CWE-459 · 205 records
Incomplete Cleanup
CVEs in this class
205 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
55Plan | CVE-2017-17090Proof of concept | An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asdigium · certified asterisk · CWE-459 | High7.5 | — | 82.2% | Dec 1, 2017 |
48Plan | CVE-2025-31650Proof of concept | Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frameapache · tomcat · CWE-459 | High7.5 | — | 61.0% | Apr 28, 2025 |
40Plan | CVE-2022-1552No exploit | A flaw was found in PostgreSQL.postgresql · postgresql · CWE-459 | High8.8 | — | 16.0% | Aug 31, 2022 |
40Plan | CVE-2020-13451No exploit | An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice cothecodingmachine · gotenberg · CWE-459 | Critical9.8 | — | 3.0% | Jan 7, 2021 |
40Plan | CVE-2005-1744No exploit | BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows tbea · weblogic server · CWE-459 | Critical9.8 | — | 2.1% | May 24, 2005 |
39Monitor | CVE-2021-45330No exploit | An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and tgitea · gitea · CWE-459 | Critical9.8 | — | 1.4% | Feb 9, 2022 |
39Monitor | CVE-2022-45347No exploit | Apache ShardingSphere-Proxy: MySQL authentication bypassapache · shardingsphere · CWE-459 | Critical9.8 | — | 1.4% | Dec 22, 2022 |
39Monitor | CVE-2021-32928No exploit | The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Manager” that allows ithalesgroup · sentinel ldk run-time environment · CWE-459 | Critical9.8 | — | 1.3% | Jun 16, 2021 |
39Monitor | CVE-2021-45706No exploit | An issue was discovered in the zeroize_derive crate before 1.1.1 for Rust.zeroize derive project · zeroize derive · CWE-459 | Critical9.8 | — | 1.2% | Dec 26, 2021 |
39Monitor | CVE-2021-36205No exploit | Metasys session tokenjohnsoncontrols · metasys application and data server · CWE-459 | Critical9.8 | — | 1.0% | Apr 15, 2022 |
39Monitor | CVE-2026-28268No exploit | Vikunja Vulnerable to Account Takeover via Password Reset Token Reusevikunja · vikunja · CWE-459 | Critical9.8 | — | 0.9% | Feb 27, 2026 |
38Monitor | CVE-2018-18924Proof of concept | The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" beprojeqtor · projeqtor · CWE-459 | High8.8 | — | 9.5% | Nov 4, 2018 |
38Monitor | CVE-2026-34263No exploit | Missing authentication check in SAP Commerce cloud configurationsap_se · sap commerce cloud configuration · CWE-459 | Critical9.6 | — | 0.6% | May 11, 2026 |
36Monitor | CVE-2019-25016No exploit | In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowedopendoas project · opendoas · CWE-459 | High8.8 | — | 2.7% | Jan 28, 2021 |
36Monitor | CVE-2019-18191No exploit | A privilege escalation vulnerability in the Trend Micro Deep Security as a Service Quick Setup cloud formation template could allow an authetrendmicro · deep security as a service · CWE-459 | High8.8 | — | 2.2% | Dec 16, 2019 |
36Monitor | CVE-2023-36468No exploit | Upgrading doesn't prevent exploiting vulnerable XWiki documentsxwiki · xwiki · CWE-459 | High8.8 | — | 1.9% | Jun 29, 2023 |
36Monitor | CVE-2024-28265No exploit | IBOS v4.5.5 has an arbitrary file deletion vulnerability via \system\modules\dashboard\controllers\LoginController.php.ibos · ibos · CWE-459 | Critical9.1 | — | 0.5% | Nov 1, 2024 |
36Monitor | CVE-2026-85043No exploit | Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via cragoogle · chrome · CWE-459 | Critical9.1 | — | 0.4% | Sep 3, 2026 |
36Monitor | CVE-2025-6338No exploit | Possible denial of service with multiple incoming connections to a Schannel based server with a TLS backendqt · qt · CWE-459 | Critical9.2 | — | 0.4% | Oct 16, 2025 |
36Monitor | CVE-2026-15390No exploit | Out-of-bounds write in Das U-Bootdenx software engineering · das u-boot · CWE-459 | Critical9.0 | — | 0.3% | 2 days ago |
35Monitor | CVE-2020-24489No exploit | Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local acintel · atom x5-e3930 · CWE-459 | High8.8 | — | 0.4% | Jun 9, 2021 |
34Monitor | CVE-2026-3304Proof of concept | Multer vulnerable to Denial of Service via incomplete cleanupexpressjs · multer · CWE-459 | High8.7 | — | 0.9% | Feb 27, 2026 |
34Monitor | CVE-2026-52736No exploit | ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cachezcashfoundation · zebra · CWE-459 | High8.7 | — | 0.6% | Aug 18, 2026 |
34Monitor | CVE-2025-21609No exploit | SiYuan has an arbitrary file deletion vulnerabilityb3log · siyuan · CWE-459 | High8.7 | — | 0.6% | Jan 3, 2025 |
34Monitor | CVE-2025-59781No exploit | BIG-IP DNS cache vulnerabilityf5 · big-ip access policy manager · CWE-459 | High8.7 | — | 0.3% | Oct 15, 2025 |
- CVE-2017-1709055Plan
An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified As
HighCVSS 7.5Proof of conceptEPSS 82%digium · certified asteriskDec 1, 2017
- CVE-2025-3165048Plan
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
HighCVSS 7.5Proof of conceptEPSS 61%apache · tomcatApr 28, 2025
- CVE-2022-155240Plan
A flaw was found in PostgreSQL.
HighCVSS 8.8No exploitEPSS 16%postgresql · postgresqlAug 31, 2022
- CVE-2020-1345140Plan
An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice co
CriticalCVSS 9.8No exploitEPSS 3%thecodingmachine · gotenbergJan 7, 2021
- CVE-2005-174440Plan
BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows t
CriticalCVSS 9.8No exploitEPSS 2%bea · weblogic serverMay 24, 2005
- CVE-2021-4533039Monitor
An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and t
CriticalCVSS 9.8No exploitEPSS 1%gitea · giteaFeb 9, 2022
- CVE-2022-4534739Monitor
Apache ShardingSphere-Proxy: MySQL authentication bypass
CriticalCVSS 9.8No exploitEPSS 1%apache · shardingsphereDec 22, 2022
- CVE-2021-3292839Monitor
The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Manager” that allows i
CriticalCVSS 9.8No exploitEPSS 1%thalesgroup · sentinel ldk run-time environmentJun 16, 2021
- CVE-2021-4570639Monitor
An issue was discovered in the zeroize_derive crate before 1.1.1 for Rust.
CriticalCVSS 9.8No exploitEPSS 1%zeroize derive project · zeroize deriveDec 26, 2021
- CVE-2021-3620539Monitor
Metasys session token
CriticalCVSS 9.8No exploitEPSS 1%johnsoncontrols · metasys application and data serverApr 15, 2022
- CVE-2026-2826839Monitor
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse
CriticalCVSS 9.8No exploitEPSS 1%vikunja · vikunjaFeb 27, 2026
- CVE-2018-1892438Monitor
The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" be
HighCVSS 8.8Proof of conceptEPSS 9%projeqtor · projeqtorNov 4, 2018
- CVE-2026-3426338Monitor
Missing authentication check in SAP Commerce cloud configuration
CriticalCVSS 9.6No exploitEPSS 1%sap_se · sap commerce cloud configurationMay 11, 2026
- CVE-2019-2501636Monitor
In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed
HighCVSS 8.8No exploitEPSS 3%opendoas project · opendoasJan 28, 2021
- CVE-2019-1819136Monitor
A privilege escalation vulnerability in the Trend Micro Deep Security as a Service Quick Setup cloud formation template could allow an authe
HighCVSS 8.8No exploitEPSS 2%trendmicro · deep security as a serviceDec 16, 2019
- CVE-2023-3646836Monitor
Upgrading doesn't prevent exploiting vulnerable XWiki documents
HighCVSS 8.8No exploitEPSS 2%xwiki · xwikiJun 29, 2023
- CVE-2024-2826536Monitor
IBOS v4.5.5 has an arbitrary file deletion vulnerability via \system\modules\dashboard\controllers\LoginController.php.
CriticalCVSS 9.1No exploitEPSS 0%ibos · ibosNov 1, 2024
- CVE-2026-8504336Monitor
Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via cra
CriticalCVSS 9.1No exploitEPSS 0%google · chromeSep 3, 2026
- CVE-2025-633836Monitor
Possible denial of service with multiple incoming connections to a Schannel based server with a TLS backend
CriticalCVSS 9.2No exploitEPSS 0%qt · qtOct 16, 2025
- CVE-2026-1539036Monitor
Out-of-bounds write in Das U-Boot
CriticalCVSS 9.0No exploitEPSS 0%denx software engineering · das u-boot2 days ago
- CVE-2020-2448935Monitor
Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local ac
HighCVSS 8.8No exploitEPSS 0%intel · atom x5-e3930Jun 9, 2021
- CVE-2026-330434Monitor
Multer vulnerable to Denial of Service via incomplete cleanup
HighCVSS 8.7Proof of conceptEPSS 1%expressjs · multerFeb 27, 2026
- CVE-2026-5273634Monitor
ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cache
HighCVSS 8.7No exploitEPSS 1%zcashfoundation · zebraAug 18, 2026
- CVE-2025-2160934Monitor
SiYuan has an arbitrary file deletion vulnerability
HighCVSS 8.7No exploitEPSS 1%b3log · siyuanJan 3, 2025
- CVE-2025-5978134Monitor
BIG-IP DNS cache vulnerability
HighCVSS 8.7No exploitEPSS 0%f5 · big-ip access policy managerOct 15, 2025