A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to ca
Transient DOS in WLAN Firmware while parsing a NAN management frame.
OpenTelemetry, also known as OTel for short, is a vendor-neutral open-source Observability framework for instrumenting,
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
Eclipse Jetty provides a web server and servlet container. In versions 11.0.0 through 11.0.15, 10.0.0 through 10.0.15, a
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft QUIC Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
DHCP Server Service Denial of Service Vulnerability
A denial-of-service vulnerability exists in the vpnserver ConnectionAccept() functionality of SoftEther VPN 5.02. A set
ONTAP 9 versions prior to 9.8P19, 9.9.1P16, 9.10.1P12, 9.11.1P8, 9.12.1P2 and 9.13.1 are susceptible to a vulnerability
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper
IBM Security Verify Access OIDC Provider could allow a remote user to cause a denial of service due to uncontrolled reso
silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a re
Discourse is an open source platform for community discussion. A malicious request can cause production log files to qui
An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection
PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java
Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. T
An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user
In Minikin, there is a possible way to trigger ANR by showing a malicious message due to resource exhaustion. This could
An issue discovered in Govee LED Strip v3.00.42 allows attackers to cause a denial of service via crafted Move and MoveW
An issue discovered in Nanoleaf Light strip v3.5.10 allows attackers to cause a denial of service via crafted write bind
A vulnerability in a logging API in Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, rem
In certain conditions for Calico Typha (v3.26.2, v3.25.1 and below), and Calico Enterprise Typha (v3.17.1, v3.16.3, v3.1
In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was
In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the commit function was id
In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the buffer was identified.
Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Success
Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the BLE daemon service accessed via the PAPI protocol.
An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not
An issue in the box_equal function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service
Traefik is an open source HTTP reverse proxy and load balancer. The traefik docker container uses 100% CPU when it serve
Dell OS10 Networking Switches running 10.5.2.x and above contain an Uncontrolled Resource Consumption (Denial of Servic
A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exha
A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaus
A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion.
A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.
Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls
`nuxt-api-party` is an open source module to proxy API requests. The library allows the user to send many options direct
Denial-of-service (DoS) vulnerability exists in FTP service of HMI GC-A2 series. If a remote unauthenticated attacker se
Denial-of-service (DoS) vulnerability exists in commplex-link service of HMI GC-A2 series. If a remote unauthenticated a
Denial-of-service (DoS) vulnerability exists in rfe service of HMI GC-A2 series. If a remote unauthenticated attacker se
Denial-of-service (DoS) vulnerability exists in NetBIOS service of HMI GC-A2 series. If a remote unauthenticated attacke
An uncaught exception issue discovered in Softing OPC UA C++ SDK before 6.30 for Windows operating system may cause the
Sentry-Javascript is official Sentry SDKs for JavaScript. A ReDoS (Regular expression Denial of Service) vulnerability h
Grackle is a GraphQL server written in functional Scala, built on the Typelevel stack. The GraphQL specification require
mx-chain-go is the official implementation of the MultiversX blockchain protocol, written in golang. When executing a re
An adversary could crash the entire device by sending a large quantity of ICMP requests if the controller has the built-
An adversary could cause a continuous restart loop to the entire device by sending a large quantity of HTTP GET requests
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started