Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-400

MITRE ↗

CWE-400

58
CRITICAL
1,666
HIGH
1,500
MEDIUM
123
LOW
3,438 CVEs · Page 25/69
5.5
CVE-2025-48584

In multiple functions of NotificationManagerService.java, there is a possible way to bypass the per-package channel limi

5.5
CVE-2025-48590

In verifyAndGetBypass of AppOpsService.java, there is a possible method for a malicious app to prevent dialing emergency

5.5
CVE-2025-48603

In InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to resource exhaustion.

5.5
CVE-2025-48569

In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to lo

5.5
CVE-2025-59529

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions

5.4
CVE-2025-53636

Open OnDemand is an open-source HPC portal. Users can flood logs by interacting with the shell app and generating many e

5.4
CVE-2025-46171

vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticat

5.3
CVE-2025-0704

A vulnerability, which was classified as problematic, was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e

5.3
CVE-2024-23814

The integrated ICMP service of the network stack of affected devices can be forced to exhaust its available memory reso

5.3
CVE-2024-6838

In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a la

5.3
CVE-2025-2833

A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been classified as problematic. Affected is an unknow

5.3
CVE-2025-32472

The multiScan and picoScan are vulnerable to a denial-of-service (DoS) attack. A remote attacker can exploit this vulner

5.3
CVE-2025-30476

Dell PowerScale InsightIQ, version 5.2, contains an uncontrolled resource consumption vulnerability. An unauthenticated

5.3
CVE-2025-6492

A vulnerability has been found in MarkText up to 0.17.1 and classified as problematic. Affected by this vulnerability is

5.3
CVE-2025-6493

A weakness has been identified in CodeMirror up to 5.65.20. Affected is an unknown function of the file mode/markdown/ma

5.3
CVE-2025-54575

ImageSharp is a 2D graphics library. In versions below 2.1.11 and 3.0.0 through 3.1.10, a specially crafted GIF file con

5.3
CVE-2025-55152

oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and

5.3
CVE-2025-9670

A security flaw has been discovered in mixmark-io turndown up to 7.2.1. This affects an unknown function of the file src

5.3
CVE-2025-58369

fs2 is a compositional, streaming I/O library for Scala. Versions up to and including 2.5.12, 3.0.0-M1 through 3.12.2, a

5.3
CVE-2025-59139

Hono is a Web application framework that provides support for any JavaScript runtime. In versions prior to 4.9.7, a flaw

5.3
CVE-2025-35432

CISA Thorium does not rate limit requests to send account verification email messages. A remote unauthenticated attacker

5.3
CVE-2025-58767

REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing

5.3
CVE-2025-6599

An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C

5.1
CVE-2025-46593

Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulner

5.1
CVE-2025-58436

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.

4.9
CVE-2025-21529

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions t

4.9
CVE-2024-52981

An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested

4.9
CVE-2025-30705

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected

4.9
CVE-2025-30715

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions

4.9
CVE-2025-49595

n8n is a workflow automation platform. Prior to version 1.99.0, there is a denial of Service vulnerability in /rest/bina

4.9
CVE-2025-50077

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are

4.9
CVE-2025-50079

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

4.9
CVE-2025-50080

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions tha

4.9
CVE-2025-50088

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are

4.9
CVE-2025-50089

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

4.9
CVE-2025-50091

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

4.9
CVE-2025-50092

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are

4.9
CVE-2025-50093

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affecte

4.9
CVE-2025-50094

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affecte

4.9
CVE-2025-50095

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

4.9
CVE-2025-50097

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions

4.9
CVE-2025-50099

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are

4.9
CVE-2025-50101

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

4.9
CVE-2025-50102

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

4.9
CVE-2025-53023

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are

4.9
CVE-2025-41676

A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to

4.9
CVE-2025-41677

A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to

4.9
CVE-2025-20370

In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.1

4.9
CVE-2025-53040

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

4.9
CVE-2025-53042

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

Frequently Asked Questions

What is CWE-400?

CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-400?

There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.

How can I protect against CWE-400 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.

Detect CWE-400 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.

Get Started