Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Starting in version
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
gmrtd is a Go library for reading Machine Readable Travel Documents (MRTDs). Prior to version 0.17.2, ReadFile accepts T
Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, authenticated users
An uncontrolled resource consumption vulnerability has been reported to affect File Station 5. If a remote attacker gain
A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger
A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimete
Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implemen
Uncontrolled Resource Consumption (CWE-400) in the Timelion component in Kibana can lead Denial of Service via Input Dat
Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server imposes no limi
Uncontrolled Resource Consumption vulnerability in hexpm hexpm/hexpm allows Excessive Allocation. Publishing an oversize
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An API end
In Forgejo through 13.0.3, the attachment component allows a denial of service by uploading a multi-gigabyte file attach
pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.1 allow an attacker to craft a malicious
ConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. The 'download' method
Vikunja is an open-source self-hosted task management platform. Starting in version 1.0.0-rc0 and prior to version 2.2.0
Nanoleaf Lines 12.3.2 does not authenticate firmware file uploads. A remote, unauthenticated attacker can upload firmwar
The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API rest
TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigati
A resample query can be used to trigger out-of-memory crashes in Grafana.
A testdata data-source can be used to trigger out-of-memory crashes in Grafana.
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5,
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL end
Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repe
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)
CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creat
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a denial of service vulnerability
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported vers
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported vers
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported vers
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affec
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: JSON). Supported versions that are affect
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and
In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when ha
A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.8.0 to befo
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does
Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the s
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.2, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to
Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain q
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot UI object-bul
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-13
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started