The product's resource pool is not large enough to handle peak demand, which allows an attacker to prevent others from accessing the resource by using a (relatively) large number of requests for resources.
Volume of CVEs assigned to CWE-410 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40224HIGH A denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP message header can lead to | Feb 7, 2023 | 7.5 | 59 | NO | NO |
CVE-2021-1615HIGH A vulnerability in the packet processing functionality of Cisco Embedded Wireless Controller (EWC) Software for Catalyst Access Points (APs) could allow an unauthenticated, remote | Sep 23, 2021 | 8.6 | 27 | NO | NO |
CVE-2026-34019MEDIUM When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to stop | May 13, 2026 | 5.3 | 25 | NO | NO |
CVE-2022-46679HIGH
Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability | Feb 1, 2023 | 7.5 | 25 | NO | NO |
CVE-2019-13921HIGH A vulnerability has been identified in SIMATIC WinAC RTX (F) 2010 (All versions < SP3 Update 1). Affected versions of the software contain a vulnerability that could allow an unaut | Oct 10, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-0056HIGH This issue only affects devices with three (3) or more MPC10's installed in a single chassis with OSPF enabled and configured on the device. An Insufficient Resource Pool weakness | Oct 9, 2019 | 7.5 | 24 | NO | NO |
CVE-2025-27479HIGH Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network. | Apr 8, 2025 | 7.5 | 23 | NO | NO |
CVE-2022-2048HIGH In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connec | Jul 7, 2022 | 7.5 | 23 | NO | NO |
CVE-2018-13815HIGH A vulnerability has been identified in SIMATIC S7-1200 (All versions), SIMATIC S7-1500 (All Versions < V2.6). An attacker could exhaust the available connection pool of an affected | Dec 13, 2018 | 7.5 | 23 | NO | NO |
CVE-2025-41653HIGH An unauthenticated remote attacker can exploit a denial-of-service vulnerability in the device's web server functionality by sending a specially crafted HTTP request with a malicio | May 27, 2025 | 7.5 | 22 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.