Перейти к содержимому
Noroxi

CWE-226 · 36 записей

Sensitive Information in Resource Not Removed Before Reuse

CVE этого класса

36 записей

  • CVE-2026-74791
    36Наблюдать

    Scriban before 7.0.0 Authorization Bypass via Stale Include Cache

    КритическаяCVSS 9,2Эксплойта нетEPSS 0 %

    scriban · scriban16 авг. 2026 г.

  • CVE-2022-39393
    34Наблюдать

    Wasmtime vulnerable to data leakage between instances in the pooling allocator

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    bytecodealliance · wasmtime10 нояб. 2022 г.

  • CVE-2019-25560
    34Наблюдать

    Lyric Video Creator 2.1 Denial of Service via MP3 File

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    lyricvideocreator · lyric video creator21 мар. 2026 г.

  • CVE-2024-21850
    33Наблюдать

    Sensitive information in resource not removed before reuse in some Intel(R) TDX Seamldr module software before version 1.5.02.00 may allow a

    ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %

    13 нояб. 2024 г.

  • CVE-2026-13585
    32Наблюдать

    Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Cont

    ВысокаяCVSS 8,2Proof of conceptEPSS 0 %

    asus · system control interface v314 июл. 2026 г.

  • CVE-2018-7166
    31Наблюдать

    In all versions of Node.js 10 prior to 10.9.0, an argument processing flaw can cause `Buffer.alloc()` to return uninitialized memory.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    nodejs · node.js21 авг. 2018 г.

  • CVE-2025-0647
    31Наблюдать

    In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to th

    ВысокаяCVSS 7,9Эксплойта нетEPSS 0 %

    arm · c1-ultra firmware14 янв. 2026 г.

  • CVE-2024-38275
    30Наблюдать

    moodle: HTTP authorization header is preserved between "emulated redirects"

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    moodle · moodle18 июн. 2024 г.

  • CVE-2025-13108
    30Наблюдать

    Fixes to common vulnerabilities found in IBM Db2 Merge Backup for Linux, UNIX and Windows

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    ibm · db2 merge backup17 февр. 2026 г.

  • GHSA-r45x-ghr2-qjxc
    30Наблюдать

    Duplicate Advisory: `#[zeroize(drop)]` doesn't implement `Drop` for `enum`s

    ВысокаяCVSS 7,5Эксплойта нет

    crates.io · zeroize_derive17 июн. 2022 г.

  • CVE-2026-5795
    29Наблюдать

    In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable.

    ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %

    eclipse · jetty8 апр. 2026 г.

  • GHSA-gc59-r5jq-98qw
    29Наблюдать

    Duplicate Advisory: Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variables

    ВысокаяCVSS 7,4Эксплойта нет

    Maven · org.eclipse.jetty.ee10:jetty-ee108 апр. 2026 г.

  • CVE-2026-32960
    28Наблюдать

    SD-330AC and AMC Manager provided by silex technology, Inc.

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    silextechnology · sd-330ac firmware20 апр. 2026 г.

  • CVE-2019-25657
    27Наблюдать

    AnyBurn 4.3 x86 Denial of Service via Image Conversion

    СредняяCVSS 6,8Эксплойта нетEPSS 0 %

    anyburn · anyburn5 апр. 2026 г.

  • CVE-2019-25563
    27Наблюдать

    PCHelpWareV2 1.0.0.5 Denial of Service via SC Creation

    СредняяCVSS 6,9Эксплойта нетEPSS 0 %

    uvnc · pchelpwarev221 мар. 2026 г.

  • CVE-2019-25571
    27Наблюдать

    MediaMonkey 4.1.23 Denial of Service via Malformed URL

    СредняяCVSS 6,9Эксплойта нетEPSS 0 %

    ventismedia · mediamonkey21 мар. 2026 г.

  • CVE-2019-25645
    27Наблюдать

    WinAVI iPod 3GP MP4 PSP Converter 4.4.2 Denial of Service

    СредняяCVSS 6,9Эксплойта нетEPSS 0 %

    winavi · winavi ipod/3gp/mp4/psp converter24 мар. 2026 г.

  • CVE-2019-25553
    27Наблюдать

    CEWE PHOTO IMPORTER 6.4.3 Denial of Service via Malformed Image

    СредняяCVSS 6,9Эксплойта нетEPSS 0 %

    cewe · photo importer21 мар. 2026 г.

  • CVE-2019-25617
    27Наблюдать

    Ease Audio Converter 5.30 Denial of Service via Audio Cutter

    СредняяCVSS 6,9Эксплойта нетEPSS 0 %

    audiotool · ease audio converter22 мар. 2026 г.

  • CVE-2024-32036
    26Наблюдать

    SixLabors.ImageSharp vulnerable to data leakage

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    sixlabors · imagesharp15 апр. 2024 г.

  • CVE-2025-2522
    26Наблюдать

    Lack of buffer clearing before reuse may result in incorrect system behavior.

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    honeywell · c300 pcnt0210 июл. 2025 г.

  • CVE-2023-41138
    26Наблюдать

    The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user p

    СредняяCVSS 6,7Эксплойта нетEPSS 0 %

    appsanywhere · appsanywhere client9 нояб. 2023 г.

  • CVE-2025-11602
    25Наблюдать

    Untargeted information leak in Bolt protocol handshake

    СредняяCVSS 6,3Эксплойта нетEPSS 0 %

    neo4j · enterprise edition31 окт. 2025 г.

  • CVE-2026-74250
    25Наблюдать

    In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing t

    СредняяCVSS 6,3Эксплойта нетEPSS 0 %

    openstack · ironic14 авг. 2026 г.

  • CVE-2023-3006
    22Наблюдать

    A known cache speculation vulnerability, known as Branch History Injection (BHI) or Spectre-BHB, becomes actual again for the new hw AmpereO

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    linux · linux kernel31 мая 2023 г.

Все классы уязвимостей