Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-1004

MITRE ↗

CWE-1004

4
HIGH
7
MEDIUM
1
LOW
13 CVEs
8.1
CVE-2026-25136

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific da

8.1
CVE-2026-42239

Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT sess

8.0
CVE-2026-35575

ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnera

7.3
CVE-2026-25733

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific da

6.8
CVE-2026-57948

Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the

6.5
CVE-2026-0696

In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some

6.1
CVE-2026-25734

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific da

6.1
CVE-2026-25735

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific da

6.1
CVE-2026-25736

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific da

6.1
CVE-2026-39338

ChurchCRM is an open-source church management system. Prior to 7.1.0, a Blind Reflected Cross-Site Scripting vulnerabili

5.4
CVE-2026-21754

HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthori

3.7
CVE-2026-11956

A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of the file security/oidc

CVE-2026-22081

This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the m

Frequently Asked Questions

What is CWE-1004?

CWE-1004 (CWE-1004) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-1004?

There are 13 CVE records associated with CWE-1004 in our database. Of these, 0 are critical severity, 4 are high severity, and 7 are medium severity.

How can I protect against CWE-1004 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1004 using AI-powered security agents.

Detect CWE-1004 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-1004 vulnerabilities across your infrastructure.

Get Started