İçeriğe atla
Noroxi

CWE-672 · 65 kayıt

Operation on a Resource after Expiration or Release

Bu sınıftaki CVE’ler

65 kayıt

  • CVE-2019-17638
    40Planlayın

    In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce

    KritikCVSS 9,4Kavram kanıtıEPSS %11

    eclipse · jetty9 Tem 2020

  • CVE-2020-24030
    40Planlayın

    ForLogic Qualiex v1 and v3 has weak token expiration.

    KritikCVSS 9,8Kavram kanıtıEPSS %3

    forlogic · qualiex2 Eyl 2020

  • CVE-2020-12043
    40Planlayın

    The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the W

    KritikCVSS 9,8İstismar yokEPSS %2

    baxter · sigma spectrum infusion system firmware29 Haz 2020

  • CVE-2024-47571
    39İzleyin

    An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper acc

    KritikCVSS 9,8İstismar yokEPSS %1

    fortinet · fortimanager14 Oca 2025

  • CVE-2020-11027
    36İzleyin

    Password reset links invalidation issue in WordPress

    YüksekCVSS 8,1Kavram kanıtıEPSS %14

    wordpress · wordpress30 Nis 2020

  • CVE-2026-43585
    36İzleyin

    OpenClaw < 2026.4.15 - Bearer Token Validation Bypass via Stale SecretRef Resolution

    KritikCVSS 9,2İstismar yokEPSS %1

    openclaw · openclaw6 May 2026

  • CVE-2013-10075
    36İzleyin

    Apache::Session versions through 1.94 for Perl re-creates deleted sessions

    KritikCVSS 9,1İstismar yokEPSS %0

    chorny · apache\8 May 2026

  • CVE-2021-23995
    35İzleyin

    When Responsive Design Mode was enabled, it used references to objects that were previously freed.

    YüksekCVSS 8,8İstismar yokEPSS %1

    mozilla · firefox24 Haz 2021

  • CVE-2022-22755
    35İzleyin

    By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScript (within th

    YüksekCVSS 8,8İstismar yokEPSS %1

    mozilla · firefox22 Ara 2022

  • CVE-2025-55669
    34İzleyin

    BIG-IP HTTP/2 vulnerability

    YüksekCVSS 8,7İstismar yokEPSS %0

    f5 · big-ip application security manager15 Eki 2025

  • CVE-2026-31875
    32İzleyin

    Parse Server MFA recovery codes not consumed after use

    YüksekCVSS 8,2İstismar yokEPSS %1

    parseplatform · parse-server11 Mar 2026

  • CVE-2026-2379
    32İzleyin

    Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is Disabled

    YüksekCVSS 8,2İstismar yokEPSS %0

    arista networks · eos5 Haz 2026

  • Duplicate Advisory: OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation

    YüksekCVSS 8,1İstismar yok

    npm · openclaw6 May 2026

  • CVE-2021-37204
    31İzleyin

    A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC Drive Controller family (All version

    YüksekCVSS 7,5İstismar yokEPSS %2

    siemens · simatic drive controller cpu 1504d tf firmware9 Şub 2022

  • CVE-2021-37185
    31İzleyin

    A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller C

    YüksekCVSS 7,5İstismar yokEPSS %2

    siemens · simatic drive controller cpu 1504d tf firmware9 Şub 2022

  • CVE-2019-15791
    31İzleyin

    Reference count underflow in shiftfs

    YüksekCVSS 7,8Kavram kanıtıEPSS %1

    linux · linux kernel23 Nis 2020

  • CVE-2017-0544
    31İzleyin

    An elevation of privilege vulnerability in CameraBase could enable a local malicious application to execute arbitrary code.

    YüksekCVSS 7,8İstismar yokEPSS %1

    google · android7 Nis 2017

  • CVE-2020-25221
    31İzleyin

    get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counti

    YüksekCVSS 7,8İstismar yokEPSS %1

    linux · linux kernel10 Eyl 2020

  • CVE-2023-34326
    31İzleyin

    x86/AMD: missing IOMMU TLB flushing

    YüksekCVSS 7,8İstismar yokEPSS %0

    xen · xen5 Oca 2024

  • CVE-2017-14895
    31İzleyin

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, after a subsystem reset, iwp

    YüksekCVSS 7,8İstismar yokEPSS %0

    google · android5 Ara 2017

  • CVE-2022-22197
    30İzleyin

    Junos OS and Junos OS Evolved: An rpd core will be observed with proxy BGP route-target filtering enabled and certain route add and delete event happening

    YüksekCVSS 7,5İstismar yokEPSS %1

    juniper · junos os evolved14 Nis 2022

  • CVE-2022-30256
    30İzleyin

    An issue was discovered in MaraDNS Deadwood through 3.5.0021 that allows variant V1 of unintended domain name resolution.

    YüksekCVSS 7,5İstismar yokEPSS %1

    maradns · maradns18 Kas 2022

  • CVE-2022-22332
    30İzleyin

    IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for th

    YüksekCVSS 7,5İstismar yokEPSS %1

    ibm · partner engagement manager1 Nis 2022

  • CVE-2026-68481
    30İzleyin

    Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider

    YüksekCVSS 7,5İstismar yokEPSS %1

    apache · cxf6 Ağu 2026

  • CVE-2025-58149
    30İzleyin

    Incorrect removal of permissions on PCI device unplug

    YüksekCVSS 7,5İstismar yokEPSS %0

    xen · xen31 Eki 2025

Tüm zafiyet sınıfları