CWE-226 · 36 записей
Sensitive Information in Resource Not Removed Before Reuse
CVE этого класса
36 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2026-74791Эксплойта нет | Scriban before 7.0.0 Authorization Bypass via Stale Include Cachescriban · scriban · CWE-226 | Критическая9,2 | — | 0,4 % | 16 авг. 2026 г. |
34Наблюдать | CVE-2022-39393Эксплойта нет | Wasmtime vulnerable to data leakage between instances in the pooling allocatorbytecodealliance · wasmtime · CWE-226 | Высокая8,6 | — | 0,7 % | 10 нояб. 2022 г. |
34Наблюдать | CVE-2019-25560Эксплойта нет | Lyric Video Creator 2.1 Denial of Service via MP3 Filelyricvideocreator · lyric video creator · CWE-226 | Высокая8,7 | — | 0,5 % | 21 мар. 2026 г. |
33Наблюдать | CVE-2024-21850Эксплойта нет | Sensitive information in resource not removed before reuse in some Intel(R) TDX Seamldr module software before version 1.5.02.00 may allow aCWE-226 | Высокая8,3 | — | 0,2 % | 13 нояб. 2024 г. |
32Наблюдать | CVE-2026-13585Proof of concept | Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Contasus · system control interface v3 · CWE-226 | Высокая8,2 | — | 0,2 % | 14 июл. 2026 г. |
31Наблюдать | CVE-2018-7166Эксплойта нет | In all versions of Node.js 10 prior to 10.9.0, an argument processing flaw can cause `Buffer.alloc()` to return uninitialized memory.nodejs · node.js · CWE-226 | Высокая7,5 | — | 2,8 % | 21 авг. 2018 г. |
31Наблюдать | CVE-2025-0647Эксплойта нет | In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to tharm · c1-ultra firmware · CWE-226 | Высокая7,9 | — | 0,2 % | 14 янв. 2026 г. |
30Наблюдать | CVE-2024-38275Эксплойта нет | moodle: HTTP authorization header is preserved between "emulated redirects"moodle · moodle · CWE-226 | Высокая7,5 | — | 0,4 % | 18 июн. 2024 г. |
30Наблюдать | CVE-2025-13108Эксплойта нет | Fixes to common vulnerabilities found in IBM Db2 Merge Backup for Linux, UNIX and Windowsibm · db2 merge backup · CWE-226 | Высокая7,5 | — | 0,2 % | 17 февр. 2026 г. |
30Наблюдать | GHSA-r45x-ghr2-qjxcЭксплойта нет | Duplicate Advisory: `#[zeroize(drop)]` doesn't implement `Drop` for `enum`scrates.io · zeroize_derive · CWE-226 | Высокая7,5 | — | — | 17 июн. 2022 г. |
29Наблюдать | CVE-2026-5795Эксплойта нет | In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable.eclipse · jetty · CWE-226 | Высокая7,4 | — | 0,6 % | 8 апр. 2026 г. |
29Наблюдать | GHSA-gc59-r5jq-98qwЭксплойта нет | Duplicate Advisory: Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variablesMaven · org.eclipse.jetty.ee10:jetty-ee10 · CWE-226 | Высокая7,4 | — | — | 8 апр. 2026 г. |
28Наблюдать | CVE-2026-32960Эксплойта нет | SD-330AC and AMC Manager provided by silex technology, Inc.silextechnology · sd-330ac firmware · CWE-226 | Высокая7,1 | — | 0,5 % | 20 апр. 2026 г. |
27Наблюдать | CVE-2019-25657Эксплойта нет | AnyBurn 4.3 x86 Denial of Service via Image Conversionanyburn · anyburn · CWE-226 | Средняя6,8 | — | 0,2 % | 5 апр. 2026 г. |
27Наблюдать | CVE-2019-25563Эксплойта нет | PCHelpWareV2 1.0.0.5 Denial of Service via SC Creationuvnc · pchelpwarev2 · CWE-226 | Средняя6,9 | — | 0,2 % | 21 мар. 2026 г. |
27Наблюдать | CVE-2019-25571Эксплойта нет | MediaMonkey 4.1.23 Denial of Service via Malformed URLventismedia · mediamonkey · CWE-226 | Средняя6,9 | — | 0,2 % | 21 мар. 2026 г. |
27Наблюдать | CVE-2019-25645Эксплойта нет | WinAVI iPod 3GP MP4 PSP Converter 4.4.2 Denial of Servicewinavi · winavi ipod/3gp/mp4/psp converter · CWE-226 | Средняя6,9 | — | 0,2 % | 24 мар. 2026 г. |
27Наблюдать | CVE-2019-25553Эксплойта нет | CEWE PHOTO IMPORTER 6.4.3 Denial of Service via Malformed Imagecewe · photo importer · CWE-226 | Средняя6,9 | — | 0,2 % | 21 мар. 2026 г. |
27Наблюдать | CVE-2019-25617Эксплойта нет | Ease Audio Converter 5.30 Denial of Service via Audio Cutteraudiotool · ease audio converter · CWE-226 | Средняя6,9 | — | 0,1 % | 22 мар. 2026 г. |
26Наблюдать | CVE-2024-32036Эксплойта нет | SixLabors.ImageSharp vulnerable to data leakagesixlabors · imagesharp · CWE-226 | Средняя6,5 | — | 0,6 % | 15 апр. 2024 г. |
26Наблюдать | CVE-2025-2522Эксплойта нет | Lack of buffer clearing before reuse may result in incorrect system behavior.honeywell · c300 pcnt02 · CWE-226 | Средняя6,5 | — | 0,2 % | 10 июл. 2025 г. |
26Наблюдать | CVE-2023-41138Эксплойта нет | The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user pappsanywhere · appsanywhere client · CWE-226 | Средняя6,7 | — | 0,2 % | 9 нояб. 2023 г. |
25Наблюдать | CVE-2025-11602Эксплойта нет | Untargeted information leak in Bolt protocol handshakeneo4j · enterprise edition · CWE-226 | Средняя6,3 | — | 0,3 % | 31 окт. 2025 г. |
25Наблюдать | CVE-2026-74250Эксплойта нет | In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing topenstack · ironic · CWE-226 | Средняя6,3 | — | 0,3 % | 14 авг. 2026 г. |
22Наблюдать | CVE-2023-3006Эксплойта нет | A known cache speculation vulnerability, known as Branch History Injection (BHI) or Spectre-BHB, becomes actual again for the new hw AmpereOlinux · linux kernel · CWE-226 | Средняя5,5 | — | 0,3 % | 31 мая 2023 г. |
- CVE-2026-7479136Наблюдать
Scriban before 7.0.0 Authorization Bypass via Stale Include Cache
КритическаяCVSS 9,2Эксплойта нетEPSS 0 %scriban · scriban16 авг. 2026 г.
- CVE-2022-3939334Наблюдать
Wasmtime vulnerable to data leakage between instances in the pooling allocator
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %bytecodealliance · wasmtime10 нояб. 2022 г.
- CVE-2019-2556034Наблюдать
Lyric Video Creator 2.1 Denial of Service via MP3 File
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %lyricvideocreator · lyric video creator21 мар. 2026 г.
- CVE-2024-2185033Наблюдать
Sensitive information in resource not removed before reuse in some Intel(R) TDX Seamldr module software before version 1.5.02.00 may allow a
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %13 нояб. 2024 г.
- CVE-2026-1358532Наблюдать
Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Cont
ВысокаяCVSS 8,2Proof of conceptEPSS 0 %asus · system control interface v314 июл. 2026 г.
- CVE-2018-716631Наблюдать
In all versions of Node.js 10 prior to 10.9.0, an argument processing flaw can cause `Buffer.alloc()` to return uninitialized memory.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %nodejs · node.js21 авг. 2018 г.
- CVE-2025-064731Наблюдать
In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to th
ВысокаяCVSS 7,9Эксплойта нетEPSS 0 %arm · c1-ultra firmware14 янв. 2026 г.
- CVE-2024-3827530Наблюдать
moodle: HTTP authorization header is preserved between "emulated redirects"
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %moodle · moodle18 июн. 2024 г.
- CVE-2025-1310830Наблюдать
Fixes to common vulnerabilities found in IBM Db2 Merge Backup for Linux, UNIX and Windows
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %ibm · db2 merge backup17 февр. 2026 г.
- GHSA-r45x-ghr2-qjxc30Наблюдать
Duplicate Advisory: `#[zeroize(drop)]` doesn't implement `Drop` for `enum`s
ВысокаяCVSS 7,5Эксплойта нетcrates.io · zeroize_derive17 июн. 2022 г.
- CVE-2026-579529Наблюдать
In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable.
ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %eclipse · jetty8 апр. 2026 г.
- GHSA-gc59-r5jq-98qw29Наблюдать
Duplicate Advisory: Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variables
ВысокаяCVSS 7,4Эксплойта нетMaven · org.eclipse.jetty.ee10:jetty-ee108 апр. 2026 г.
- CVE-2026-3296028Наблюдать
SD-330AC and AMC Manager provided by silex technology, Inc.
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %silextechnology · sd-330ac firmware20 апр. 2026 г.
- CVE-2019-2565727Наблюдать
AnyBurn 4.3 x86 Denial of Service via Image Conversion
СредняяCVSS 6,8Эксплойта нетEPSS 0 %anyburn · anyburn5 апр. 2026 г.
- CVE-2019-2556327Наблюдать
PCHelpWareV2 1.0.0.5 Denial of Service via SC Creation
СредняяCVSS 6,9Эксплойта нетEPSS 0 %uvnc · pchelpwarev221 мар. 2026 г.
- CVE-2019-2557127Наблюдать
MediaMonkey 4.1.23 Denial of Service via Malformed URL
СредняяCVSS 6,9Эксплойта нетEPSS 0 %ventismedia · mediamonkey21 мар. 2026 г.
- CVE-2019-2564527Наблюдать
WinAVI iPod 3GP MP4 PSP Converter 4.4.2 Denial of Service
СредняяCVSS 6,9Эксплойта нетEPSS 0 %winavi · winavi ipod/3gp/mp4/psp converter24 мар. 2026 г.
- CVE-2019-2555327Наблюдать
CEWE PHOTO IMPORTER 6.4.3 Denial of Service via Malformed Image
СредняяCVSS 6,9Эксплойта нетEPSS 0 %cewe · photo importer21 мар. 2026 г.
- CVE-2019-2561727Наблюдать
Ease Audio Converter 5.30 Denial of Service via Audio Cutter
СредняяCVSS 6,9Эксплойта нетEPSS 0 %audiotool · ease audio converter22 мар. 2026 г.
- CVE-2024-3203626Наблюдать
SixLabors.ImageSharp vulnerable to data leakage
СредняяCVSS 6,5Эксплойта нетEPSS 1 %sixlabors · imagesharp15 апр. 2024 г.
- CVE-2025-252226Наблюдать
Lack of buffer clearing before reuse may result in incorrect system behavior.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %honeywell · c300 pcnt0210 июл. 2025 г.
- CVE-2023-4113826Наблюдать
The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user p
СредняяCVSS 6,7Эксплойта нетEPSS 0 %appsanywhere · appsanywhere client9 нояб. 2023 г.
- CVE-2025-1160225Наблюдать
Untargeted information leak in Bolt protocol handshake
СредняяCVSS 6,3Эксплойта нетEPSS 0 %neo4j · enterprise edition31 окт. 2025 г.
- CVE-2026-7425025Наблюдать
In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing t
СредняяCVSS 6,3Эксплойта нетEPSS 0 %openstack · ironic14 авг. 2026 г.
- CVE-2023-300622Наблюдать
A known cache speculation vulnerability, known as Branch History Injection (BHI) or Spectre-BHB, becomes actual again for the new hw AmpereO
СредняяCVSS 5,5Эксплойта нетEPSS 0 %linux · linux kernel31 мая 2023 г.