CWE-405: CWE-405
Yearly Trend
Top Affected Vendors
All CWE-405 CVEs (22)
CVE-2025-42874 is a remote code execution vulnerability in SAP NetWeaver's Xcelsius remote service that allows attackers with network access and high ...
Dec 9, 2025CVE-2026-0485 is a denial-of-service vulnerability in SAP BusinessObjects BI Platform that allows unauthenticated attackers to crash and restart the C...
Feb 10, 2026CVE-2026-22774 is a denial-of-service vulnerability in the Svelte devalue JavaScript library where specially crafted inputs cause excessive CPU and me...
Jan 15, 2026CVE-2026-22775 is a denial-of-service vulnerability in the Svelte devalue JavaScript library where specially crafted inputs cause excessive CPU and me...
Jan 15, 2026This CVE describes a resource exhaustion vulnerability in Sigstore Timestamp Authority where malicious requests with excessively long OIDs or malforme...
Dec 4, 2025This vulnerability in Fulcio allows attackers to cause resource exhaustion through a denial-of-service attack by sending malicious OIDC identity token...
Dec 4, 2025A denial-of-service vulnerability in BIND DNS servers where querying a specially crafted zone containing malformed DNSKEY records causes CPU exhaustio...
Oct 22, 2025This high-severity Denial of Service vulnerability in Confluence Data Center allows attackers to make resources unavailable to legitimate users by dis...
Oct 21, 2025This vulnerability in golang-jwt allows attackers to cause denial of service through resource exhaustion by sending malicious JWT tokens with many per...
Mar 21, 2025This CVE describes a resource exhaustion vulnerability in BIND DNS servers where specially crafted zones can generate responses with excessive records...
Jan 29, 2025CVE-2025-24356 is a UDP amplification vulnerability in fastd VPN daemon that allows attackers to spoof source addresses and trigger handshake packets,...
Jan 27, 2025This vulnerability in Suricata allows attackers to send specially crafted DNS messages with compressed resource names that can cause excessive resourc...
Jan 6, 2025CVE-2024-45590 is a denial-of-service vulnerability in body-parser middleware for Node.js applications. Attackers can send specially crafted URL-encod...
Sep 10, 2024This vulnerability in the Botan cryptography library allows attackers to cause denial of service by presenting specially crafted X.509 certificates wi...
Jun 30, 2024An unauthenticated denial-of-service vulnerability exists in Lenovo's SMM v1, SMM v2, and FPC management web servers that allows remote attackers to c...
Jun 26, 2023This CVE describes a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud Financials General Ledger. Authenticated attackers with l...
Dec 9, 2025This vulnerability allows authenticated users with standard privileges in SAP BusinessObjects Business Intelligence Platform to execute a specific que...
Feb 10, 2026An authenticated Zabbix user (including Guest accounts) can send specially crafted parameters to /imgstore.php, causing excessive CPU consumption on t...
Dec 1, 2025This CVE describes a denial-of-service vulnerability in SAPUI5/OpenUI5 where malformed markdown input triggers an infinite loop in the outdated markdo...
Dec 9, 2025Marshmallow library versions 3.0.0rc1-3.26.1 and 4.0.0-4.1.1 contain a denial of service vulnerability in Schema.load() with many=True parameter. Atta...
Dec 22, 2025This vulnerability in the Botan cryptography library allows denial-of-service attacks via quadratic complexity in X.509 certificate name constraint va...
Jul 8, 2024CVE-2025-31987 is a resource exhaustion vulnerability in HCL Connections Docs where improper validation of uploaded documents can lead to denial of se...
Aug 14, 2025About CWE-405 (CWE-405)
Our database tracks 22 CVEs classified as CWE-405, with 0 rated critical and 16 rated high severity. The average CVSS score for CWE-405 vulnerabilities is 7.0.
External reference: View CWE-405 on MITRE CWE →
Monitor CWE-405 Vulnerabilities
Get alerted when new CWE-405 CVEs affect your infrastructure.
Start Monitoring Free