Strapi is the an open-source headless content management system. Prior to version 4.12.1, field level permissions are no
A use-after-free flaw was found in btrfs_get_dev_args_from_path in fs/btrfs/volumes.c in btrfs file-system in the Linux
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.1 could allow an authenticated user to exhaust server res
A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which ca
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco Webex Room Phone and Cisco Webex Share devi
Authenticated denial of service
Nordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers
A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8
Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS pa
Korenix JetWave 4200 Series 1.3.0 and JetWave 3200 Series 1.6.0 are vulnerable to Denial of Service via /goform/formDefa
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user t
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754,
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754,
Microsoft Excel Denial of Service Vulnerability
Windows Hyper-V Denial of Service Vulnerability
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue c
In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versio
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. When a user with checkuserlog permissio
An issue found in Directus API v.2.2.0 allows a remote attacker to cause a denial of service via a great amount of HTTP
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrol
SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attac
In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a speci
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrol
An issue was discovered in ONOS 2.5.1. To attack an intent installed by a normal user, a remote attacker can install a d
Denial-of-service (DoS) vulnerability in Message of Cybozu Garoon 4.10.0 to 5.9.2 allows a remote authenticated attacker
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malici
mp4v2 v2.1.2 was discovered to contain a memory leak via the class MP4BytesProperty.
If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and d
If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused mem
zxcvbn-ts is an open source password strength estimator written in typescript. This vulnerability affects users running
Mattermost fails to validate links on external websites when constructing a preview for a linked website, allowing an at
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performan
Windows Authentication Denial of Service Vulnerability
Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar secti
An issue was discovered in ngiflib 0.4. There is SEGV in SDL_LoadAnimatedGif when use SDLaffgif. poc : ./SDLaffgif CA_fi
An issue was discovered in StaticPool in SUCHMOKUO node-worker-threads-pool version 1.4.3, allows attackers to cause a d
In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes w
read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can use the `printf` SPL function to perf
A denial-of-service issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3. A rem
Argo CD is a declarative continuous deployment for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug wher
.NET Core and Visual Studio Denial of Service Vulnerability
Uncontrolled resource consumption in ekorRCI, allowing an attacker with low-privileged access to the web server to send
A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 17 and iPadOS 17, m
Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really lo
Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_error at /jbig2dec/jbig2.c.
An issue in TP-Link Tapo C100 v1.1.15 Build 211130 Rel.15378n(4555) and before allows attackers to cause a Denial of Ser
Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.1.0 to 4.1.1 allows a remote authenticated at
A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiat
A vulnerability was found in Samba's "rpcecho" development server, a non-Windows RPC server used to test Samba's DCE/RPC
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started