CWE-404: CWE-404

127
Total CVEs
0
Critical
36
High
5.7
Avg CVSS

Yearly Trend

2026
36
2025
59
2024
18
2023
9
2022
2

Top Affected Vendors

1 Open5gs 18
2 Free5gc 9
3 Iobit 6
4 Tenda 5
5 Gpac 4
6 Linux 4
7 Apple 4
8 F5 3
9 Asrmicro 3
10 Birkir 3

All CWE-404 CVEs (127)

CVE-2025-38385
7.8

This CVE describes a kernel warning triggered during USB device disconnection in the Linux kernel's lan78xx network driver. The vulnerability occurs w...

Jul 25, 2025
CVE-2022-23033
7.8

This Xen hypervisor vulnerability on ARM systems allows guest virtual machines to retain access to memory pages after returning them to Xen, potential...

Jan 25, 2022
CVE-2021-0984
7.8

This vulnerability in Android 12 allows local privilege escalation without user interaction. An incorrectly unbound service in ManagedServices.java en...

Dec 15, 2021
CVE-2021-1098
7.8

NVIDIA vGPU software has a resource management vulnerability where the Virtual GPU Manager fails to properly release resources during guest driver unl...

Jul 21, 2021
CVE-2025-63895
7.5

A vulnerability in the Bluetooth firmware of JXL 9 Inch Car Android Double Din Player allows attackers to cause a Denial of Service (DoS) by sending a...

Dec 10, 2025
CVE-2025-67635
7.5

Jenkins versions 2.540 and earlier (including LTS 2.528.2 and earlier) have a vulnerability where HTTP-based CLI connections aren't properly closed wh...

Dec 10, 2025
CVE-2025-48989
7.5

This CVE describes an Improper Resource Shutdown or Release vulnerability in Apache Tomcat that enables a 'made you reset' attack. Attackers can explo...

Aug 13, 2025
CVE-2025-4749
7.5

A critical vulnerability in D-Link DI-7003GV2 routers allows remote attackers to trigger a denial of service via the factory reset handler. This affec...

May 16, 2025
CVE-2025-31237
7.5

A vulnerability in macOS AFP (Apple Filing Protocol) allows attackers to cause system termination (kernel panic/crash) by mounting a maliciously craft...

May 12, 2025
CVE-2025-41399
7.5

This vulnerability allows attackers to cause memory exhaustion on F5 BIG-IP systems by sending specially crafted SCTP requests to virtual servers with...

May 7, 2025
CVE-2024-47213
7.5

A denial-of-service vulnerability in Snowplow Enrich allows attackers to crash the pipeline by sending maliciously crafted events. This affects all us...

Apr 3, 2025
CVE-2025-29357
7.5

This buffer overflow vulnerability in Tenda RX3 routers allows attackers to cause denial of service by sending specially crafted packets to the PPTP s...

Mar 13, 2025
CVE-2025-24811
7.5

This vulnerability affects multiple Siemens SIMATIC S7-1200 and SIPLUS S7-1200 CPU models, allowing an unauthenticated attacker to send specially craf...

Feb 11, 2025
CVE-2025-22846
7.5

This vulnerability in F5 BIG-IP systems causes the Traffic Management Microkernel (TMM) to crash when specific SIP Session and Router ALG profiles are...

Feb 5, 2025
CVE-2025-0492
7.5

A critical null pointer dereference vulnerability in D-Link DIR-823X routers allows remote attackers to potentially crash the device or execute arbitr...

Jan 15, 2025
CVE-2024-57654
7.5

A vulnerability in the qst_vec_get_int64 component of OpenLink Virtuoso Open-Source allows attackers to cause Denial of Service (DoS) through speciall...

Jan 14, 2025
CVE-2024-57659
7.5

This vulnerability in OpenLink Virtuoso OpenSource allows attackers to cause denial of service by sending specially crafted SQL statements to the sqlg...

Jan 14, 2025
CVE-2024-57661
7.5

A vulnerability in the sqlo_df component of OpenLink Virtuoso OpenSource allows attackers to cause Denial of Service (DoS) through specially crafted S...

Jan 14, 2025
CVE-2024-57618
7.5

A vulnerability in MonetDB Server's bind_col_exp component allows attackers to execute crafted SQL statements that cause a Denial of Service (DoS). Th...

Jan 14, 2025
CVE-2024-57623
7.5

This vulnerability in MonetDB Server's HEAP_malloc component allows attackers to cause Denial of Service (DoS) by sending specially crafted SQL statem...

Jan 14, 2025
CVE-2024-55553
7.5

This vulnerability in FRRouting (FRR) allows attackers to trigger continuous route re-validation by sending RTR updates exceeding the socket buffer si...

Jan 6, 2025
CVE-2024-51179
7.5

A denial-of-service vulnerability in Open 5GS allows remote attackers to disrupt PDU session establishment by targeting NFV components like UPF and SM...

Nov 12, 2024
CVE-2024-27527
7.5

CVE-2024-27527 is a denial-of-service vulnerability in wasm3 WebAssembly interpreter where specially crafted WASM modules can cause infinite loops or ...

Nov 8, 2024
CVE-2024-9399
7.5

A denial-of-service vulnerability in Firefox, Firefox ESR, and Thunderbird allows a malicious website to crash the browser process by initiating a spe...

Oct 1, 2024
CVE-2024-4791
7.5

A critical vulnerability in Contemporary Control System BASrouter BACnet BASRT-B 2.7.2 allows remote attackers to cause denial of service by manipulat...

May 14, 2024
CVE-2024-33844
7.5

This vulnerability in Parrot ANAFI USA drone firmware allows attackers to disrupt the connection between the controller and drone by sending specially...

May 3, 2024
CVE-2023-7209
7.5

A critical vulnerability in Uniway Router up to version 2.0 allows remote attackers to cause denial of service by exploiting the device reset handler ...

Jan 7, 2024
CVE-2023-4882
7.5

This CVE describes a denial-of-service vulnerability in Open5GS where an attacker can register a new Virtual Network Function (VNF) value that trigger...

Oct 3, 2023
CVE-2022-48489
7.5

This vulnerability involves configuration defects in Huawei's secure OS module that can be exploited to cause denial of service. It affects Huawei dev...

Jun 19, 2023
CVE-2022-48500
7.5

This vulnerability involves configuration defects in Huawei's secure OS module that can be exploited to cause denial of service. It affects Huawei sma...

Jun 19, 2023
CVE-2021-27458
7.5

This vulnerability in JTEKT TOYOPUC industrial control systems allows attackers to disrupt Ethernet communications by leaving connections in an open s...

Apr 19, 2021
CVE-2025-69821
7.4

A vulnerability in Beat XP VEGA Smartwatch firmware allows attackers to cause denial of service via Bluetooth Low Energy (BLE) connections. This affec...

Jan 22, 2026
CVE-2023-34059
7.4

CVE-2023-34059 is a file descriptor hijack vulnerability in open-vm-tools' vmware-user-suid-wrapper that allows non-root users to hijack the /dev/uinp...

Oct 27, 2023
CVE-2021-41441
7.4

This vulnerability allows remote attackers to cause a denial-of-service (DoS) by tricking an authenticated user into visiting a specially crafted URL,...

Feb 9, 2022
CVE-2024-13009
7.2

This vulnerability in Eclipse Jetty allows incorrect buffer release during gzip decompression errors, potentially leading to data corruption or uninte...

May 8, 2025
CVE-2024-23248
7.1

This vulnerability in macOS allows processing a malicious file to cause a denial-of-service or potentially leak memory contents. It affects macOS syst...

Mar 8, 2024
CVE-2025-36006
6.5

This vulnerability in IBM Db2 allows authenticated users to cause denial of service by exploiting improper resource release after use. It affects Db2 ...

Nov 7, 2025
CVE-2025-47148
6.5

This vulnerability affects BIG-IP systems configured as both SAML service provider and identity provider with single logout enabled. Undisclosed reque...

Oct 15, 2025
CVE-2025-11550
6.5

A null pointer dereference vulnerability in Tenda W12 routers allows remote attackers to cause denial of service by sending specially crafted HTTP req...

Oct 9, 2025
CVE-2025-4998
6.5

This vulnerability in H3C Magic R200G routers allows remote attackers to cause denial of service by manipulating parameters in specific HTTP POST requ...

May 20, 2025
CVE-2025-2959
6.5

This vulnerability in TRENDnet TEW-410APB wireless access points allows local network attackers to cause a denial of service via null pointer derefere...

Mar 30, 2025
CVE-2025-2957
6.5

A null pointer dereference vulnerability in the TRENDnet TEW-411BRP+ router's HTTP request handler allows local network attackers to crash the httpd s...

Mar 30, 2025
CVE-2024-11650
6.5

A critical null pointer dereference vulnerability in Tenda i9 routers allows remote attackers to crash the device or potentially execute arbitrary cod...

Nov 25, 2024
CVE-2024-5095
6.5

A denial-of-service vulnerability exists in the MQTT Packet Handler of Victor Zsviot Camera version 8.26.31. Attackers can remotely exploit this vulne...

May 19, 2024
CVE-2025-58473
5.9

An unauthenticated attacker can cause denial-of-service on Click Plus C2-03CPU-2 devices by exhausting all available programming software sessions thr...

Sep 23, 2025
CVE-2025-52982
5.9

An unauthenticated network attacker can cause a denial-of-service by sending a specific sequence of SIP calls to Juniper MX Series devices with MS-MPC...

Jul 11, 2025
CVE-2025-10475
5.5

A local denial-of-service vulnerability exists in SpyShelter's kernel driver (SpyShelter.sys) through improper IOCTL handling. Attackers with local ac...

Sep 15, 2025
CVE-2025-4003
5.5

A null pointer dereference vulnerability in RefindPlus 0.14.2.AB's InternalApfsTranslateBlock function allows local attackers to cause denial of servi...

Apr 28, 2025
CVE-2025-4002
5.5

This vulnerability in RefindPlus 0.14.2.AB allows local attackers to trigger a null pointer dereference in the GetDebugLogFile function, potentially c...

Apr 28, 2025
CVE-2024-57493
5.5

A vulnerability in redoxOS relibc allows a local attacker to cause denial of service via the setsockopt function. This affects systems running redoxOS...

Apr 18, 2025

About CWE-404 (CWE-404)

Our database tracks 127 CVEs classified as CWE-404, with 0 rated critical and 36 rated high severity. The average CVSS score for CWE-404 vulnerabilities is 5.7.

External reference: View CWE-404 on MITRE CWE →

Monitor CWE-404 Vulnerabilities

Get alerted when new CWE-404 CVEs affect your infrastructure.

Start Monitoring Free