Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontro
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontro
The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.2 and 4.20.2, the library perm
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to unbounde
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontro
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontro
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper
Uncontrolled resource consumption in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthe
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.2, the join filter in
Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontro
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a crafted UDP packet to
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and
justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkificatio
An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-
libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh pa
Ech0 before 5.0.1 does not impose any size or shape limit on the Accept-Language header processed by its i18n middleware
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application
icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Comp
Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking w
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of
openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allo
Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a
An attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresse
An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenti
An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which
SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunction
SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a C
vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMed
An issue in the seekdir() function (/dirent/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Servic
An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Servic
multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is abort
multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted
Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Core). The sup
Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutra
IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource consumption.
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is a
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos
Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachm
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).
Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). Th
Volcano is a Kubernetes-native batch scheduling system. Prior to v1.14.2, v1.13.3, and v1.12.4, the Volcano webhook serv
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.4` contai
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Fluid Core). Supported
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve
Paessler PRTG Network Monitor before 25.4.114 allows Denial-of-Service (DoS) by an authenticated attacker via the Notifi
Frequently Asked Questions
What is CWE-400?
CWE-400 (CWE-400) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-400?
There are 3,937 CVE records associated with CWE-400 in our database. Of these, 58 are critical severity, 1666 are high severity, and 1500 are medium severity.
How can I protect against CWE-400 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-400 using AI-powered security agents.
Detect CWE-400 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-400 vulnerabilities across your infrastructure.
Get Started