Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-404

MITRE ↗

CWE-404

2
CRITICAL
161
HIGH
412
MEDIUM
187
LOW
766 CVEs · Page 5/16
3.3
CVE-2026-14790

A flaw has been found in GPAC 26.02.0. This affects the function nhmldump_send_frame of the file src/filters/write_nhml.

3.3
CVE-2026-14801

A security vulnerability has been detected in GPAC 26.03-DEV-rev342-g80071f700-master. The impacted element is the funct

3.3
CVE-2026-15184

A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_next_entity of the file

3.3
CVE-2026-15274

A vulnerability was detected in lo48576 fbxcel up to 0.9.0. This affects an unknown part of the file src/pull_parser/v74

3.3
CVE-2026-15276

A flaw has been found in pdeljanov Symphonia up to 0.6.0. This vulnerability affects unknown code of the component Metad

3.3
CVE-2026-76014

A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/w

3.1
CVE-2026-3465

A vulnerability was determined in Tuya App and SDK 24.07.11 on Android. Affected by this vulnerability is an unknown fun

3.1
CVE-2026-10705

A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/datafram

3.1
CVE-2026-15690

A vulnerability was identified in open62541 up to 1.5.5. Affected by this issue is the function responseReadNamespacesAr

2.8
CVE-2026-61187

Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The

2.3
CVE-2026-19382

A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan

1.9
CVE-2026-61028

Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations). S

CVE-2026-3206

Improper Resource Shutdown or Release vulnerability in KrakenD, SLU KrakenD-CE (CircuitBreaker modules), KrakenD, SLU Kr

CVE-2026-11317

A denial of service security issue exists in the affected product. The security issue stems from a fault occurring when

CVE-2026-17610

In SiSDK v2026.6.0 and earlier, high network traffic loads can cause a dropped ACK leading to a denial of service. This

8.0
CVE-2025-5867

A vulnerability classified as critical was found in RT-Thread 5.1.0. This vulnerability affects the function csys_sendto

7.8
CVE-2024-56757

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: add intf release flow w

7.8
CVE-2025-38385

In the Linux kernel, the following vulnerability has been resolved: net: usb: lan78xx: fix WARN in __netif_napi_del_loc

7.7
CVE-2025-20127

A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firewall Adaptive Security Applianc

7.5
CVE-2024-55553

In FRRouting (FRR) before 10.3 from 6.0 onward, all routes are re-validated if the total size of an update received via

7.5
CVE-2024-57618

An issue in the bind_col_exp component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) v

7.5
CVE-2024-57623

An issue in the HEAP_malloc component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via

7.5
CVE-2024-57654

An issue in the qst_vec_get_int64 component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial o

7.5
CVE-2024-57659

An issue in the sqlg_parallel_ts_seq component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denia

7.5
CVE-2024-57661

An issue in the sqlo_df component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service

7.5
CVE-2025-0492

A vulnerability has been found in D-Link DIR-823X 240126/240802 and classified as critical. Affected by this vulnerabili

7.5
CVE-2025-22846

When SIP Session and Router ALG profiles are configured on a Message Routing type virtual server, undisclosed traffic ca

7.5
CVE-2025-24811

A vulnerability has been identified in SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0), SIMATIC S7-1200 CPU 121

7.5
CVE-2025-29357

Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the startIp and endIp parameters at

7.5
CVE-2025-29313

Use of incorrectly resolved name or reference in OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4

7.5
CVE-2024-47213

An issue was discovered affecting Enrich 5.1.0 and below. It involves sending a maliciously crafted Snowplow event to th

7.5
CVE-2025-41399

When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can c

7.5
CVE-2025-31237

This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ven

7.5
CVE-2025-4749

A vulnerability classified as critical was found in D-Link DI-7003GV2 24.04.18D1 R(68125). This vulnerability affects th

7.5
CVE-2025-8761

A vulnerability has been found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This vulnerability affects unknown code of the co

7.5
CVE-2025-48989

Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack

7.5
CVE-2025-8671

A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architect

7.5
CVE-2025-9784

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering ab

7.5
CVE-2025-67635

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connectio

7.5
CVE-2025-63895

An issue in the Bluetooth firmware of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to cause a

7.2
CVE-2024-13009

In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when in

6.5
CVE-2025-1103

A vulnerability, which was classified as problematic, was found in D-Link DIR-823X 240126/240802. This affects the funct

6.5
CVE-2025-1877

A vulnerability, which was classified as critical, was found in D-Link DAP-1562 1.10. This affects the function pure_aut

6.5
CVE-2025-2956

A vulnerability was found in TRENDnet TI-G102i 1.0.7.S0_ /1.0.8.S0_ and classified as problematic. This issue affects th

6.5
CVE-2025-2957

A vulnerability was found in TRENDnet TEW-411BRP+ 2.07. It has been classified as problematic. Affected is the function

6.5
CVE-2025-2958

A vulnerability was found in TRENDnet TEW-818DRU 1.0.14.6. It has been declared as problematic. Affected by this vulnera

6.5
CVE-2025-2959

A vulnerability was found in TRENDnet TEW-410APB 1.3.06b. It has been rated as problematic. Affected by this issue is th

6.5
CVE-2025-2960

A vulnerability classified as problematic has been found in TRENDnet TEW-637AP and TEW-638APB 1.2.7/1.3.0.106. This affe

6.5
CVE-2025-3167

A vulnerability, which was classified as problematic, has been found in Tenda AC23 16.03.07.52. This issue affects some

6.5
CVE-2025-4867

A vulnerability was found in Tenda A15 15.13.07.13. It has been declared as problematic. Affected by this vulnerability

Frequently Asked Questions

What is CWE-404?

CWE-404 (CWE-404) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-404?

There are 847 CVE records associated with CWE-404 in our database. Of these, 2 are critical severity, 161 are high severity, and 412 are medium severity.

How can I protect against CWE-404 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-404 using AI-powered security agents.

Detect CWE-404 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-404 vulnerabilities across your infrastructure.

Get Started