CWE-402 · 24 records
Transmission of Private Resources into a New Sphere ('Resource Leak')
CVEs in this class
24 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2021-23264No exploit | Transmission of Private Resources into a New Sphere ('Resource Leak') and Exposure of Resource to Wrong Sphere in Crafter Searchcraftercms · crafter cms · CWE-402 | Critical9.1 | — | 1.2% | Dec 2, 2021 |
34Monitor | CVE-2025-29925Proof of concept | XWiki allows unregistered users to access private pages information through REST endpointxwiki · xwiki · CWE-402 | High8.7 | — | 0.9% | Mar 19, 2025 |
34Monitor | GHSA-j9wr-49vq-rm5gNo exploit | Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19Maven · com.vaadin:vaadin-bom · CWE-402 | High8.6 | — | — | Apr 19, 2021 |
32Monitor | CVE-2025-48383No exploit | Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leakingcodingjoe · django-select2 · CWE-402 | High8.2 | — | 0.3% | May 27, 2025 |
32Monitor | CVE-2025-32360No exploit | In Zammad 6.4.x before 6.4.2, there is information exposure.zammad · zammad · CWE-402 | High8.1 | — | 0.3% | Apr 5, 2025 |
31Monitor | CVE-2021-31407No exploit | Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19vaadin · flow · CWE-402 | High7.5 | — | 2.4% | Apr 23, 2021 |
31Monitor | CVE-2021-23263No exploit | Transmission of Private Resources into a New Sphere ('Resource Leak') in Crafter Enginecraftercms · crafter cms · CWE-402 | High7.5 | — | 1.7% | Dec 2, 2021 |
31Monitor | CVE-2021-31410No exploit | Project sources exposure in Vaadin Designervaadin · designer · CWE-402 | High7.5 | — | 1.7% | Apr 23, 2021 |
30Monitor | CVE-2022-3596No exploit | Instack-undercloud: rsync leaks information to undercloudredhat · openstack platform · CWE-402 | High7.5 | — | 1.1% | Sep 20, 2023 |
30Monitor | CVE-2023-34467No exploit | XWiki Platform may retrieve email addresses of all usersxwiki · xwiki · CWE-402 | High7.5 | — | 1.0% | Jun 23, 2023 |
30Monitor | CVE-2024-29900No exploit | @electron/packager's build process memory potentially leaked into final executableopenjsf · packager · CWE-402 | High7.5 | — | 0.6% | Mar 29, 2024 |
30Monitor | CVE-2025-67745No exploit | Myhoard logs backup encryption key in plain textaiven · myhoard · CWE-402 | High7.5 | — | 0.2% | Dec 18, 2025 |
28Monitor | CVE-2024-47146No exploit | Ruijie Reyee OS Resource Leakruijienetworks · reyee os · CWE-402 | High7.1 | — | 0.3% | Dec 6, 2024 |
27Monitor | CVE-2022-30231No exploit | A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6).siemens · sicam gridedge essential · CWE-402 | Medium6.9 | — | 0.6% | Jun 14, 2022 |
27Monitor | CVE-2025-0502No exploit | Transmission of Private Resources into a New Sphere in Crafter Enginecraftercms · craftercms · CWE-402 | Medium6.9 | — | 0.4% | Jan 15, 2025 |
26Monitor | CVE-2017-8442No exploit | Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configuratelastic · x-pack · CWE-402 | Medium6.5 | — | 0.9% | Jul 7, 2017 |
23Monitor | CVE-2025-49618No exploit | In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint.plesk · obsidian · CWE-402 | Medium5.8 | — | 0.4% | Jul 3, 2025 |
22Monitor | CVE-2023-4569No exploit | Kernel: information leak in nft_set_catchall_flush in net/netfilter/nf_tables_api.clinux · linux kernel · CWE-402 | Medium5.5 | — | 0.3% | Aug 28, 2023 |
22Monitor | CVE-2024-0443No exploit | Kernel: blkio memory leakage due to blkcg and some blkgs are not freed after they are made offline.linux · linux kernel · CWE-402 | Medium5.5 | — | 0.2% | Jan 11, 2024 |
21Monitor | CVE-2024-32388No exploit | Due to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP packets.kerlink · keros · CWE-402 | Medium5.3 | — | 1.2% | Dec 1, 2025 |
20Monitor | CVE-2025-52925No exploit | In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812.onelogin · active directory connector · CWE-402 | Medium5.0 | — | 0.2% | Jul 2, 2025 |
18Monitor | CVE-2025-55014No exploit | The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dstardict · stardict · CWE-402 | Medium4.7 | — | 0.4% | Aug 4, 2025 |
17Monitor | CVE-2023-38509No exploit | XWiki Platform's obfuscated email addresses should not be sortedxwiki · xwiki · CWE-402 | Medium4.3 | — | 0.8% | Nov 7, 2023 |
17Monitor | CVE-2025-66422No exploit | Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information.tryton · trytond · CWE-402 | Medium4.3 | — | 0.3% | Nov 30, 2025 |
- CVE-2021-2326436Monitor
Transmission of Private Resources into a New Sphere ('Resource Leak') and Exposure of Resource to Wrong Sphere in Crafter Search
CriticalCVSS 9.1No exploitEPSS 1%craftercms · crafter cmsDec 2, 2021
- CVE-2025-2992534Monitor
XWiki allows unregistered users to access private pages information through REST endpoint
HighCVSS 8.7Proof of conceptEPSS 1%xwiki · xwikiMar 19, 2025
- GHSA-j9wr-49vq-rm5g34Monitor
Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19
HighCVSS 8.6No exploitMaven · com.vaadin:vaadin-bomApr 19, 2021
- CVE-2025-4838332Monitor
Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking
HighCVSS 8.2No exploitEPSS 0%codingjoe · django-select2May 27, 2025
- CVE-2025-3236032Monitor
In Zammad 6.4.x before 6.4.2, there is information exposure.
HighCVSS 8.1No exploitEPSS 0%zammad · zammadApr 5, 2025
- CVE-2021-3140731Monitor
Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19
HighCVSS 7.5No exploitEPSS 2%vaadin · flowApr 23, 2021
- CVE-2021-2326331Monitor
Transmission of Private Resources into a New Sphere ('Resource Leak') in Crafter Engine
HighCVSS 7.5No exploitEPSS 2%craftercms · crafter cmsDec 2, 2021
- CVE-2021-3141031Monitor
Project sources exposure in Vaadin Designer
HighCVSS 7.5No exploitEPSS 2%vaadin · designerApr 23, 2021
- CVE-2022-359630Monitor
Instack-undercloud: rsync leaks information to undercloud
HighCVSS 7.5No exploitEPSS 1%redhat · openstack platformSep 20, 2023
- CVE-2023-3446730Monitor
XWiki Platform may retrieve email addresses of all users
HighCVSS 7.5No exploitEPSS 1%xwiki · xwikiJun 23, 2023
- CVE-2024-2990030Monitor
@electron/packager's build process memory potentially leaked into final executable
HighCVSS 7.5No exploitEPSS 1%openjsf · packagerMar 29, 2024
- CVE-2025-6774530Monitor
Myhoard logs backup encryption key in plain text
HighCVSS 7.5No exploitEPSS 0%aiven · myhoardDec 18, 2025
- CVE-2024-4714628Monitor
Ruijie Reyee OS Resource Leak
HighCVSS 7.1No exploitEPSS 0%ruijienetworks · reyee osDec 6, 2024
- CVE-2022-3023127Monitor
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6).
MediumCVSS 6.9No exploitEPSS 1%siemens · sicam gridedge essentialJun 14, 2022
- CVE-2025-050227Monitor
Transmission of Private Resources into a New Sphere in Crafter Engine
MediumCVSS 6.9No exploitEPSS 0%craftercms · craftercmsJan 15, 2025
- CVE-2017-844226Monitor
Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configurat
MediumCVSS 6.5No exploitEPSS 1%elastic · x-packJul 7, 2017
- CVE-2025-4961823Monitor
In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint.
MediumCVSS 5.8No exploitEPSS 0%plesk · obsidianJul 3, 2025
- CVE-2023-456922Monitor
Kernel: information leak in nft_set_catchall_flush in net/netfilter/nf_tables_api.c
MediumCVSS 5.5No exploitEPSS 0%linux · linux kernelAug 28, 2023
- CVE-2024-044322Monitor
Kernel: blkio memory leakage due to blkcg and some blkgs are not freed after they are made offline.
MediumCVSS 5.5No exploitEPSS 0%linux · linux kernelJan 11, 2024
- CVE-2024-3238821Monitor
Due to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP packets.
MediumCVSS 5.3No exploitEPSS 1%kerlink · kerosDec 1, 2025
- CVE-2025-5292520Monitor
In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812.
MediumCVSS 5.0No exploitEPSS 0%onelogin · active directory connectorJul 2, 2025
- CVE-2025-5501418Monitor
The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the d
MediumCVSS 4.7No exploitEPSS 0%stardict · stardictAug 4, 2025
- CVE-2023-3850917Monitor
XWiki Platform's obfuscated email addresses should not be sorted
MediumCVSS 4.3No exploitEPSS 1%xwiki · xwikiNov 7, 2023
- CVE-2025-6642217Monitor
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information.
MediumCVSS 4.3No exploitEPSS 0%tryton · trytondNov 30, 2025