On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6
On F5 BIG-IP 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when multiple route domains are con
The Multipass service was found to have code paths that could be abused to cause a denial of service for authentication
In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated
RSSHub is an open source, extensible RSS feed generator. In commits prior to 5c4177441417 passing some special values to
OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsIn
A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out
JOSE is "JSON Web Almost Everything" - JWA, JWS, JWE, JWT, JWK, JWKS with no dependencies using runtime's native crypto
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i80
supybot-fedora implements the command 'refresh', that refreshes the cache of all users from FAS. This takes quite a whil
A vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) Software could allow
An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.
A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmwar
The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with net
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.50), SIPROTEC 5 6MD85 (CP200) (All ve
Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontr
Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at
A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for
An issue was discovered in the MediaWiki through 1.38.2. The community configuration pages for the GrowthExperiments ext
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user who can create search macros and schedule se
Cargo is a package manager for the rust programming language. It was discovered that Cargo did not limit the amount of d
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server prior
The Zoom Client for Meetings chat functionality was susceptible to Zip bombing attacks in the following product versions
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at
Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at
A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while
Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while draft
A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions
A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Ha
Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.
The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied imag
Logging of Excessive Data vulnerability in audit log of Secomea GateManager allows logged in user to write text entries
On all versions of 17.0.x, 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x on F5 BIG-IP, an authenticated iControl RE
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2.
Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the
The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported fi
A Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scannin
Samourai Wallet Stonewallx2 0.99.98e allows a denial of service via a P2P coinjoin. The attacker and victim must follow
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all version
Dell PowerStore contains an Uncontrolled Resource Consumption Vulnerability in PowerStore User Interface. A remote unaut
A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function
Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can caus
An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigg
An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DO
Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit u
Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5, calendar name lengths ar
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started