Skip to content
Noroxi

CWE-459 · 205 records

Incomplete Cleanup

CVEs in this class

205 records

  • An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified As

    HighCVSS 7.5Proof of conceptEPSS 82%

    digium · certified asteriskDec 1, 2017

  • Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame

    HighCVSS 7.5Proof of conceptEPSS 61%

    apache · tomcatApr 28, 2025

  • A flaw was found in PostgreSQL.

    HighCVSS 8.8No exploitEPSS 16%

    postgresql · postgresqlAug 31, 2022

  • An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice co

    CriticalCVSS 9.8No exploitEPSS 3%

    thecodingmachine · gotenbergJan 7, 2021

  • BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows t

    CriticalCVSS 9.8No exploitEPSS 2%

    bea · weblogic serverMay 24, 2005

  • An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and t

    CriticalCVSS 9.8No exploitEPSS 1%

    gitea · giteaFeb 9, 2022

  • Apache ShardingSphere-Proxy: MySQL authentication bypass

    CriticalCVSS 9.8No exploitEPSS 1%

    apache · shardingsphereDec 22, 2022

  • The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Manager” that allows i

    CriticalCVSS 9.8No exploitEPSS 1%

    thalesgroup · sentinel ldk run-time environmentJun 16, 2021

  • An issue was discovered in the zeroize_derive crate before 1.1.1 for Rust.

    CriticalCVSS 9.8No exploitEPSS 1%

    zeroize derive project · zeroize deriveDec 26, 2021

  • Metasys session token

    CriticalCVSS 9.8No exploitEPSS 1%

    johnsoncontrols · metasys application and data serverApr 15, 2022

  • Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse

    CriticalCVSS 9.8No exploitEPSS 1%

    vikunja · vikunjaFeb 27, 2026

  • The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" be

    HighCVSS 8.8Proof of conceptEPSS 9%

    projeqtor · projeqtorNov 4, 2018

  • Missing authentication check in SAP Commerce cloud configuration

    CriticalCVSS 9.6No exploitEPSS 1%

    sap_se · sap commerce cloud configurationMay 11, 2026

  • In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed

    HighCVSS 8.8No exploitEPSS 3%

    opendoas project · opendoasJan 28, 2021

  • A privilege escalation vulnerability in the Trend Micro Deep Security as a Service Quick Setup cloud formation template could allow an authe

    HighCVSS 8.8No exploitEPSS 2%

    trendmicro · deep security as a serviceDec 16, 2019

  • Upgrading doesn't prevent exploiting vulnerable XWiki documents

    HighCVSS 8.8No exploitEPSS 2%

    xwiki · xwikiJun 29, 2023

  • IBOS v4.5.5 has an arbitrary file deletion vulnerability via \system\modules\dashboard\controllers\LoginController.php.

    CriticalCVSS 9.1No exploitEPSS 0%

    ibos · ibosNov 1, 2024

  • Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via cra

    CriticalCVSS 9.1No exploitEPSS 0%

    google · chromeSep 3, 2026

  • CVE-2025-6338
    36Monitor

    Possible denial of service with multiple incoming connections to a Schannel based server with a TLS backend

    CriticalCVSS 9.2No exploitEPSS 0%

    qt · qtOct 16, 2025

  • Out-of-bounds write in Das U-Boot

    CriticalCVSS 9.0No exploitEPSS 0%

    denx software engineering · das u-boot2 days ago

  • Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local ac

    HighCVSS 8.8No exploitEPSS 0%

    intel · atom x5-e3930Jun 9, 2021

  • CVE-2026-3304
    34Monitor

    Multer vulnerable to Denial of Service via incomplete cleanup

    HighCVSS 8.7Proof of conceptEPSS 1%

    expressjs · multerFeb 27, 2026

  • ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cache

    HighCVSS 8.7No exploitEPSS 1%

    zcashfoundation · zebraAug 18, 2026

  • SiYuan has an arbitrary file deletion vulnerability

    HighCVSS 8.7No exploitEPSS 1%

    b3log · siyuanJan 3, 2025

  • BIG-IP DNS cache vulnerability

    HighCVSS 8.7No exploitEPSS 0%

    f5 · big-ip access policy managerOct 15, 2025

All vulnerability classes