CWE-405: CWE-405

22
Total CVEs
0
Critical
16
High
7.0
Avg CVSS

Yearly Trend

2026
4
2025
14
2024
3
2023
1

Top Affected Vendors

1 Sap 2
2 Svelte 2
3 Openjsf 1
4 Hcltech 1
5 Zabbix 1
6 Atlassian 1
7 Lenovo 1
8 Oisf 1
9 Fastd Project 1

All CWE-405 CVEs (22)

CVE-2025-42874
7.9

CVE-2025-42874 is a remote code execution vulnerability in SAP NetWeaver's Xcelsius remote service that allows attackers with network access and high ...

Dec 9, 2025
CVE-2026-0485
7.5

CVE-2026-0485 is a denial-of-service vulnerability in SAP BusinessObjects BI Platform that allows unauthenticated attackers to crash and restart the C...

Feb 10, 2026
CVE-2026-22774
7.5

CVE-2026-22774 is a denial-of-service vulnerability in the Svelte devalue JavaScript library where specially crafted inputs cause excessive CPU and me...

Jan 15, 2026
CVE-2026-22775
7.5

CVE-2026-22775 is a denial-of-service vulnerability in the Svelte devalue JavaScript library where specially crafted inputs cause excessive CPU and me...

Jan 15, 2026
CVE-2025-66564
7.5

This CVE describes a resource exhaustion vulnerability in Sigstore Timestamp Authority where malicious requests with excessively long OIDs or malforme...

Dec 4, 2025
CVE-2025-66506
7.5

This vulnerability in Fulcio allows attackers to cause resource exhaustion through a denial-of-service attack by sending malicious OIDC identity token...

Dec 4, 2025
CVE-2025-8677
7.5

A denial-of-service vulnerability in BIND DNS servers where querying a specially crafted zone containing malformed DNSKEY records causes CPU exhaustio...

Oct 22, 2025
CVE-2025-22166
7.5

This high-severity Denial of Service vulnerability in Confluence Data Center allows attackers to make resources unavailable to legitimate users by dis...

Oct 21, 2025
CVE-2025-30204
7.5

This vulnerability in golang-jwt allows attackers to cause denial of service through resource exhaustion by sending malicious JWT tokens with many per...

Mar 21, 2025
CVE-2024-11187
7.5

This CVE describes a resource exhaustion vulnerability in BIND DNS servers where specially crafted zones can generate responses with excessive records...

Jan 29, 2025
CVE-2025-24356
7.5

CVE-2025-24356 is a UDP amplification vulnerability in fastd VPN daemon that allows attackers to spoof source addresses and trigger handshake packets,...

Jan 27, 2025
CVE-2024-55628
7.5

This vulnerability in Suricata allows attackers to send specially crafted DNS messages with compressed resource names that can cause excessive resourc...

Jan 6, 2025
CVE-2024-45590
7.5

CVE-2024-45590 is a denial-of-service vulnerability in body-parser middleware for Node.js applications. Attackers can send specially crafted URL-encod...

Sep 10, 2024
CVE-2024-34703
7.5

This vulnerability in the Botan cryptography library allows attackers to cause denial of service by presenting specially crafted X.509 certificates wi...

Jun 30, 2024
CVE-2023-2992
7.5

An unauthenticated denial-of-service vulnerability exists in Lenovo's SMM v1, SMM v2, and FPC management web servers that allows remote attackers to c...

Jun 26, 2023
CVE-2025-42876
7.1

This CVE describes a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud Financials General Ledger. Authenticated attackers with l...

Dec 9, 2025
CVE-2026-24324
6.5

This vulnerability allows authenticated users with standard privileges in SAP BusinessObjects Business Intelligence Platform to execute a specific que...

Feb 10, 2026
CVE-2025-49643
6.5

An authenticated Zabbix user (including Guest accounts) can send specially crafted parameters to /imgstore.php, causing excessive CPU consumption on t...

Dec 1, 2025
CVE-2025-42873
5.9

This CVE describes a denial-of-service vulnerability in SAPUI5/OpenUI5 where malformed markdown input triggers an infinite loop in the outdated markdo...

Dec 9, 2025
CVE-2025-68480
5.3

Marshmallow library versions 3.0.0rc1-3.26.1 and 4.0.0-4.1.1 contain a denial of service vulnerability in Schema.load() with many=True parameter. Atta...

Dec 22, 2025
CVE-2024-34702
5.3

This vulnerability in the Botan cryptography library allows denial-of-service attacks via quadratic complexity in X.509 certificate name constraint va...

Jul 8, 2024
CVE-2025-31987
4.8

CVE-2025-31987 is a resource exhaustion vulnerability in HCL Connections Docs where improper validation of uploaded documents can lead to denial of se...

Aug 14, 2025

About CWE-405 (CWE-405)

Our database tracks 22 CVEs classified as CWE-405, with 0 rated critical and 16 rated high severity. The average CVSS score for CWE-405 vulnerabilities is 7.0.

External reference: View CWE-405 on MITRE CWE →

Monitor CWE-405 Vulnerabilities

Get alerted when new CWE-405 CVEs affect your infrastructure.

Start Monitoring Free