CWE-412 · 6 records
Unrestricted Externally Accessible Lock
CVEs in this class
6 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2019-18269No exploit | Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability.omron · plc cj firmware · CWE-412 | Critical9.8 | — | 1.0% | Dec 16, 2019 |
35Monitor | CVE-2026-62426No exploit | sysctl and platform-op locks open to abusexen · xen · CWE-412 | High8.8 | — | 0.4% | Jul 28, 2026 |
30Monitor | CVE-2023-22318No exploit | Denial of service against webconftribe29 · checkmk appliance firmware · CWE-412 | High7.5 | — | 0.5% | May 15, 2023 |
28Monitor | CVE-2026-25612No exploit | Internal ResourceId collision may affect unrelated collectionsmongodb inc · mongodb server · CWE-412 | High7.1 | — | 0.4% | Feb 10, 2026 |
13Monitor | CVE-2019-11485No exploit | apport created lock file in wrong directoryapport project · apport · CWE-412 | Low3.3 | — | 0.3% | Feb 8, 2020 |
7Monitor | CVE-2026-82312No exploit | OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULopenvpn · openvpn · CWE-412 | Low1.8 | — | 0.1% | Sep 7, 2026 |
- CVE-2019-1826939Monitor
Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability.
CriticalCVSS 9.8No exploitEPSS 1%omron · plc cj firmwareDec 16, 2019
- CVE-2026-6242635Monitor
sysctl and platform-op locks open to abuse
HighCVSS 8.8No exploitEPSS 0%xen · xenJul 28, 2026
- CVE-2023-2231830Monitor
Denial of service against webconf
HighCVSS 7.5No exploitEPSS 1%tribe29 · checkmk appliance firmwareMay 15, 2023
- CVE-2026-2561228Monitor
Internal ResourceId collision may affect unrelated collections
HighCVSS 7.1No exploitEPSS 0%mongodb inc · mongodb serverFeb 10, 2026
- CVE-2019-1148513Monitor
apport created lock file in wrong directory
LowCVSS 3.3No exploitEPSS 0%apport project · apportFeb 8, 2020
- CVE-2026-823127Monitor
OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NUL
LowCVSS 1.8No exploitEPSS 0%openvpn · openvpnSep 7, 2026