Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-400
Weakness type CWE-400 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 941 | 883 | 8 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▂▁▁▃▄▃▂▄▃▄▂▂█▁▂▁
2024-02 3 · 2024-03 2 · 2024-04 1 · 2024-05 3 · 2024-06 2 · 2024-07 3 · 2024-08 1 · 2024-09 1 · 2024-10 8 · 2024-11 0 · 2024-12 1 · 2025-01 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2021-44228 | 10.0 | 100.0 | KEV | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other J… |
| CVE-2023-44487 | 7.5 | 100.0 | KEV | IETF HTTP/2 |
| CVE-2023-38180 | 7.5 | 96.5 | KEV | .NET and Visual Studio Denial of Service Vulnerability |
| CVE-2004-1464 | 5.9 | 91.7 | KEV | Cisco IOS |
| CVE-2020-3566 | 8.6 | 89.4 | KEV | Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability |
| CVE-2020-3569 | 8.6 | 88.2 | KEV | Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerabilities |
| CVE-2026-28318 | 7.5 | 79.4 | KEV | SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability |
| CVE-2026-45498 | 7.5 | 68.7 | KEV | Microsoft Defender Denial of Service Vulnerability |
| CVE-2024-1635 | 7.5 | 91.3 | — | Undertow: out-of-memory error after several closed connections with wildfly-http-client… |
| CVE-2023-5685 | 7.5 | 88.7 | — | Xnio: stackoverflowexception when the chain of notifier states becomes problematically big |
| CVE-2025-26673 | 7.5 | 85.0 | — | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
| CVE-2023-38178 | 7.5 | 84.8 | — | .NET Core and Visual Studio Denial of Service Vulnerability |
| CVE-2024-21342 | 7.5 | 84.4 | — | Windows DNS Client Denial of Service Vulnerability |
| CVE-2025-27469 | 7.5 | 84.0 | — | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
| CVE-2026-33116 | 7.5 | 83.8 | — | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability |
| CVE-2026-45591 | 7.5 | 83.8 | — | ASP.NET Core Denial of Service Vulnerability |
| CVE-2024-21386 | 7.5 | 83.5 | — | .NET Denial of Service Vulnerability |
| CVE-2024-43541 | 7.5 | 82.9 | — | Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability |
| CVE-2024-43506 | 7.5 | 82.9 | — | BranchCache Denial of Service Vulnerability |
| CVE-2024-43575 | 7.5 | 82.8 | — | Windows Hyper-V Denial of Service Vulnerability |