Mattermost fails to to check the length when setting the title in a run checklist in Playbooks, allowing an attacker to
Mattermost fails to handle a null request body in the /add endpoint, allowing a simple member to send a request with nul
Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integra
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29
Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `b
A vulnerability was found in y_project RuoYi up to 4.7.7. It has been classified as problematic. Affected is the functio
A vulnerability has been found in OmniSharp csharp-language-server-protocol up to 0.19.6 and classified as problematic.
Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue af
Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1
Uncontrolled resource consumption in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a priviledg
Microsoft Access Denial of Service Vulnerability
Keep-alive vulnerability in the sticky broadcast mechanism. Successful exploitation of this vulnerability may cause mali
An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 b
Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enro
Cosign is a sigstore signing tool for OCI containers. Cosign is susceptible to a denial of service by an attacker contro
Discourse is an open source platform for community discussion. In affected versions a maliciously crafted request from a
Fides is an open-source privacy engineering platform for managing data privacy requests and privacy regulations. The Fid
Fides is an open-source privacy engineering platform for managing data privacy requests and privacy regulations. The Fid
IBM Security Verify Privilege On-Premises 11.5 could allow a privileged user to cause by using a malicious payload. IB
Affected devices do not properly validate the length of inputs when performing certain configuration changes in the web
notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry
A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logic
A flaw was found in StarWind iSCSI target. StarWind service does not limit client connections and allocates memory on ea
A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability m
A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large
Certain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory de
A remote potential adjacent denial of service (DoS) and potential adjacent arbitrary code execution vulnerability that c
A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could allow an unauthentic
A vulnerability in the DNS inspection handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat D
The denial-of-service can be triggered by transmitting a carefully crafted CAN frame on the same CAN network as the vuln
CAMS for HIS Log Server contained in the following Yokogawa Electric products is vulnerable to uncontrolled resource con
A DMA reentrancy issue was found in the Tulip device emulation in QEMU. When Tulip reads or writes to the rx/tx descript
A vulnerability in the NETCONF over SSH feature of Cisco IOS XE Software could allow a low-privileged, authenticated, re
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to c
Authenticated (subscriber+) Denial Of Service (DoS) vulnerability in WordPlus WordPress Better Messages plugin <= 1.9.10
Flux2 is a tool for keeping Kubernetes clusters in sync with sources of configuration, and Flux's helm-controller is a K
net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicaliza
The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integ
There is an uncontrolled resource consumption vulnerability in the display module. Successful exploitation of this vulne
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. A denial of service
Possible denial of service due to out of memory while processing RRC and NAS OTA message in Snapdragon Auto, Snapdragon
Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastro
Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `inline.reflinkSearch` may cau
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien
An Uncontrolled Resource Consumption vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated
Requests may be used to interrupt the normal operation of the device. When exploited, Fresenius Kabi Agilia Link+ versio
On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, and 14.1.2.6-14.1.4.4, when a Client SSL profile is confi
On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.2, and all versions of 13.1.x, wh
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started