Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-400

MITRE ↗

CWE-400

58
CRITICAL
1,666
HIGH
1,500
MEDIUM
123
LOW
3,438 CVEs · Page 15/69
5.3
CVE-2026-48990

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar

5.3
CVE-2026-57962

A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitr

5.3
CVE-2026-55594

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-

5.3
CVE-2026-54712

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. I

5.3
CVE-2026-58203

pydantic-settings provides settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSecretsSettingsSource rea

5.3
CVE-2026-8609

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory

5.3
CVE-2026-48125

UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From

5.3
CVE-2026-44433

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b

5.3
CVE-2026-53596

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeSco

5.3
CVE-2026-47021

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE

5.3
CVE-2026-61070

Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Cash Ma

5.3
CVE-2026-61192

Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The

5.3
CVE-2026-21723

The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates

5.3
CVE-2026-66299

Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache To

5.3
CVE-2026-19113

Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of servic

5.3
CVE-2026-54338

JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid in

5.3
CVE-2026-73228

Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing

5.3
CVE-2026-73556

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex paramet

5.3
CVE-2026-17078

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to resource exhaustion.

5.3
CVE-2026-19830

A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of th

5.3
CVE-2026-63016

Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational configuration or allow

5.3
CVE-2026-67445

Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit reads SMTP commands through internal/s

5.3
CVE-2026-67446

Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-supplied image attach

5.3
CVE-2026-78684

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decod

5.3
CVE-2026-59315

The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads. Spring Cloud Config

5.3
CVE-2026-82256

SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the N

5.0
CVE-2026-21942

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). Supported versions that are aff

5.0
CVE-2025-69644

An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing

5.0
CVE-2026-54786

Wasmtime is a runtime for WebAssembly. All versions prior to 24.0.10; versions 25.0.0 through those before 36.0.11; ver

4.9
CVE-2026-21941

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

4.9
CVE-2026-21948

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

4.9
CVE-2026-21952

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affe

4.9
CVE-2026-22228

An authenticated user with high privileges may trigger a denial‑of‑service condition in TP-Link Archer BE230 v1.2 by res

4.9
CVE-2026-3116

Mattermost Plugins versions <=11.4 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to validate incoming request size which allows a

4.9
CVE-2026-21998

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

4.9
CVE-2026-22002

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

4.9
CVE-2026-22004

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are

4.9
CVE-2026-22005

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

4.9
CVE-2026-34267

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

4.9
CVE-2026-34278

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

4.9
CVE-2026-34293

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte

4.9
CVE-2026-34304

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are

4.9
CVE-2026-28967

A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.

4.9
CVE-2026-5308

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request bo

4.9
CVE-2026-11790

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on t

4.9
CVE-2026-47008

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: InnoDB). Supported versions that a

4.9
CVE-2026-47023

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported ve

4.9
CVE-2026-47052

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: InnoDB). Supported versions that a

4.9
CVE-2026-60171

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are

4.9
CVE-2026-61128

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported vers

Frequently Asked Questions

What is CWE-400?

CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-400?

There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.

How can I protect against CWE-400 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.

Detect CWE-400 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.

Get Started