CWE-459 · 205 записей
Incomplete Cleanup
CVE этого класса
205 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
55В плане | CVE-2017-17090Proof of concept | An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asdigium · certified asterisk · CWE-459 | Высокая7,5 | — | 82,2 % | 1 дек. 2017 г. |
48В плане | CVE-2025-31650Proof of concept | Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frameapache · tomcat · CWE-459 | Высокая7,5 | — | 61,0 % | 28 апр. 2025 г. |
40В плане | CVE-2022-1552Эксплойта нет | A flaw was found in PostgreSQL.postgresql · postgresql · CWE-459 | Высокая8,8 | — | 16,0 % | 31 авг. 2022 г. |
40В плане | CVE-2020-13451Эксплойта нет | An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice cothecodingmachine · gotenberg · CWE-459 | Критическая9,8 | — | 3,0 % | 7 янв. 2021 г. |
40В плане | CVE-2005-1744Эксплойта нет | BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows tbea · weblogic server · CWE-459 | Критическая9,8 | — | 2,1 % | 24 мая 2005 г. |
39Наблюдать | CVE-2021-45330Эксплойта нет | An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and tgitea · gitea · CWE-459 | Критическая9,8 | — | 1,4 % | 9 февр. 2022 г. |
39Наблюдать | CVE-2022-45347Эксплойта нет | Apache ShardingSphere-Proxy: MySQL authentication bypassapache · shardingsphere · CWE-459 | Критическая9,8 | — | 1,4 % | 22 дек. 2022 г. |
39Наблюдать | CVE-2021-32928Эксплойта нет | The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Manager” that allows ithalesgroup · sentinel ldk run-time environment · CWE-459 | Критическая9,8 | — | 1,3 % | 16 июн. 2021 г. |
39Наблюдать | CVE-2021-45706Эксплойта нет | An issue was discovered in the zeroize_derive crate before 1.1.1 for Rust.zeroize derive project · zeroize derive · CWE-459 | Критическая9,8 | — | 1,2 % | 26 дек. 2021 г. |
39Наблюдать | CVE-2021-36205Эксплойта нет | Metasys session tokenjohnsoncontrols · metasys application and data server · CWE-459 | Критическая9,8 | — | 1,0 % | 15 апр. 2022 г. |
39Наблюдать | CVE-2026-28268Эксплойта нет | Vikunja Vulnerable to Account Takeover via Password Reset Token Reusevikunja · vikunja · CWE-459 | Критическая9,8 | — | 0,9 % | 27 февр. 2026 г. |
38Наблюдать | CVE-2018-18924Proof of concept | The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" beprojeqtor · projeqtor · CWE-459 | Высокая8,8 | — | 9,5 % | 4 нояб. 2018 г. |
38Наблюдать | CVE-2026-34263Эксплойта нет | Missing authentication check in SAP Commerce cloud configurationsap_se · sap commerce cloud configuration · CWE-459 | Критическая9,6 | — | 0,6 % | 11 мая 2026 г. |
36Наблюдать | CVE-2019-25016Эксплойта нет | In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowedopendoas project · opendoas · CWE-459 | Высокая8,8 | — | 2,7 % | 28 янв. 2021 г. |
36Наблюдать | CVE-2019-18191Эксплойта нет | A privilege escalation vulnerability in the Trend Micro Deep Security as a Service Quick Setup cloud formation template could allow an authetrendmicro · deep security as a service · CWE-459 | Высокая8,8 | — | 2,2 % | 16 дек. 2019 г. |
36Наблюдать | CVE-2023-36468Эксплойта нет | Upgrading doesn't prevent exploiting vulnerable XWiki documentsxwiki · xwiki · CWE-459 | Высокая8,8 | — | 1,9 % | 29 июн. 2023 г. |
36Наблюдать | CVE-2024-28265Эксплойта нет | IBOS v4.5.5 has an arbitrary file deletion vulnerability via \system\modules\dashboard\controllers\LoginController.php.ibos · ibos · CWE-459 | Критическая9,1 | — | 0,5 % | 1 нояб. 2024 г. |
36Наблюдать | CVE-2026-85043Эксплойта нет | Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via cragoogle · chrome · CWE-459 | Критическая9,1 | — | 0,4 % | 3 сент. 2026 г. |
36Наблюдать | CVE-2025-6338Эксплойта нет | Possible denial of service with multiple incoming connections to a Schannel based server with a TLS backendqt · qt · CWE-459 | Критическая9,2 | — | 0,4 % | 16 окт. 2025 г. |
36Наблюдать | CVE-2026-15390Эксплойта нет | Out-of-bounds write in Das U-Bootdenx software engineering · das u-boot · CWE-459 | Критическая9,0 | — | — | 1 день назад |
35Наблюдать | CVE-2020-24489Эксплойта нет | Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local acintel · atom x5-e3930 · CWE-459 | Высокая8,8 | — | 0,4 % | 9 июн. 2021 г. |
34Наблюдать | CVE-2026-3304Proof of concept | Multer vulnerable to Denial of Service via incomplete cleanupexpressjs · multer · CWE-459 | Высокая8,7 | — | 0,9 % | 27 февр. 2026 г. |
34Наблюдать | CVE-2026-52736Эксплойта нет | ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cachezcashfoundation · zebra · CWE-459 | Высокая8,7 | — | 0,6 % | 18 авг. 2026 г. |
34Наблюдать | CVE-2025-21609Эксплойта нет | SiYuan has an arbitrary file deletion vulnerabilityb3log · siyuan · CWE-459 | Высокая8,7 | — | 0,6 % | 3 янв. 2025 г. |
34Наблюдать | CVE-2025-59781Эксплойта нет | BIG-IP DNS cache vulnerabilityf5 · big-ip access policy manager · CWE-459 | Высокая8,7 | — | 0,3 % | 15 окт. 2025 г. |
- CVE-2017-1709055В плане
An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified As
ВысокаяCVSS 7,5Proof of conceptEPSS 82 %digium · certified asterisk1 дек. 2017 г.
- CVE-2025-3165048В плане
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
ВысокаяCVSS 7,5Proof of conceptEPSS 61 %apache · tomcat28 апр. 2025 г.
- CVE-2022-155240В плане
A flaw was found in PostgreSQL.
ВысокаяCVSS 8,8Эксплойта нетEPSS 16 %postgresql · postgresql31 авг. 2022 г.
- CVE-2020-1345140В плане
An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice co
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %thecodingmachine · gotenberg7 янв. 2021 г.
- CVE-2005-174440В плане
BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows t
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %bea · weblogic server24 мая 2005 г.
- CVE-2021-4533039Наблюдать
An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and t
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gitea · gitea9 февр. 2022 г.
- CVE-2022-4534739Наблюдать
Apache ShardingSphere-Proxy: MySQL authentication bypass
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %apache · shardingsphere22 дек. 2022 г.
- CVE-2021-3292839Наблюдать
The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Manager” that allows i
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %thalesgroup · sentinel ldk run-time environment16 июн. 2021 г.
- CVE-2021-4570639Наблюдать
An issue was discovered in the zeroize_derive crate before 1.1.1 for Rust.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zeroize derive project · zeroize derive26 дек. 2021 г.
- CVE-2021-3620539Наблюдать
Metasys session token
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %johnsoncontrols · metasys application and data server15 апр. 2022 г.
- CVE-2026-2826839Наблюдать
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %vikunja · vikunja27 февр. 2026 г.
- CVE-2018-1892438Наблюдать
The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" be
ВысокаяCVSS 8,8Proof of conceptEPSS 9 %projeqtor · projeqtor4 нояб. 2018 г.
- CVE-2026-3426338Наблюдать
Missing authentication check in SAP Commerce cloud configuration
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %sap_se · sap commerce cloud configuration11 мая 2026 г.
- CVE-2019-2501636Наблюдать
In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %opendoas project · opendoas28 янв. 2021 г.
- CVE-2019-1819136Наблюдать
A privilege escalation vulnerability in the Trend Micro Deep Security as a Service Quick Setup cloud formation template could allow an authe
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %trendmicro · deep security as a service16 дек. 2019 г.
- CVE-2023-3646836Наблюдать
Upgrading doesn't prevent exploiting vulnerable XWiki documents
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %xwiki · xwiki29 июн. 2023 г.
- CVE-2024-2826536Наблюдать
IBOS v4.5.5 has an arbitrary file deletion vulnerability via \system\modules\dashboard\controllers\LoginController.php.
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %ibos · ibos1 нояб. 2024 г.
- CVE-2026-8504336Наблюдать
Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via cra
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %google · chrome3 сент. 2026 г.
- CVE-2025-633836Наблюдать
Possible denial of service with multiple incoming connections to a Schannel based server with a TLS backend
КритическаяCVSS 9,2Эксплойта нетEPSS 0 %qt · qt16 окт. 2025 г.
- CVE-2026-1539036Наблюдать
Out-of-bounds write in Das U-Boot
КритическаяCVSS 9,0Эксплойта нетdenx software engineering · das u-boot1 день назад
- CVE-2020-2448935Наблюдать
Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local ac
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %intel · atom x5-e39309 июн. 2021 г.
- CVE-2026-330434Наблюдать
Multer vulnerable to Denial of Service via incomplete cleanup
ВысокаяCVSS 8,7Proof of conceptEPSS 1 %expressjs · multer27 февр. 2026 г.
- CVE-2026-5273634Наблюдать
ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cache
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %zcashfoundation · zebra18 авг. 2026 г.
- CVE-2025-2160934Наблюдать
SiYuan has an arbitrary file deletion vulnerability
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %b3log · siyuan3 янв. 2025 г.
- CVE-2025-5978134Наблюдать
BIG-IP DNS cache vulnerability
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %f5 · big-ip access policy manager15 окт. 2025 г.