Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-400

MITRE ↗

CWE-400

58
CRITICAL
1,666
HIGH
1,500
MEDIUM
123
LOW
3,438 CVEs · Page 23/69
6.5
CVE-2025-25186

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and

6.5
CVE-2024-54658

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, mac

6.5
CVE-2025-21352

Internet Connection Sharing (ICS) Denial of Service Vulnerability

6.5
CVE-2025-27100

lakeFS is an open-source tool that transforms your object storage into a Git-like repository. In affected versions an au

6.5
CVE-2024-11033

A Denial of Service (DoS) vulnerability exists in the file upload feature of binary-husky/gpt_academic version 3.83. The

6.5
CVE-2024-12074

A Denial of Service (DoS) vulnerability was discovered in the file upload feature of automatic1111/stable-diffusion-webu

6.5
CVE-2024-7771

A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denia

6.5
CVE-2025-0191

A Denial of Service (DoS) vulnerability exists in the file upload feature of gaizhenbiao/chuanhuchatgpt version 20240914

6.5
CVE-2025-2820

An authenticated attacker can compromise the availability of the device via the network

6.5
CVE-2025-29490

libming v0.4.8 was discovered to contain a segmentation fault via the decompileCALLMETHOD function. This vulnerability a

6.5
CVE-2024-52974

An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana serve

6.5
CVE-2024-52980

A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the

6.5
CVE-2025-21574

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affe

6.5
CVE-2025-21575

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affe

6.5
CVE-2025-21577

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are

6.5
CVE-2025-43857

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.5.7, 0.4.

6.5
CVE-2024-52979

Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache

6.5
CVE-2025-43915

In Linkerd edge releases before edge-25.2.1, and Buoyant Enterprise for Linkerd releases 2.13.0–2.13.7, 2.14.0–2.14.10,

6.5
CVE-2025-46392

Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x. There are a number of issues in Ap

6.5
CVE-2025-31210

The issue was addressed with improved UI. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. Processing web

6.5
CVE-2025-22892

Uncontrolled resource consumption for some OpenVINO™ model server software maintained by Intel(R) before version 2024.4

6.5
CVE-2025-3112

CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause Denial of Service when an authenticated

6.5
CVE-2025-44559

An issue in the Bluetooth Low Energy (BLE) stack of Realtek RTL8762E BLE SDK v1.4.0 allows attackers within Bluetooth ra

6.5
CVE-2025-6712

MongoDB Server may be susceptible to disruption caused by high memory usage, potentially leading to server crash. This c

6.5
CVE-2025-53893

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ

6.5
CVE-2025-30753

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t

6.5
CVE-2025-50076

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte

6.5
CVE-2025-50078

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte

6.5
CVE-2025-50082

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

6.5
CVE-2025-50083

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

6.5
CVE-2025-50861

The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, whi

6.5
CVE-2025-55028

Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and all

6.5
CVE-2025-55521

An issue in the component /settings/localisation of Akaunting v3.1.18 allows authenticated attackers to cause a Denial o

6.5
CVE-2025-54995

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP

6.5
CVE-2025-29898

An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains

6.5
CVE-2025-52867

An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains

6.5
CVE-2025-52961

An Uncontrolled Resource Consumption vulnerability in the Connectivity Fault Management (CFM) daemon and the Connectivit

6.5
CVE-2025-37148

A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an unauthenticated remote atta

6.5
CVE-2025-60790

ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is

6.5
CVE-2025-53068

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affec

6.5
CVE-2025-62706

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JWE zip=DEF

6.5
CVE-2025-11681

Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2

6.5
CVE-2025-55128

HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in th

6.5
CVE-2025-48631

In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhausti

6.5
CVE-2025-8872

On affected platforms running Arista EOS with OSPFv3 configured, a specially crafted packet can cause the OSFPv3 process

6.5
CVE-2025-60458

UxPlay 1.72 contains a double free vulnerability in its RTSP request handling. A specially crafted RTSP TEARDOWN request

6.4
CVE-2025-21548

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that ar

6.4
CVE-2023-42983

Processing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS

6.3
CVE-2024-13065

Improper Enforcement of Behavioral Workflow, Uncontrolled Resource Consumption vulnerability in Akinsoft MyRezzta allows

6.2
CVE-2025-0426

A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthen

Frequently Asked Questions

What is CWE-400?

CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-400?

There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.

How can I protect against CWE-400 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.

Detect CWE-400 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.

Get Started