Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, ther
Axios is a promise based HTTP client for the browser and Node.js. Starting in version 1.13.0 and prior to 1.13.2, Axios
A rogue primary server may cause file descriptor exhaustion and eventually a denial of service, when a PowerDNS secondar
An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataA
HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetD
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0
Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowE
Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Sup
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 a
CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledg
CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate
Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Mexico product of Oracle PeopleSoft (component: Global Pay
A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Rec
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1
Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representation
Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical lines — for examp
An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin i
filebrowser through 2.63.23 fails to validate named pipes in directory archive and public download handlers, allowing at
Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthentica
A vulnerability in danny-avila/librechat allows attackers to exploit the unrestricted Fork Function in `/api/convos/fork
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i
NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, where an attacker could cause uncontrolled
An uncontrolled allocation of resources without limits or throttling in the e-mail handling in OTRS allows excessive all
Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.1.0 and prior to ve
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.0
An issue inTcpreplay v4.5.1 allows a local attacker to cause a denial of service via a crafted file to the tcpedit_dlt_g
An issue in mquickjs before commit 74b7e (2026-01-15) allows a local attacker to cause a denial of service via a crafted
An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains
An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains
An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains
The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug
Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service
CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with loc
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when executing a specially
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can cr
In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This cou
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to resource ex
In verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource exhaustion. This could
In getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service due to resource exhaustio
In multiple places, there is a possible persistent denial of service due to resource exhaustion. This could lead to loca
In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can cr
containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vuln
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started