Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-400

MITRE ↗

CWE-400

58
CRITICAL
1,666
HIGH
1,500
MEDIUM
123
LOW
3,438 CVEs · Page 30/69
7.5
CVE-2024-6427

Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can u

7.5
CVE-2024-34750

Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When proc

7.5
CVE-2023-52340

The IPv6 implementation in the Linux kernel before 6.3 has a net/ipv6/route.c max_size threshold that can be consumed ea

7.5
CVE-2024-30105

.NET and Visual Studio Denial of Service Vulnerability

7.5
CVE-2024-38015

Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability

7.5
CVE-2024-38031

Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability

7.5
CVE-2024-38067

Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability

7.5
CVE-2024-38068

Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability

7.5
CVE-2024-21521

All versions of the package @discordjs/opus are vulnerable to Denial of Service (DoS) due to providing an input object w

7.5
CVE-2024-21523

All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to

7.5
CVE-2024-21526

All versions of the package speaker are vulnerable to Denial of Service (DoS) when providing unexpected input types to t

7.5
CVE-2024-39693

Next.js is a React framework. A Denial of Service (DoS) condition was identified in Next.js. Exploitation of the bug can

7.5
CVE-2024-39548

An Uncontrolled Resource Consumption vulnerability in the aftmand process of Juniper Networks Junos OS Evolved allows an

7.5
CVE-2024-39551

An Uncontrolled Resource Consumption vulnerability in the H.323 ALG (Application Layer Gateway) of  Juniper Networks Jun

7.5
CVE-2024-32007

An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an at

7.5
CVE-2024-40634

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability i

7.5
CVE-2024-41818

fast-xml-parser is an open source, pure javascript xml parser. a ReDOS exists on currency.js. This vulnerability is fixe

7.5
CVE-2024-41989

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to

7.5
CVE-2024-42481

Skyport Daemon (skyportd) is the daemon for the Skyport Panel. By making thousands of folders & files (easy due to skypo

7.5
CVE-2024-38168

.NET and Visual Studio Denial of Service Vulnerability

7.5
CVE-2024-41727

In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using Intel E810 SR-IOV NI

7.5
CVE-2024-42943

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSe

7.5
CVE-2024-42950

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the Go parameter in the fromSafeClientFilter

7.5
CVE-2024-42951

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the mit_pptpusrpw parameter in the fromWizar

7.5
CVE-2024-42969

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeUrlFilter fun

7.5
CVE-2024-42980

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the frmL7ImForm function.

7.5
CVE-2024-42981

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting

7.5
CVE-2024-7592

There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When

7.5
CVE-2024-8182

An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of

7.5
CVE-2024-8418

A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP

7.5
CVE-2024-43647

A vulnerability has been identified in SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0) (All versions), SIMATIC S7-200

7.5
CVE-2024-38236

DHCP Server Service Denial of Service Vulnerability

7.5
CVE-2024-27874

This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. A remote attack

7.5
CVE-2023-28451

An issue was discovered in Technitium 11.0.2. There is a vulnerability (called BadDNS) in DNS resolving software, which

7.5
CVE-2024-7254

Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGRO

7.5
CVE-2024-31145

Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reportin

7.5
CVE-2024-31146

When multiple devices share resources and one of them is to be passed through to a guest, security of the entire system

7.5
CVE-2024-37125

Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x,10.5.3.x, contains an Uncontrolled Resource Consum

7.5
CVE-2024-8451

Certain switch models from PLANET Technology have an SSH service that improperly handles insufficiently authenticated co

7.5
CVE-2024-47850

CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a sing

7.5
CVE-2024-43789

Discourse is an open source platform for community discussion. A user can create a post with many replies, and then atte

7.5
CVE-2024-8626

Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious

7.5
CVE-2024-38149

BranchCache Denial of Service Vulnerability

7.5
CVE-2024-43506

BranchCache Denial of Service Vulnerability

7.5
CVE-2024-43515

Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability

7.5
CVE-2024-43541

Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability

7.5
CVE-2024-43544

Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability

7.5
CVE-2024-43545

Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability

7.5
CVE-2024-43575

Windows Hyper-V Denial of Service Vulnerability

7.5
CVE-2024-7294

In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous

Frequently Asked Questions

What is CWE-400?

CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-400?

There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.

How can I protect against CWE-400 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.

Detect CWE-400 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.

Get Started