CWE-226 · 36 kayıt
Sensitive Information in Resource Not Removed Before Reuse
Bu sınıftaki CVE’ler
36 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2026-74791İstismar yok | Scriban before 7.0.0 Authorization Bypass via Stale Include Cachescriban · scriban · CWE-226 | Kritik9,2 | — | %0,4 | 16 Ağu 2026 |
34İzleyin | CVE-2022-39393İstismar yok | Wasmtime vulnerable to data leakage between instances in the pooling allocatorbytecodealliance · wasmtime · CWE-226 | Yüksek8,6 | — | %0,7 | 10 Kas 2022 |
34İzleyin | CVE-2019-25560İstismar yok | Lyric Video Creator 2.1 Denial of Service via MP3 Filelyricvideocreator · lyric video creator · CWE-226 | Yüksek8,7 | — | %0,5 | 21 Mar 2026 |
33İzleyin | CVE-2024-21850İstismar yok | Sensitive information in resource not removed before reuse in some Intel(R) TDX Seamldr module software before version 1.5.02.00 may allow aCWE-226 | Yüksek8,3 | — | %0,2 | 13 Kas 2024 |
32İzleyin | CVE-2026-13585Kavram kanıtı | Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Contasus · system control interface v3 · CWE-226 | Yüksek8,2 | — | %0,2 | 14 Tem 2026 |
31İzleyin | CVE-2018-7166İstismar yok | In all versions of Node.js 10 prior to 10.9.0, an argument processing flaw can cause `Buffer.alloc()` to return uninitialized memory.nodejs · node.js · CWE-226 | Yüksek7,5 | — | %2,8 | 21 Ağu 2018 |
31İzleyin | CVE-2025-0647İstismar yok | In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to tharm · c1-ultra firmware · CWE-226 | Yüksek7,9 | — | %0,2 | 14 Oca 2026 |
30İzleyin | CVE-2024-38275İstismar yok | moodle: HTTP authorization header is preserved between "emulated redirects"moodle · moodle · CWE-226 | Yüksek7,5 | — | %0,4 | 18 Haz 2024 |
30İzleyin | CVE-2025-13108İstismar yok | Fixes to common vulnerabilities found in IBM Db2 Merge Backup for Linux, UNIX and Windowsibm · db2 merge backup · CWE-226 | Yüksek7,5 | — | %0,2 | 17 Şub 2026 |
30İzleyin | GHSA-r45x-ghr2-qjxcİstismar yok | Duplicate Advisory: `#[zeroize(drop)]` doesn't implement `Drop` for `enum`scrates.io · zeroize_derive · CWE-226 | Yüksek7,5 | — | — | 17 Haz 2022 |
29İzleyin | CVE-2026-5795İstismar yok | In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable.eclipse · jetty · CWE-226 | Yüksek7,4 | — | %0,6 | 8 Nis 2026 |
29İzleyin | GHSA-gc59-r5jq-98qwİstismar yok | Duplicate Advisory: Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variablesMaven · org.eclipse.jetty.ee10:jetty-ee10 · CWE-226 | Yüksek7,4 | — | — | 8 Nis 2026 |
28İzleyin | CVE-2026-32960İstismar yok | SD-330AC and AMC Manager provided by silex technology, Inc.silextechnology · sd-330ac firmware · CWE-226 | Yüksek7,1 | — | %0,5 | 20 Nis 2026 |
27İzleyin | CVE-2019-25657İstismar yok | AnyBurn 4.3 x86 Denial of Service via Image Conversionanyburn · anyburn · CWE-226 | Orta6,8 | — | %0,2 | 5 Nis 2026 |
27İzleyin | CVE-2019-25563İstismar yok | PCHelpWareV2 1.0.0.5 Denial of Service via SC Creationuvnc · pchelpwarev2 · CWE-226 | Orta6,9 | — | %0,2 | 21 Mar 2026 |
27İzleyin | CVE-2019-25571İstismar yok | MediaMonkey 4.1.23 Denial of Service via Malformed URLventismedia · mediamonkey · CWE-226 | Orta6,9 | — | %0,2 | 21 Mar 2026 |
27İzleyin | CVE-2019-25645İstismar yok | WinAVI iPod 3GP MP4 PSP Converter 4.4.2 Denial of Servicewinavi · winavi ipod/3gp/mp4/psp converter · CWE-226 | Orta6,9 | — | %0,2 | 24 Mar 2026 |
27İzleyin | CVE-2019-25553İstismar yok | CEWE PHOTO IMPORTER 6.4.3 Denial of Service via Malformed Imagecewe · photo importer · CWE-226 | Orta6,9 | — | %0,2 | 21 Mar 2026 |
27İzleyin | CVE-2019-25617İstismar yok | Ease Audio Converter 5.30 Denial of Service via Audio Cutteraudiotool · ease audio converter · CWE-226 | Orta6,9 | — | %0,1 | 22 Mar 2026 |
26İzleyin | CVE-2024-32036İstismar yok | SixLabors.ImageSharp vulnerable to data leakagesixlabors · imagesharp · CWE-226 | Orta6,5 | — | %0,6 | 15 Nis 2024 |
26İzleyin | CVE-2025-2522İstismar yok | Lack of buffer clearing before reuse may result in incorrect system behavior.honeywell · c300 pcnt02 · CWE-226 | Orta6,5 | — | %0,2 | 10 Tem 2025 |
26İzleyin | CVE-2023-41138İstismar yok | The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user pappsanywhere · appsanywhere client · CWE-226 | Orta6,7 | — | %0,2 | 9 Kas 2023 |
25İzleyin | CVE-2025-11602İstismar yok | Untargeted information leak in Bolt protocol handshakeneo4j · enterprise edition · CWE-226 | Orta6,3 | — | %0,3 | 31 Eki 2025 |
25İzleyin | CVE-2026-74250İstismar yok | In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing topenstack · ironic · CWE-226 | Orta6,3 | — | %0,3 | 14 Ağu 2026 |
22İzleyin | CVE-2023-3006İstismar yok | A known cache speculation vulnerability, known as Branch History Injection (BHI) or Spectre-BHB, becomes actual again for the new hw AmpereOlinux · linux kernel · CWE-226 | Orta5,5 | — | %0,3 | 31 May 2023 |
- CVE-2026-7479136İzleyin
Scriban before 7.0.0 Authorization Bypass via Stale Include Cache
KritikCVSS 9,2İstismar yokEPSS %0scriban · scriban16 Ağu 2026
- CVE-2022-3939334İzleyin
Wasmtime vulnerable to data leakage between instances in the pooling allocator
YüksekCVSS 8,6İstismar yokEPSS %1bytecodealliance · wasmtime10 Kas 2022
- CVE-2019-2556034İzleyin
Lyric Video Creator 2.1 Denial of Service via MP3 File
YüksekCVSS 8,7İstismar yokEPSS %0lyricvideocreator · lyric video creator21 Mar 2026
- CVE-2024-2185033İzleyin
Sensitive information in resource not removed before reuse in some Intel(R) TDX Seamldr module software before version 1.5.02.00 may allow a
YüksekCVSS 8,3İstismar yokEPSS %013 Kas 2024
- CVE-2026-1358532İzleyin
Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Cont
YüksekCVSS 8,2Kavram kanıtıEPSS %0asus · system control interface v314 Tem 2026
- CVE-2018-716631İzleyin
In all versions of Node.js 10 prior to 10.9.0, an argument processing flaw can cause `Buffer.alloc()` to return uninitialized memory.
YüksekCVSS 7,5İstismar yokEPSS %3nodejs · node.js21 Ağu 2018
- CVE-2025-064731İzleyin
In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to th
YüksekCVSS 7,9İstismar yokEPSS %0arm · c1-ultra firmware14 Oca 2026
- CVE-2024-3827530İzleyin
moodle: HTTP authorization header is preserved between "emulated redirects"
YüksekCVSS 7,5İstismar yokEPSS %0moodle · moodle18 Haz 2024
- CVE-2025-1310830İzleyin
Fixes to common vulnerabilities found in IBM Db2 Merge Backup for Linux, UNIX and Windows
YüksekCVSS 7,5İstismar yokEPSS %0ibm · db2 merge backup17 Şub 2026
- GHSA-r45x-ghr2-qjxc30İzleyin
Duplicate Advisory: `#[zeroize(drop)]` doesn't implement `Drop` for `enum`s
YüksekCVSS 7,5İstismar yokcrates.io · zeroize_derive17 Haz 2022
- CVE-2026-579529İzleyin
In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable.
YüksekCVSS 7,4İstismar yokEPSS %1eclipse · jetty8 Nis 2026
- GHSA-gc59-r5jq-98qw29İzleyin
Duplicate Advisory: Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variables
YüksekCVSS 7,4İstismar yokMaven · org.eclipse.jetty.ee10:jetty-ee108 Nis 2026
- CVE-2026-3296028İzleyin
SD-330AC and AMC Manager provided by silex technology, Inc.
YüksekCVSS 7,1İstismar yokEPSS %0silextechnology · sd-330ac firmware20 Nis 2026
- CVE-2019-2565727İzleyin
AnyBurn 4.3 x86 Denial of Service via Image Conversion
OrtaCVSS 6,8İstismar yokEPSS %0anyburn · anyburn5 Nis 2026
- CVE-2019-2556327İzleyin
PCHelpWareV2 1.0.0.5 Denial of Service via SC Creation
OrtaCVSS 6,9İstismar yokEPSS %0uvnc · pchelpwarev221 Mar 2026
- CVE-2019-2557127İzleyin
MediaMonkey 4.1.23 Denial of Service via Malformed URL
OrtaCVSS 6,9İstismar yokEPSS %0ventismedia · mediamonkey21 Mar 2026
- CVE-2019-2564527İzleyin
WinAVI iPod 3GP MP4 PSP Converter 4.4.2 Denial of Service
OrtaCVSS 6,9İstismar yokEPSS %0winavi · winavi ipod/3gp/mp4/psp converter24 Mar 2026
- CVE-2019-2555327İzleyin
CEWE PHOTO IMPORTER 6.4.3 Denial of Service via Malformed Image
OrtaCVSS 6,9İstismar yokEPSS %0cewe · photo importer21 Mar 2026
- CVE-2019-2561727İzleyin
Ease Audio Converter 5.30 Denial of Service via Audio Cutter
OrtaCVSS 6,9İstismar yokEPSS %0audiotool · ease audio converter22 Mar 2026
- CVE-2024-3203626İzleyin
SixLabors.ImageSharp vulnerable to data leakage
OrtaCVSS 6,5İstismar yokEPSS %1sixlabors · imagesharp15 Nis 2024
- CVE-2025-252226İzleyin
Lack of buffer clearing before reuse may result in incorrect system behavior.
OrtaCVSS 6,5İstismar yokEPSS %0honeywell · c300 pcnt0210 Tem 2025
- CVE-2023-4113826İzleyin
The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user p
OrtaCVSS 6,7İstismar yokEPSS %0appsanywhere · appsanywhere client9 Kas 2023
- CVE-2025-1160225İzleyin
Untargeted information leak in Bolt protocol handshake
OrtaCVSS 6,3İstismar yokEPSS %0neo4j · enterprise edition31 Eki 2025
- CVE-2026-7425025İzleyin
In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing t
OrtaCVSS 6,3İstismar yokEPSS %0openstack · ironic14 Ağu 2026
- CVE-2023-300622İzleyin
A known cache speculation vulnerability, known as Branch History Injection (BHI) or Spectre-BHB, becomes actual again for the new hw AmpereO
OrtaCVSS 5,5İstismar yokEPSS %0linux · linux kernel31 May 2023