Skip to content
Noroxi

CWE-672 · 71 records

Operation on a Resource after Expiration or Release

CVEs in this class

71 records

  • In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce

    CriticalCVSS 9.4Proof of conceptEPSS 11%

    eclipse · jettyJul 9, 2020

  • ForLogic Qualiex v1 and v3 has weak token expiration.

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    forlogic · qualiexSep 2, 2020

  • The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the W

    CriticalCVSS 9.8No exploitEPSS 2%

    baxter · sigma spectrum infusion system firmwareJun 29, 2020

  • An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper acc

    CriticalCVSS 9.8No exploitEPSS 1%

    fortinet · fortimanagerJan 14, 2025

  • Password reset links invalidation issue in WordPress

    HighCVSS 8.1Proof of conceptEPSS 14%

    wordpress · wordpressApr 30, 2020

  • OpenClaw < 2026.4.15 - Bearer Token Validation Bypass via Stale SecretRef Resolution

    CriticalCVSS 9.2No exploitEPSS 1%

    openclaw · openclawMay 6, 2026

  • Apache::Session versions through 1.94 for Perl re-creates deleted sessions

    CriticalCVSS 9.1No exploitEPSS 0%

    chorny · apache\May 8, 2026

  • When Responsive Design Mode was enabled, it used references to objects that were previously freed.

    HighCVSS 8.8No exploitEPSS 1%

    mozilla · firefoxJun 24, 2021

  • By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScript (within th

    HighCVSS 8.8No exploitEPSS 1%

    mozilla · firefoxDec 22, 2022

  • BIG-IP HTTP/2 vulnerability

    HighCVSS 8.7No exploitEPSS 0%

    f5 · big-ip application security managerOct 15, 2025

  • Parse Server MFA recovery codes not consumed after use

    HighCVSS 8.2No exploitEPSS 1%

    parseplatform · parse-serverMar 11, 2026

  • CVE-2026-2379
    32Monitor

    Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is Disabled

    HighCVSS 8.2No exploitEPSS 0%

    arista networks · eosJun 5, 2026

  • Duplicate Advisory: OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation

    HighCVSS 8.1No exploit

    npm · openclawMay 6, 2026

  • A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC Drive Controller family (All version

    HighCVSS 7.5No exploitEPSS 2%

    siemens · simatic drive controller cpu 1504d tf firmwareFeb 9, 2022

  • A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller C

    HighCVSS 7.5No exploitEPSS 2%

    siemens · simatic drive controller cpu 1504d tf firmwareFeb 9, 2022

  • Reference count underflow in shiftfs

    HighCVSS 7.8Proof of conceptEPSS 1%

    linux · linux kernelApr 23, 2020

  • CVE-2017-0544
    31Monitor

    An elevation of privilege vulnerability in CameraBase could enable a local malicious application to execute arbitrary code.

    HighCVSS 7.8No exploitEPSS 1%

    google · androidApr 7, 2017

  • get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counti

    HighCVSS 7.8No exploitEPSS 1%

    linux · linux kernelSep 10, 2020

  • x86/AMD: missing IOMMU TLB flushing

    HighCVSS 7.8No exploitEPSS 0%

    xen · xenJan 5, 2024

  • In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, after a subsystem reset, iwp

    HighCVSS 7.8No exploitEPSS 0%

    google · androidDec 5, 2017

  • Junos OS and Junos OS Evolved: An rpd core will be observed with proxy BGP route-target filtering enabled and certain route add and delete event happening

    HighCVSS 7.5No exploitEPSS 1%

    juniper · junos os evolvedApr 14, 2022

  • An issue was discovered in MaraDNS Deadwood through 3.5.0021 that allows variant V1 of unintended domain name resolution.

    HighCVSS 7.5No exploitEPSS 1%

    maradns · maradnsNov 18, 2022

  • IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for th

    HighCVSS 7.5No exploitEPSS 1%

    ibm · partner engagement managerApr 1, 2022

  • Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider

    HighCVSS 7.5No exploitEPSS 1%

    apache · cxfAug 6, 2026

  • Incorrect removal of permissions on PCI device unplug

    HighCVSS 7.5No exploitEPSS 0%

    xen · xenOct 31, 2025

All vulnerability classes