CWE-460 · 25 records
Improper Cleanup on Thrown Exception
CVEs in this class
25 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2022-22150No exploit | A memory corruption vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.1.0.52543.foxit · pdf reader · CWE-460 | High8.8 | — | 1.8% | Feb 4, 2022 |
35Monitor | CVE-2026-40583No exploit | UltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Haltultradag · ultradag · CWE-460 | High8.8 | — | 0.6% | Apr 21, 2026 |
31Monitor | CVE-2022-4744No exploit | A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the device when the register_linux · linux kernel · CWE-460 | High7.8 | — | 0.5% | Mar 30, 2023 |
30Monitor | CVE-2026-93710No exploit | Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooksCWE-460 | High7.5 | — | 0.6% | Sep 21, 2026 |
30Monitor | CVE-2023-46393No exploit | gougucms v4.08.18 was discovered to contain a password reset poisoning vulnerability which allows attackers to arbitrarily reset users' passgougucms · gougucms · CWE-460 | High7.5 | — | 0.4% | Oct 27, 2023 |
30Monitor | CVE-2025-30157No exploit | Envoy crashes when HTTP ext_proc processes local repliesenvoyproxy · envoy · CWE-460 | High7.5 | — | 0.4% | Mar 21, 2025 |
30Monitor | CVE-2024-0316No exploit | Improper cleanup vulnerability in FireEye Endpoint Securityfireeye · endpoint security · CWE-460 | High7.5 | — | 0.3% | Jan 15, 2024 |
29Monitor | CVE-2021-34716No exploit | Cisco Expressway Series and TelePresence Video Communication Server Remote Code Execution Vulnerabilitycisco · expressway · CWE-460 | High7.2 | — | 2.4% | Aug 18, 2021 |
29Monitor | CVE-2024-20354No exploit | A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjcisco · wireless lan controller software · CWE-460 | High7.4 | — | 0.3% | Mar 27, 2024 |
27Monitor | CVE-2026-86748No exploit | Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archivesnipeitapp · snipe-it · CWE-460 | Medium6.9 | — | 0.4% | Sep 9, 2026 |
27Monitor | CVE-2026-20118No exploit | Cisco IOS-XR NCS 5500 and NCS 5700 Egress Packet Network Interfaces Aligner Interrupt Denial of Service Vulnerabilitycisco · cisco ios xr software · CWE-460 | Medium6.8 | — | 0.3% | Mar 11, 2026 |
27Monitor | CVE-2026-96273No exploit | Ghidra before 12.1.4 Denial of Service via Unreleased Lock in OptionsDBnationalsecurityagency · ghidra · CWE-460 | Medium6.8 | — | 0.1% | Sep 23, 2026 |
26Monitor | CVE-2017-9657No exploit | Under specific 802.11 network conditions, a partial re-association of the Philips IntelliVue MX40 Version B.06.18 WLAN monitor to the centraphilips · intellivue mx40 firmware · CWE-460 | Medium6.5 | — | 0.8% | Apr 30, 2018 |
26Monitor | CVE-2025-32439No exploit | pleezer allows resource exhaustion through uncollected hook script processesroderickvd · pleezer · CWE-460 | Medium6.5 | — | 0.4% | Apr 15, 2025 |
24Monitor | CVE-2025-69652No exploit | GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformedgnu · binutils · CWE-460 | Medium6.2 | — | 0.2% | Mar 6, 2026 |
23Monitor | CVE-2024-12289No exploit | Boundary Controller Incorrectly Handles HTTP Requests On Initialization Which May Lead to a Denial of Servicehashicorp · boundary · CWE-460 | Medium5.9 | — | 0.4% | Dec 12, 2024 |
22Monitor | CVE-2017-15127No exploit | A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13.linux · linux kernel · CWE-460 | Medium5.5 | — | 0.4% | Jan 14, 2018 |
22Monitor | CVE-2022-3707No exploit | A double-free memory flaw was found in the Linux kernel.linux · linux kernel · CWE-460 | Medium5.5 | — | 0.2% | Mar 6, 2023 |
21Monitor | CVE-2026-33481No exploit | Syft improper temporary file cleanupanchore · syft · CWE-460 | Medium5.3 | — | 0.5% | Mar 26, 2026 |
20Monitor | CVE-2019-14891No exploit | A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup.kubernetes · cri-o · CWE-460 | Medium5.0 | — | 0.8% | Nov 25, 2019 |
17Monitor | CVE-2016-9592No exploit | openshift before versions 3.3.1.11, 3.2.1.23, 3.4 is vulnerable to a flaw when a volume fails to detach, which causes the delete operation tredhat · openshift · CWE-460 | Medium4.3 | — | 1.2% | Apr 16, 2018 |
17Monitor | CVE-2020-14304No exploit | A memory disclosure flaw was found in the Linux kernel's ethernet drivers, in the way it read data from the EEPROM of the device.linux · linux kernel · CWE-460 | Medium4.4 | — | 0.4% | Sep 15, 2020 |
14Monitor | CVE-2026-48524No exploit | PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)pyjwt project · pyjwt · CWE-460 | Low3.7 | — | 0.3% | May 28, 2026 |
12Monitor | CVE-2025-59399No exploit | libocpp before 0.28.0 allows a denial of service (EVerest crash) because a secondary exception is thrown during error message generation.everest · libocpp · CWE-460 | Low3.1 | — | 0.2% | Sep 15, 2025 |
9Monitor | CVE-2022-3301No exploit | Improper Cleanup on Thrown Exception in ikus060/rdiffwebikus-soft · rdiffweb · CWE-460 | Low2.4 | — | 0.7% | Sep 26, 2022 |
- CVE-2022-2215036Monitor
A memory corruption vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.1.0.52543.
HighCVSS 8.8No exploitEPSS 2%foxit · pdf readerFeb 4, 2022
- CVE-2026-4058335Monitor
UltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Halt
HighCVSS 8.8No exploitEPSS 1%ultradag · ultradagApr 21, 2026
- CVE-2022-474431Monitor
A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the device when the register_
HighCVSS 7.8No exploitEPSS 0%linux · linux kernelMar 30, 2023
- CVE-2026-9371030Monitor
Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks
HighCVSS 7.5No exploitEPSS 1%Sep 21, 2026
- CVE-2023-4639330Monitor
gougucms v4.08.18 was discovered to contain a password reset poisoning vulnerability which allows attackers to arbitrarily reset users' pass
HighCVSS 7.5No exploitEPSS 0%gougucms · gougucmsOct 27, 2023
- CVE-2025-3015730Monitor
Envoy crashes when HTTP ext_proc processes local replies
HighCVSS 7.5No exploitEPSS 0%envoyproxy · envoyMar 21, 2025
- CVE-2024-031630Monitor
Improper cleanup vulnerability in FireEye Endpoint Security
HighCVSS 7.5No exploitEPSS 0%fireeye · endpoint securityJan 15, 2024
- CVE-2021-3471629Monitor
Cisco Expressway Series and TelePresence Video Communication Server Remote Code Execution Vulnerability
HighCVSS 7.2No exploitEPSS 2%cisco · expresswayAug 18, 2021
- CVE-2024-2035429Monitor
A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adj
HighCVSS 7.4No exploitEPSS 0%cisco · wireless lan controller softwareMar 27, 2024
- CVE-2026-8674827Monitor
Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archive
MediumCVSS 6.9No exploitEPSS 0%snipeitapp · snipe-itSep 9, 2026
- CVE-2026-2011827Monitor
Cisco IOS-XR NCS 5500 and NCS 5700 Egress Packet Network Interfaces Aligner Interrupt Denial of Service Vulnerability
MediumCVSS 6.8No exploitEPSS 0%cisco · cisco ios xr softwareMar 11, 2026
- CVE-2026-9627327Monitor
Ghidra before 12.1.4 Denial of Service via Unreleased Lock in OptionsDB
MediumCVSS 6.8No exploitEPSS 0%nationalsecurityagency · ghidraSep 23, 2026
- CVE-2017-965726Monitor
Under specific 802.11 network conditions, a partial re-association of the Philips IntelliVue MX40 Version B.06.18 WLAN monitor to the centra
MediumCVSS 6.5No exploitEPSS 1%philips · intellivue mx40 firmwareApr 30, 2018
- CVE-2025-3243926Monitor
pleezer allows resource exhaustion through uncollected hook script processes
MediumCVSS 6.5No exploitEPSS 0%roderickvd · pleezerApr 15, 2025
- CVE-2025-6965224Monitor
GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed
MediumCVSS 6.2No exploitEPSS 0%gnu · binutilsMar 6, 2026
- CVE-2024-1228923Monitor
Boundary Controller Incorrectly Handles HTTP Requests On Initialization Which May Lead to a Denial of Service
MediumCVSS 5.9No exploitEPSS 0%hashicorp · boundaryDec 12, 2024
- CVE-2017-1512722Monitor
A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13.
MediumCVSS 5.5No exploitEPSS 0%linux · linux kernelJan 14, 2018
- CVE-2022-370722Monitor
A double-free memory flaw was found in the Linux kernel.
MediumCVSS 5.5No exploitEPSS 0%linux · linux kernelMar 6, 2023
- CVE-2026-3348121Monitor
Syft improper temporary file cleanup
MediumCVSS 5.3No exploitEPSS 1%anchore · syftMar 26, 2026
- CVE-2019-1489120Monitor
A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup.
MediumCVSS 5.0No exploitEPSS 1%kubernetes · cri-oNov 25, 2019
- CVE-2016-959217Monitor
openshift before versions 3.3.1.11, 3.2.1.23, 3.4 is vulnerable to a flaw when a volume fails to detach, which causes the delete operation t
MediumCVSS 4.3No exploitEPSS 1%redhat · openshiftApr 16, 2018
- CVE-2020-1430417Monitor
A memory disclosure flaw was found in the Linux kernel's ethernet drivers, in the way it read data from the EEPROM of the device.
MediumCVSS 4.4No exploitEPSS 0%linux · linux kernelSep 15, 2020
- CVE-2026-4852414Monitor
PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
LowCVSS 3.7No exploitEPSS 0%pyjwt project · pyjwtMay 28, 2026
- CVE-2025-5939912Monitor
libocpp before 0.28.0 allows a denial of service (EVerest crash) because a secondary exception is thrown during error message generation.
LowCVSS 3.1No exploitEPSS 0%everest · libocppSep 15, 2025
- CVE-2022-33019Monitor
Improper Cleanup on Thrown Exception in ikus060/rdiffweb
LowCVSS 2.4No exploitEPSS 1%ikus-soft · rdiffwebSep 26, 2022