Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-400

MITRE ↗

CWE-400

58
CRITICAL
1,666
HIGH
1,500
MEDIUM
123
LOW
3,438 CVEs · Page 12/69
6.5
CVE-2026-63261

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)

6.5
CVE-2026-63263

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansio

6.5
CVE-2026-43804

This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6

6.5
CVE-2026-55497

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image

6.5
CVE-2026-70489

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automatio

6.5
CVE-2026-63457

A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.

6.5
CVE-2026-16265

The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not r

6.5
CVE-2026-65785

Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacen

6.5
CVE-2026-73216

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in sr

6.5
CVE-2026-19587

Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.

6.5
CVE-2026-73559

vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions Complet

6.5
CVE-2026-74785

Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluation that bypass exis

6.5
CVE-2026-65976

Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.300, a connected peer can send r

6.5
CVE-2026-65347

The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. P

6.5
CVE-2026-19653

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to improper

6.5
CVE-2026-68555

Coturn is a free open source implementation of TURN and STUN Server. In 4.15.0, an authenticated TURN user can repeatedl

6.5
CVE-2026-55531

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream mcp_post handler creates a new _

6.5
CVE-2026-55588

ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORAS CLI versions up to

6.5
CVE-2026-62326

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.

6.5
CVE-2026-40014

An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU dispr

6.5
CVE-2026-40017

An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal ha

6.5
CVE-2026-52687

An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression st

6.4
CVE-2026-60620

Vulnerability in the JD Edwards EnterpriseOne Configurator product of Oracle JD Edwards (component: Configuration Manage

6.2
CVE-2025-66676

An issue in IObit Unlocker v1.3.0.11 allows attackers to cause a Denial of Service (DoS) via a crafted request.

6.2
CVE-2026-26066

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1

6.2
CVE-2026-0049

In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhausti

6.2
CVE-2026-35406

Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS que

6.2
CVE-2026-43653

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and

6.2
CVE-2026-34673

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consu

6.2
CVE-2026-34677

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consu

6.2
CVE-2026-34678

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consu

6.2
CVE-2026-47902

CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu

6.2
CVE-2026-47904

CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu

6.2
CVE-2026-47905

CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu

6.2
CVE-2026-48357

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application

6.2
CVE-2026-60747

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported ve

6.2
CVE-2026-61147

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

6.2
CVE-2026-63119

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Tran

6.2
CVE-2026-10695

IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated qu

6.2
CVE-2026-58045

A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:z

6.2
CVE-2026-48434

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application

6.2
CVE-2026-48443

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application

6.2
CVE-2026-55373

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

6.2
CVE-2026-81720

openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing

6.1
CVE-2026-50171

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other

6.0
CVE-2026-22003

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot).

6.0
CVE-2026-47041

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

6.0
CVE-2026-71128

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

5.9
CVE-2025-59471

A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for t

5.9
CVE-2025-59472

A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in min

Frequently Asked Questions

What is CWE-400?

CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-400?

There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.

How can I protect against CWE-400 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.

Detect CWE-400 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.

Get Started