Skip to content
Noroxi

CWE-402 · 24 records

Transmission of Private Resources into a New Sphere ('Resource Leak')

CVEs in this class

24 records

  • Transmission of Private Resources into a New Sphere ('Resource Leak') and Exposure of Resource to Wrong Sphere in Crafter Search

    CriticalCVSS 9.1No exploitEPSS 1%

    craftercms · crafter cmsDec 2, 2021

  • XWiki allows unregistered users to access private pages information through REST endpoint

    HighCVSS 8.7Proof of conceptEPSS 1%

    xwiki · xwikiMar 19, 2025

  • Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19

    HighCVSS 8.6No exploit

    Maven · com.vaadin:vaadin-bomApr 19, 2021

  • Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking

    HighCVSS 8.2No exploitEPSS 0%

    codingjoe · django-select2May 27, 2025

  • In Zammad 6.4.x before 6.4.2, there is information exposure.

    HighCVSS 8.1No exploitEPSS 0%

    zammad · zammadApr 5, 2025

  • Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19

    HighCVSS 7.5No exploitEPSS 2%

    vaadin · flowApr 23, 2021

  • Transmission of Private Resources into a New Sphere ('Resource Leak') in Crafter Engine

    HighCVSS 7.5No exploitEPSS 2%

    craftercms · crafter cmsDec 2, 2021

  • Project sources exposure in Vaadin Designer

    HighCVSS 7.5No exploitEPSS 2%

    vaadin · designerApr 23, 2021

  • CVE-2022-3596
    30Monitor

    Instack-undercloud: rsync leaks information to undercloud

    HighCVSS 7.5No exploitEPSS 1%

    redhat · openstack platformSep 20, 2023

  • XWiki Platform may retrieve email addresses of all users

    HighCVSS 7.5No exploitEPSS 1%

    xwiki · xwikiJun 23, 2023

  • @electron/packager's build process memory potentially leaked into final executable

    HighCVSS 7.5No exploitEPSS 1%

    openjsf · packagerMar 29, 2024

  • Myhoard logs backup encryption key in plain text

    HighCVSS 7.5No exploitEPSS 0%

    aiven · myhoardDec 18, 2025

  • Ruijie Reyee OS Resource Leak

    HighCVSS 7.1No exploitEPSS 0%

    ruijienetworks · reyee osDec 6, 2024

  • A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6).

    MediumCVSS 6.9No exploitEPSS 1%

    siemens · sicam gridedge essentialJun 14, 2022

  • CVE-2025-0502
    27Monitor

    Transmission of Private Resources into a New Sphere in Crafter Engine

    MediumCVSS 6.9No exploitEPSS 0%

    craftercms · craftercmsJan 15, 2025

  • CVE-2017-8442
    26Monitor

    Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configurat

    MediumCVSS 6.5No exploitEPSS 1%

    elastic · x-packJul 7, 2017

  • In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint.

    MediumCVSS 5.8No exploitEPSS 0%

    plesk · obsidianJul 3, 2025

  • CVE-2023-4569
    22Monitor

    Kernel: information leak in nft_set_catchall_flush in net/netfilter/nf_tables_api.c

    MediumCVSS 5.5No exploitEPSS 0%

    linux · linux kernelAug 28, 2023

  • CVE-2024-0443
    22Monitor

    Kernel: blkio memory leakage due to blkcg and some blkgs are not freed after they are made offline.

    MediumCVSS 5.5No exploitEPSS 0%

    linux · linux kernelJan 11, 2024

  • Due to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP packets.

    MediumCVSS 5.3No exploitEPSS 1%

    kerlink · kerosDec 1, 2025

  • In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812.

    MediumCVSS 5.0No exploitEPSS 0%

    onelogin · active directory connectorJul 2, 2025

  • The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the d

    MediumCVSS 4.7No exploitEPSS 0%

    stardict · stardictAug 4, 2025

  • XWiki Platform's obfuscated email addresses should not be sorted

    MediumCVSS 4.3No exploitEPSS 1%

    xwiki · xwikiNov 7, 2023

  • Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information.

    MediumCVSS 4.3No exploitEPSS 0%

    tryton · trytondNov 30, 2025

All vulnerability classes