denial-of-service security issue exists in 1734 POINT I/O™ module. The security issue stems from improper handling of crafted CIP…
CVE-2026-53653: Grav is a file-based Web platform. Prior to 1.7.53 and 2.0.0-rc.8, Grav allows an unauthenticated visitor to exhaust server memory and CPU…
CVE-2026-56810: Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint (Mint.HTTP1 module) allows a denial of service via…