VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective authentication serv
An uncontrolled resource consumption vulnerability in Palo Alto Networks PAN-OS allows for a remote unauthenticated user
Receiving a large text message containing URLs in WhatsApp for iOS prior to v2.20.91.4 could have caused the application
This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The
All versions of package express-validators are vulnerable to Regular Expression Denial of Service (ReDoS) when validatin
All versions of package djvalidator are vulnerable to Regular Expression Denial of Service (ReDoS) by sending crafted in
A denial of service exists in strapi v3.0.0-beta.18.3 and earlier that can be abused in the admin console using admin ri
An issue was discovered in GitLab Community and Enterprise Edition 11.11 through 12.0.2. When an admin enabled one of th
Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a
An issue was discovered in GitLab Enterprise Edition 8.11.0 through 12.0.2. By using brute-force a user with access to a
A potential DOS vulnerability was discovered in GitLab versions 13.1, 13.2 and 13.3. The api to update an asset as a lin
A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name che
An issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a f
A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to tr
In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of
nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).
A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, loc
In freewvs before 0.1.1, a user could create a large file that freewvs will try to read, which will terminate a scan pro
In freewvs before 0.1.1, a directory structure of more than 1000 nested directories can interrupt a freewvs scan due to
A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject prope
A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.
A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary
A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitra
Rockwell Automation PowerFlex 525 AC Drives 5.001 and earlier allow remote attackers to cause a denial of service by cra
An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code exec
Index of array is processed in a wrong way inside a while loop and result in invalid index (-1 or something else) leads
Resource allocation error while playing the video whose dimensions are more than supported dimension in Snapdragon Auto,
set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked in
deeply is vulnerable to Prototype Pollution in versions before 3.1.0. The function assign-deep could be tricked into add
A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip dri
In IoTivity through 1.3.1, the CoAP server interface can be used for Distributed Denial of Service attacks using source
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before
A vulnerability in the processing of IP Service Level Agreement (SLA) packets by Cisco IOS Software and Cisco IOS XE sof
A vulnerability in the WebVPN login process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Thre
A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for the
A vulnerability in the interactions between the DHCP and TFTP features for Cisco Small Business 300 Series (Sx300) Manag
A vulnerability in the cryptographic driver for Cisco Adaptive Security Appliance Software (ASA) and Firepower Threat De
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5),
A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Softwa
eQ-3 Homematic CCU2 and CCU3 obtain session IDs without login. This allows a Denial of Service and is a starting point f
There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a c
A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow an authenticated, rem
A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool o
A vulnerability in the UDP protocol implementation for Cisco IoT Field Network Director (IoT-FND) could allow an unauthe
SPARQL Injection in VIVO Vitro v1.10.0 allows a remote attacker to execute arbitrary SPARQL via the uri parameter, leadi
A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary propert
Mitsubishi Electric Q03/04/06/13/26UDVCPU: serial number 20081 and prior, Q04/06/13/26UDPVCPU: serial number 20081 and p
Denial of Service attack in airMAX < 8.3.2 , airMAX < 6.0.7 and EdgeMAX < 1.9.7 allow attackers to use the Discovery Pro
An issue was discovered in WTCMS 1.0. It allows remote attackers to cause a denial of service (resource consumption) via
An error when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif version 0.6.21 can be explo
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started