CWE-672 · 65 kayıt
Operation on a Resource after Expiration or Release
Bu sınıftaki CVE’ler
65 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-17638Kavram kanıtı | In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produceeclipse · jetty · CWE-672 | Kritik9,4 | — | %11,1 | 9 Tem 2020 |
40Planlayın | CVE-2020-24030Kavram kanıtı | ForLogic Qualiex v1 and v3 has weak token expiration.forlogic · qualiex · CWE-672 | Kritik9,8 | — | %2,7 | 2 Eyl 2020 |
40Planlayın | CVE-2020-12043İstismar yok | The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the Wbaxter · sigma spectrum infusion system firmware · CWE-672 | Kritik9,8 | — | %2,1 | 29 Haz 2020 |
39İzleyin | CVE-2024-47571İstismar yok | An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper accfortinet · fortimanager · CWE-672 | Kritik9,8 | — | %0,9 | 14 Oca 2025 |
36İzleyin | CVE-2020-11027Kavram kanıtı | Password reset links invalidation issue in WordPresswordpress · wordpress · CWE-672 | Yüksek8,1 | — | %13,6 | 30 Nis 2020 |
36İzleyin | CVE-2026-43585İstismar yok | OpenClaw < 2026.4.15 - Bearer Token Validation Bypass via Stale SecretRef Resolutionopenclaw · openclaw · CWE-672 | Kritik9,2 | — | %0,8 | 6 May 2026 |
36İzleyin | CVE-2013-10075İstismar yok | Apache::Session versions through 1.94 for Perl re-creates deleted sessionschorny · apache\ · CWE-672 | Kritik9,1 | — | %0,4 | 8 May 2026 |
35İzleyin | CVE-2021-23995İstismar yok | When Responsive Design Mode was enabled, it used references to objects that were previously freed.mozilla · firefox · CWE-672 | Yüksek8,8 | — | %1,2 | 24 Haz 2021 |
35İzleyin | CVE-2022-22755İstismar yok | By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScript (within thmozilla · firefox · CWE-672 | Yüksek8,8 | — | %0,6 | 22 Ara 2022 |
34İzleyin | CVE-2025-55669İstismar yok | BIG-IP HTTP/2 vulnerabilityf5 · big-ip application security manager · CWE-672 | Yüksek8,7 | — | %0,4 | 15 Eki 2025 |
32İzleyin | CVE-2026-31875İstismar yok | Parse Server MFA recovery codes not consumed after useparseplatform · parse-server · CWE-672 | Yüksek8,2 | — | %0,5 | 11 Mar 2026 |
32İzleyin | CVE-2026-2379İstismar yok | Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is Disabledarista networks · eos · CWE-672 | Yüksek8,2 | — | %0,2 | 5 Haz 2026 |
32İzleyin | GHSA-m8wm-r5vq-qjpgİstismar yok | Duplicate Advisory: OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotationnpm · openclaw · CWE-672 | Yüksek8,1 | — | — | 6 May 2026 |
31İzleyin | CVE-2021-37204İstismar yok | A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC Drive Controller family (All versionsiemens · simatic drive controller cpu 1504d tf firmware · CWE-672 | Yüksek7,5 | — | %2,2 | 9 Şub 2022 |
31İzleyin | CVE-2021-37185İstismar yok | A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller Csiemens · simatic drive controller cpu 1504d tf firmware · CWE-672 | Yüksek7,5 | — | %2,1 | 9 Şub 2022 |
31İzleyin | CVE-2019-15791Kavram kanıtı | Reference count underflow in shiftfslinux · linux kernel · CWE-672 | Yüksek7,8 | — | %1,3 | 23 Nis 2020 |
31İzleyin | CVE-2017-0544İstismar yok | An elevation of privilege vulnerability in CameraBase could enable a local malicious application to execute arbitrary code.google · android · CWE-672 | Yüksek7,8 | — | %0,9 | 7 Nis 2017 |
31İzleyin | CVE-2020-25221İstismar yok | get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference countilinux · linux kernel · CWE-672 | Yüksek7,8 | — | %0,7 | 10 Eyl 2020 |
31İzleyin | CVE-2023-34326İstismar yok | x86/AMD: missing IOMMU TLB flushingxen · xen · CWE-672 | Yüksek7,8 | — | %0,3 | 5 Oca 2024 |
31İzleyin | CVE-2017-14895İstismar yok | In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, after a subsystem reset, iwpgoogle · android · CWE-672 | Yüksek7,8 | — | %0,3 | 5 Ara 2017 |
30İzleyin | CVE-2022-22197İstismar yok | Junos OS and Junos OS Evolved: An rpd core will be observed with proxy BGP route-target filtering enabled and certain route add and delete event happeningjuniper · junos os evolved · CWE-672 | Yüksek7,5 | — | %1,1 | 14 Nis 2022 |
30İzleyin | CVE-2022-30256İstismar yok | An issue was discovered in MaraDNS Deadwood through 3.5.0021 that allows variant V1 of unintended domain name resolution.maradns · maradns · CWE-672 | Yüksek7,5 | — | %1,0 | 18 Kas 2022 |
30İzleyin | CVE-2022-22332İstismar yok | IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for thibm · partner engagement manager · CWE-672 | Yüksek7,5 | — | %0,8 | 1 Nis 2022 |
30İzleyin | CVE-2026-68481İstismar yok | Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProviderapache · cxf · CWE-672 | Yüksek7,5 | — | %0,7 | 6 Ağu 2026 |
30İzleyin | CVE-2025-58149İstismar yok | Incorrect removal of permissions on PCI device unplugxen · xen · CWE-672 | Yüksek7,5 | — | %0,4 | 31 Eki 2025 |
- CVE-2019-1763840Planlayın
In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce
KritikCVSS 9,4Kavram kanıtıEPSS %11eclipse · jetty9 Tem 2020
- CVE-2020-2403040Planlayın
ForLogic Qualiex v1 and v3 has weak token expiration.
KritikCVSS 9,8Kavram kanıtıEPSS %3forlogic · qualiex2 Eyl 2020
- CVE-2020-1204340Planlayın
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the W
KritikCVSS 9,8İstismar yokEPSS %2baxter · sigma spectrum infusion system firmware29 Haz 2020
- CVE-2024-4757139İzleyin
An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper acc
KritikCVSS 9,8İstismar yokEPSS %1fortinet · fortimanager14 Oca 2025
- CVE-2020-1102736İzleyin
Password reset links invalidation issue in WordPress
YüksekCVSS 8,1Kavram kanıtıEPSS %14wordpress · wordpress30 Nis 2020
- CVE-2026-4358536İzleyin
OpenClaw < 2026.4.15 - Bearer Token Validation Bypass via Stale SecretRef Resolution
KritikCVSS 9,2İstismar yokEPSS %1openclaw · openclaw6 May 2026
- CVE-2013-1007536İzleyin
Apache::Session versions through 1.94 for Perl re-creates deleted sessions
KritikCVSS 9,1İstismar yokEPSS %0chorny · apache\8 May 2026
- CVE-2021-2399535İzleyin
When Responsive Design Mode was enabled, it used references to objects that were previously freed.
YüksekCVSS 8,8İstismar yokEPSS %1mozilla · firefox24 Haz 2021
- CVE-2022-2275535İzleyin
By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScript (within th
YüksekCVSS 8,8İstismar yokEPSS %1mozilla · firefox22 Ara 2022
- CVE-2025-5566934İzleyin
BIG-IP HTTP/2 vulnerability
YüksekCVSS 8,7İstismar yokEPSS %0f5 · big-ip application security manager15 Eki 2025
- CVE-2026-3187532İzleyin
Parse Server MFA recovery codes not consumed after use
YüksekCVSS 8,2İstismar yokEPSS %1parseplatform · parse-server11 Mar 2026
- CVE-2026-237932İzleyin
Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is Disabled
YüksekCVSS 8,2İstismar yokEPSS %0arista networks · eos5 Haz 2026
- GHSA-m8wm-r5vq-qjpg32İzleyin
Duplicate Advisory: OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation
YüksekCVSS 8,1İstismar yoknpm · openclaw6 May 2026
- CVE-2021-3720431İzleyin
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC Drive Controller family (All version
YüksekCVSS 7,5İstismar yokEPSS %2siemens · simatic drive controller cpu 1504d tf firmware9 Şub 2022
- CVE-2021-3718531İzleyin
A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller C
YüksekCVSS 7,5İstismar yokEPSS %2siemens · simatic drive controller cpu 1504d tf firmware9 Şub 2022
- CVE-2019-1579131İzleyin
Reference count underflow in shiftfs
YüksekCVSS 7,8Kavram kanıtıEPSS %1linux · linux kernel23 Nis 2020
- CVE-2017-054431İzleyin
An elevation of privilege vulnerability in CameraBase could enable a local malicious application to execute arbitrary code.
YüksekCVSS 7,8İstismar yokEPSS %1google · android7 Nis 2017
- CVE-2020-2522131İzleyin
get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counti
YüksekCVSS 7,8İstismar yokEPSS %1linux · linux kernel10 Eyl 2020
- CVE-2023-3432631İzleyin
x86/AMD: missing IOMMU TLB flushing
YüksekCVSS 7,8İstismar yokEPSS %0xen · xen5 Oca 2024
- CVE-2017-1489531İzleyin
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, after a subsystem reset, iwp
YüksekCVSS 7,8İstismar yokEPSS %0google · android5 Ara 2017
- CVE-2022-2219730İzleyin
Junos OS and Junos OS Evolved: An rpd core will be observed with proxy BGP route-target filtering enabled and certain route add and delete event happening
YüksekCVSS 7,5İstismar yokEPSS %1juniper · junos os evolved14 Nis 2022
- CVE-2022-3025630İzleyin
An issue was discovered in MaraDNS Deadwood through 3.5.0021 that allows variant V1 of unintended domain name resolution.
YüksekCVSS 7,5İstismar yokEPSS %1maradns · maradns18 Kas 2022
- CVE-2022-2233230İzleyin
IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for th
YüksekCVSS 7,5İstismar yokEPSS %1ibm · partner engagement manager1 Nis 2022
- CVE-2026-6848130İzleyin
Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider
YüksekCVSS 7,5İstismar yokEPSS %1apache · cxf6 Ağu 2026
- CVE-2025-5814930İzleyin
Incorrect removal of permissions on PCI device unplug
YüksekCVSS 7,5İstismar yokEPSS %0xen · xen31 Eki 2025