Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the s
Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are aff
A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a special
A logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.6. Enabling Lockdown
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions
es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into
An uncontrolled resource consumption of file descriptors in SEH Computertechnik utnserver Pro, SEH Computertechnik utnse
A denial-of-service vulnerability exists via the CIP/Modbus port in the Rockwell Automation Micro850/870 (2080 -L50E/208
Authenticated users can upload specifically crafted files to leak server resources. This behavior can potentially be use
In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the auto-generation functi
In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the refuse function was id
In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was
An issue exists in SoftIron HyperCloud where authenticated, but non-admin users can create data pools, which could pote
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 bu
The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super
Through the exploitation of active user sessions, an attacker could send custom requests to cause a denial-of-service c
Vulnerability discovered is related to the peer-to-peer (p2p) communications, attackers can craft consensus messages, se
An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or writ
Switcher Client is a JavaScript SDK to work with Switcher API which is cloud-based Feature Flag. Unsanitized input flows
get-func-name is a module to retrieve a function's name securely and consistently both in NodeJS and the browser. Versio
A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, rem
Boxo, formerly known as go-libipfs, is a library for building IPFS applications and implementations. In versions 0.4.0 a
Control de Ciber, in its 1.650 version, is affected by a Denial of Service condition through the version function. Sendi
Buffer Overflow vulnerability in Control de Ciber version 1.650, in the printing function. Sending a modified request by
Cyber Control, in its 1.650 version, is affected by a vulnerability in the generation on the server of pop-up windows wi
ASP.NET Core Denial of Service Vulnerability
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated
Shenzhen Hichip Vision Technology IP Camera Firmware V11.4.8.1.1-20170926 has a denial of service vulnerability through
Werkzeug is a comprehensive WSGI web application library. In versions on the 3.x branch prior to 3.0.1 and on the 2.x br
In addPermission of PermissionManagerServiceImpl.java , there is a possible failure to persist permission settings due t
Denial of Service in GitHub repository gpac/gpac prior to 2.4.0.
In several functions of SnoozeHelper.java, there is a possible way to grant notifications access due to resource exhaust
An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecifie
An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecifie
A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally au
Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
Windows Netlogon Denial of Service Vulnerability
An Uncontrolled Resource Consumption vulnerability in TCP processing on the Routing Engine (RE) of Juniper Networks Juno
An Uncontrolled Resource Consumption vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos
Mercedes-Benz XENTRY Retail Data Storage 7.8.1 allows remote attackers to cause a denial of service (device restart) via
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
Unauthenticated denial of service
Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `
On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in version 1.6.0, when a c
On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.0 before 15.1.8, 14.1.x before 14.1.5.3, and all versio
Dell Enterprise SONiC OS, 3.5.3, 4.0.0, 4.0.1, 4.0.2, contains an "Uncontrolled Resource Consumption vulnerability" in
opentelemetry-go-contrib is a collection of extensions for OpenTelemetry-Go. The v0.38.0 release of `go.opentelemetry.io
A denial of service vulnerability present in ActiveRecord's PostgreSQL adapter <7.0.4.1 and <6.1.7.1. When a value outsi
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started