CWE-672 · 71 records
Operation on a Resource after Expiration or Release
CVEs in this class
71 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-17638Proof of concept | In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produceeclipse · jetty · CWE-672 | Critical9.4 | — | 11.1% | Jul 9, 2020 |
40Plan | CVE-2020-24030Proof of concept | ForLogic Qualiex v1 and v3 has weak token expiration.forlogic · qualiex · CWE-672 | Critical9.8 | — | 2.7% | Sep 2, 2020 |
40Plan | CVE-2020-12043No exploit | The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the Wbaxter · sigma spectrum infusion system firmware · CWE-672 | Critical9.8 | — | 2.1% | Jun 29, 2020 |
39Monitor | CVE-2024-47571No exploit | An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper accfortinet · fortimanager · CWE-672 | Critical9.8 | — | 0.9% | Jan 14, 2025 |
36Monitor | CVE-2020-11027Proof of concept | Password reset links invalidation issue in WordPresswordpress · wordpress · CWE-672 | High8.1 | — | 13.6% | Apr 30, 2020 |
36Monitor | CVE-2026-43585No exploit | OpenClaw < 2026.4.15 - Bearer Token Validation Bypass via Stale SecretRef Resolutionopenclaw · openclaw · CWE-672 | Critical9.2 | — | 0.8% | May 6, 2026 |
36Monitor | CVE-2013-10075No exploit | Apache::Session versions through 1.94 for Perl re-creates deleted sessionschorny · apache\ · CWE-672 | Critical9.1 | — | 0.4% | May 8, 2026 |
35Monitor | CVE-2021-23995No exploit | When Responsive Design Mode was enabled, it used references to objects that were previously freed.mozilla · firefox · CWE-672 | High8.8 | — | 1.2% | Jun 24, 2021 |
35Monitor | CVE-2022-22755No exploit | By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScript (within thmozilla · firefox · CWE-672 | High8.8 | — | 0.6% | Dec 22, 2022 |
34Monitor | CVE-2025-55669No exploit | BIG-IP HTTP/2 vulnerabilityf5 · big-ip application security manager · CWE-672 | High8.7 | — | 0.4% | Oct 15, 2025 |
32Monitor | CVE-2026-31875No exploit | Parse Server MFA recovery codes not consumed after useparseplatform · parse-server · CWE-672 | High8.2 | — | 0.5% | Mar 11, 2026 |
32Monitor | CVE-2026-2379No exploit | Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is Disabledarista networks · eos · CWE-672 | High8.2 | — | 0.2% | Jun 5, 2026 |
32Monitor | GHSA-m8wm-r5vq-qjpgNo exploit | Duplicate Advisory: OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotationnpm · openclaw · CWE-672 | High8.1 | — | — | May 6, 2026 |
31Monitor | CVE-2021-37204No exploit | A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC Drive Controller family (All versionsiemens · simatic drive controller cpu 1504d tf firmware · CWE-672 | High7.5 | — | 2.2% | Feb 9, 2022 |
31Monitor | CVE-2021-37185No exploit | A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller Csiemens · simatic drive controller cpu 1504d tf firmware · CWE-672 | High7.5 | — | 2.1% | Feb 9, 2022 |
31Monitor | CVE-2019-15791Proof of concept | Reference count underflow in shiftfslinux · linux kernel · CWE-672 | High7.8 | — | 1.3% | Apr 23, 2020 |
31Monitor | CVE-2017-0544No exploit | An elevation of privilege vulnerability in CameraBase could enable a local malicious application to execute arbitrary code.google · android · CWE-672 | High7.8 | — | 0.9% | Apr 7, 2017 |
31Monitor | CVE-2020-25221No exploit | get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference countilinux · linux kernel · CWE-672 | High7.8 | — | 0.7% | Sep 10, 2020 |
31Monitor | CVE-2023-34326No exploit | x86/AMD: missing IOMMU TLB flushingxen · xen · CWE-672 | High7.8 | — | 0.3% | Jan 5, 2024 |
31Monitor | CVE-2017-14895No exploit | In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, after a subsystem reset, iwpgoogle · android · CWE-672 | High7.8 | — | 0.3% | Dec 5, 2017 |
30Monitor | CVE-2022-22197No exploit | Junos OS and Junos OS Evolved: An rpd core will be observed with proxy BGP route-target filtering enabled and certain route add and delete event happeningjuniper · junos os evolved · CWE-672 | High7.5 | — | 1.1% | Apr 14, 2022 |
30Monitor | CVE-2022-30256No exploit | An issue was discovered in MaraDNS Deadwood through 3.5.0021 that allows variant V1 of unintended domain name resolution.maradns · maradns · CWE-672 | High7.5 | — | 1.0% | Nov 18, 2022 |
30Monitor | CVE-2022-22332No exploit | IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for thibm · partner engagement manager · CWE-672 | High7.5 | — | 0.8% | Apr 1, 2022 |
30Monitor | CVE-2026-68481No exploit | Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProviderapache · cxf · CWE-672 | High7.5 | — | 0.7% | Aug 6, 2026 |
30Monitor | CVE-2025-58149No exploit | Incorrect removal of permissions on PCI device unplugxen · xen · CWE-672 | High7.5 | — | 0.4% | Oct 31, 2025 |
- CVE-2019-1763840Plan
In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce
CriticalCVSS 9.4Proof of conceptEPSS 11%eclipse · jettyJul 9, 2020
- CVE-2020-2403040Plan
ForLogic Qualiex v1 and v3 has weak token expiration.
CriticalCVSS 9.8Proof of conceptEPSS 3%forlogic · qualiexSep 2, 2020
- CVE-2020-1204340Plan
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the W
CriticalCVSS 9.8No exploitEPSS 2%baxter · sigma spectrum infusion system firmwareJun 29, 2020
- CVE-2024-4757139Monitor
An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper acc
CriticalCVSS 9.8No exploitEPSS 1%fortinet · fortimanagerJan 14, 2025
- CVE-2020-1102736Monitor
Password reset links invalidation issue in WordPress
HighCVSS 8.1Proof of conceptEPSS 14%wordpress · wordpressApr 30, 2020
- CVE-2026-4358536Monitor
OpenClaw < 2026.4.15 - Bearer Token Validation Bypass via Stale SecretRef Resolution
CriticalCVSS 9.2No exploitEPSS 1%openclaw · openclawMay 6, 2026
- CVE-2013-1007536Monitor
Apache::Session versions through 1.94 for Perl re-creates deleted sessions
CriticalCVSS 9.1No exploitEPSS 0%chorny · apache\May 8, 2026
- CVE-2021-2399535Monitor
When Responsive Design Mode was enabled, it used references to objects that were previously freed.
HighCVSS 8.8No exploitEPSS 1%mozilla · firefoxJun 24, 2021
- CVE-2022-2275535Monitor
By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScript (within th
HighCVSS 8.8No exploitEPSS 1%mozilla · firefoxDec 22, 2022
- CVE-2025-5566934Monitor
BIG-IP HTTP/2 vulnerability
HighCVSS 8.7No exploitEPSS 0%f5 · big-ip application security managerOct 15, 2025
- CVE-2026-3187532Monitor
Parse Server MFA recovery codes not consumed after use
HighCVSS 8.2No exploitEPSS 1%parseplatform · parse-serverMar 11, 2026
- CVE-2026-237932Monitor
Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is Disabled
HighCVSS 8.2No exploitEPSS 0%arista networks · eosJun 5, 2026
- GHSA-m8wm-r5vq-qjpg32Monitor
Duplicate Advisory: OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation
HighCVSS 8.1No exploitnpm · openclawMay 6, 2026
- CVE-2021-3720431Monitor
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC Drive Controller family (All version
HighCVSS 7.5No exploitEPSS 2%siemens · simatic drive controller cpu 1504d tf firmwareFeb 9, 2022
- CVE-2021-3718531Monitor
A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller C
HighCVSS 7.5No exploitEPSS 2%siemens · simatic drive controller cpu 1504d tf firmwareFeb 9, 2022
- CVE-2019-1579131Monitor
Reference count underflow in shiftfs
HighCVSS 7.8Proof of conceptEPSS 1%linux · linux kernelApr 23, 2020
- CVE-2017-054431Monitor
An elevation of privilege vulnerability in CameraBase could enable a local malicious application to execute arbitrary code.
HighCVSS 7.8No exploitEPSS 1%google · androidApr 7, 2017
- CVE-2020-2522131Monitor
get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counti
HighCVSS 7.8No exploitEPSS 1%linux · linux kernelSep 10, 2020
- CVE-2023-3432631Monitor
x86/AMD: missing IOMMU TLB flushing
HighCVSS 7.8No exploitEPSS 0%xen · xenJan 5, 2024
- CVE-2017-1489531Monitor
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, after a subsystem reset, iwp
HighCVSS 7.8No exploitEPSS 0%google · androidDec 5, 2017
- CVE-2022-2219730Monitor
Junos OS and Junos OS Evolved: An rpd core will be observed with proxy BGP route-target filtering enabled and certain route add and delete event happening
HighCVSS 7.5No exploitEPSS 1%juniper · junos os evolvedApr 14, 2022
- CVE-2022-3025630Monitor
An issue was discovered in MaraDNS Deadwood through 3.5.0021 that allows variant V1 of unintended domain name resolution.
HighCVSS 7.5No exploitEPSS 1%maradns · maradnsNov 18, 2022
- CVE-2022-2233230Monitor
IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for th
HighCVSS 7.5No exploitEPSS 1%ibm · partner engagement managerApr 1, 2022
- CVE-2026-6848130Monitor
Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider
HighCVSS 7.5No exploitEPSS 1%apache · cxfAug 6, 2026
- CVE-2025-5814930Monitor
Incorrect removal of permissions on PCI device unplug
HighCVSS 7.5No exploitEPSS 0%xen · xenOct 31, 2025