Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the
SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause t
A series of specifically crafted, unauthenticated messages can exhaust available memory and crash a MongoDB server.
Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, unauthenticated denial of service (DoS) vul
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-be
Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far
SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to
Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of special break characters.
Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in con
Bitcoin Core through 29.0 allows a denial of service via a crafted transaction.
OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook handling t
OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-32011 where the Feishu webhook handler accepts request
UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to view any user profile o
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically cra
An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically craft
Frequently Asked Questions
What is CWE-405?
CWE-405 (CWE-405) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-405?
There are 20 CVE records associated with CWE-405 in our database. Of these, 0 are critical severity, 8 are high severity, and 6 are medium severity.
How can I protect against CWE-405 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-405 using AI-powered security agents.
Detect CWE-405 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-405 vulnerabilities across your infrastructure.
Get Started