Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-400

MITRE ↗

CWE-400

58
CRITICAL
1,666
HIGH
1,500
MEDIUM
123
LOW
3,438 CVEs · Page 9/69
7.5
CVE-2026-73882

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

7.5
CVE-2026-16690

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontro

7.5
CVE-2026-16818

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontro

7.5
CVE-2026-49289

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.2 and 4.20.2, the library perm

7.5
CVE-2026-16824

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to unbounde

7.5
CVE-2026-16831

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontro

7.5
CVE-2026-16836

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontro

7.5
CVE-2026-16837

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper

7.5
CVE-2026-19507

Uncontrolled resource consumption in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthe

7.5
CVE-2026-69222

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.2, the join filter in

7.5
CVE-2026-63495

Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c

7.5
CVE-2026-17121

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontro

7.5
CVE-2026-19446

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a crafted UDP packet to

7.5
CVE-2026-55241

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and

7.5
CVE-2026-4671

justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkificatio

7.5
CVE-2026-75371

An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-

7.5
CVE-2026-77384

libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh pa

7.5
CVE-2026-79658

Ech0 before 5.0.1 does not impose any size or shape limit on the Accept-Language header processed by its i18n middleware

7.5
CVE-2026-71360

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application

7.5
CVE-2026-55099

icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Comp

7.5
CVE-2026-68763

Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking w

7.5
CVE-2025-61478

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker

7.5
CVE-2025-61480

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker

7.5
CVE-2026-47886

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of

7.5
CVE-2026-81721

openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allo

7.5
CVE-2026-59282

Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a

7.5
CVE-2026-27852

An attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresse

7.5
CVE-2026-33605

An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenti

7.5
CVE-2026-42391

An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which

7.5
CVE-2026-82260

SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunction

7.5
CVE-2026-82261

SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a C

7.5
CVE-2026-37237

vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMed

7.5
CVE-2026-38636

An issue in the seekdir() function (/dirent/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Servic

7.5
CVE-2026-38638

An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Servic

7.5
CVE-2026-77037

multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is abort

7.5
CVE-2026-82333

multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted

7.4
CVE-2026-60667

Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Core). The sup

7.3
CVE-2026-43870

Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutra

7.1
CVE-2026-7528

IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource consumption.

7.1
CVE-2026-46914

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is a

7.1
CVE-2026-47214

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos

7.1
CVE-2026-52890

Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachm

7.1
CVE-2026-60647

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).

7.1
CVE-2026-61165

Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). Th

6.8
CVE-2026-44247

Volcano is a Kubernetes-native batch scheduling system. Prior to v1.14.2, v1.13.3, and v1.12.4, the Volcano webhook serv

6.7
CVE-2026-33623

PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.4` contai

6.7
CVE-2026-60846

Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server

6.6
CVE-2026-34277

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Fluid Core). Supported

6.6
CVE-2026-62465

Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve

6.5
CVE-2025-67835

Paessler PRTG Network Monitor before 25.4.114 allows Denial-of-Service (DoS) by an authenticated attacker via the Notifi

Frequently Asked Questions

What is CWE-400?

CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-400?

There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.

How can I protect against CWE-400 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.

Detect CWE-400 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.

Get Started