CWE-402 · 24 записей
Transmission of Private Resources into a New Sphere ('Resource Leak')
CVE этого класса
24 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2021-23264Эксплойта нет | Transmission of Private Resources into a New Sphere ('Resource Leak') and Exposure of Resource to Wrong Sphere in Crafter Searchcraftercms · crafter cms · CWE-402 | Критическая9,1 | — | 1,2 % | 2 дек. 2021 г. |
34Наблюдать | CVE-2025-29925Proof of concept | XWiki allows unregistered users to access private pages information through REST endpointxwiki · xwiki · CWE-402 | Высокая8,7 | — | 0,9 % | 19 мар. 2025 г. |
34Наблюдать | GHSA-j9wr-49vq-rm5gЭксплойта нет | Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19Maven · com.vaadin:vaadin-bom · CWE-402 | Высокая8,6 | — | — | 19 апр. 2021 г. |
32Наблюдать | CVE-2025-48383Эксплойта нет | Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leakingcodingjoe · django-select2 · CWE-402 | Высокая8,2 | — | 0,3 % | 27 мая 2025 г. |
32Наблюдать | CVE-2025-32360Эксплойта нет | In Zammad 6.4.x before 6.4.2, there is information exposure.zammad · zammad · CWE-402 | Высокая8,1 | — | 0,2 % | 5 апр. 2025 г. |
31Наблюдать | CVE-2021-31407Эксплойта нет | Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19vaadin · flow · CWE-402 | Высокая7,5 | — | 2,4 % | 23 апр. 2021 г. |
31Наблюдать | CVE-2021-23263Эксплойта нет | Transmission of Private Resources into a New Sphere ('Resource Leak') in Crafter Enginecraftercms · crafter cms · CWE-402 | Высокая7,5 | — | 1,7 % | 2 дек. 2021 г. |
31Наблюдать | CVE-2021-31410Эксплойта нет | Project sources exposure in Vaadin Designervaadin · designer · CWE-402 | Высокая7,5 | — | 1,7 % | 23 апр. 2021 г. |
30Наблюдать | CVE-2022-3596Эксплойта нет | Instack-undercloud: rsync leaks information to undercloudredhat · openstack platform · CWE-402 | Высокая7,5 | — | 1,1 % | 20 сент. 2023 г. |
30Наблюдать | CVE-2023-34467Эксплойта нет | XWiki Platform may retrieve email addresses of all usersxwiki · xwiki · CWE-402 | Высокая7,5 | — | 1,0 % | 23 июн. 2023 г. |
30Наблюдать | CVE-2024-29900Эксплойта нет | @electron/packager's build process memory potentially leaked into final executableopenjsf · packager · CWE-402 | Высокая7,5 | — | 0,6 % | 29 мар. 2024 г. |
30Наблюдать | CVE-2025-67745Эксплойта нет | Myhoard logs backup encryption key in plain textaiven · myhoard · CWE-402 | Высокая7,5 | — | 0,2 % | 18 дек. 2025 г. |
28Наблюдать | CVE-2024-47146Эксплойта нет | Ruijie Reyee OS Resource Leakruijienetworks · reyee os · CWE-402 | Высокая7,1 | — | 0,3 % | 6 дек. 2024 г. |
27Наблюдать | CVE-2022-30231Эксплойта нет | A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6).siemens · sicam gridedge essential · CWE-402 | Средняя6,9 | — | 0,6 % | 14 июн. 2022 г. |
27Наблюдать | CVE-2025-0502Эксплойта нет | Transmission of Private Resources into a New Sphere in Crafter Enginecraftercms · craftercms · CWE-402 | Средняя6,9 | — | 0,4 % | 15 янв. 2025 г. |
26Наблюдать | CVE-2017-8442Эксплойта нет | Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configuratelastic · x-pack · CWE-402 | Средняя6,5 | — | 0,9 % | 7 июл. 2017 г. |
23Наблюдать | CVE-2025-49618Эксплойта нет | In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint.plesk · obsidian · CWE-402 | Средняя5,8 | — | 0,4 % | 3 июл. 2025 г. |
22Наблюдать | CVE-2023-4569Эксплойта нет | Kernel: information leak in nft_set_catchall_flush in net/netfilter/nf_tables_api.clinux · linux kernel · CWE-402 | Средняя5,5 | — | 0,3 % | 28 авг. 2023 г. |
22Наблюдать | CVE-2024-0443Эксплойта нет | Kernel: blkio memory leakage due to blkcg and some blkgs are not freed after they are made offline.linux · linux kernel · CWE-402 | Средняя5,5 | — | 0,2 % | 11 янв. 2024 г. |
21Наблюдать | CVE-2024-32388Эксплойта нет | Due to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP packets.kerlink · keros · CWE-402 | Средняя5,3 | — | 1,2 % | 1 дек. 2025 г. |
20Наблюдать | CVE-2025-52925Эксплойта нет | In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812.onelogin · active directory connector · CWE-402 | Средняя5,0 | — | 0,2 % | 2 июл. 2025 г. |
18Наблюдать | CVE-2025-55014Эксплойта нет | The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dstardict · stardict · CWE-402 | Средняя4,7 | — | 0,4 % | 4 авг. 2025 г. |
17Наблюдать | CVE-2023-38509Эксплойта нет | XWiki Platform's obfuscated email addresses should not be sortedxwiki · xwiki · CWE-402 | Средняя4,3 | — | 0,8 % | 7 нояб. 2023 г. |
17Наблюдать | CVE-2025-66422Эксплойта нет | Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information.tryton · trytond · CWE-402 | Средняя4,3 | — | 0,3 % | 29 нояб. 2025 г. |
- CVE-2021-2326436Наблюдать
Transmission of Private Resources into a New Sphere ('Resource Leak') and Exposure of Resource to Wrong Sphere in Crafter Search
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %craftercms · crafter cms2 дек. 2021 г.
- CVE-2025-2992534Наблюдать
XWiki allows unregistered users to access private pages information through REST endpoint
ВысокаяCVSS 8,7Proof of conceptEPSS 1 %xwiki · xwiki19 мар. 2025 г.
- GHSA-j9wr-49vq-rm5g34Наблюдать
Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19
ВысокаяCVSS 8,6Эксплойта нетMaven · com.vaadin:vaadin-bom19 апр. 2021 г.
- CVE-2025-4838332Наблюдать
Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %codingjoe · django-select227 мая 2025 г.
- CVE-2025-3236032Наблюдать
In Zammad 6.4.x before 6.4.2, there is information exposure.
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %zammad · zammad5 апр. 2025 г.
- CVE-2021-3140731Наблюдать
Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %vaadin · flow23 апр. 2021 г.
- CVE-2021-2326331Наблюдать
Transmission of Private Resources into a New Sphere ('Resource Leak') in Crafter Engine
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %craftercms · crafter cms2 дек. 2021 г.
- CVE-2021-3141031Наблюдать
Project sources exposure in Vaadin Designer
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %vaadin · designer23 апр. 2021 г.
- CVE-2022-359630Наблюдать
Instack-undercloud: rsync leaks information to undercloud
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %redhat · openstack platform20 сент. 2023 г.
- CVE-2023-3446730Наблюдать
XWiki Platform may retrieve email addresses of all users
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %xwiki · xwiki23 июн. 2023 г.
- CVE-2024-2990030Наблюдать
@electron/packager's build process memory potentially leaked into final executable
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openjsf · packager29 мар. 2024 г.
- CVE-2025-6774530Наблюдать
Myhoard logs backup encryption key in plain text
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %aiven · myhoard18 дек. 2025 г.
- CVE-2024-4714628Наблюдать
Ruijie Reyee OS Resource Leak
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %ruijienetworks · reyee os6 дек. 2024 г.
- CVE-2022-3023127Наблюдать
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6).
СредняяCVSS 6,9Эксплойта нетEPSS 1 %siemens · sicam gridedge essential14 июн. 2022 г.
- CVE-2025-050227Наблюдать
Transmission of Private Resources into a New Sphere in Crafter Engine
СредняяCVSS 6,9Эксплойта нетEPSS 0 %craftercms · craftercms15 янв. 2025 г.
- CVE-2017-844226Наблюдать
Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configurat
СредняяCVSS 6,5Эксплойта нетEPSS 1 %elastic · x-pack7 июл. 2017 г.
- CVE-2025-4961823Наблюдать
In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint.
СредняяCVSS 5,8Эксплойта нетEPSS 0 %plesk · obsidian3 июл. 2025 г.
- CVE-2023-456922Наблюдать
Kernel: information leak in nft_set_catchall_flush in net/netfilter/nf_tables_api.c
СредняяCVSS 5,5Эксплойта нетEPSS 0 %linux · linux kernel28 авг. 2023 г.
- CVE-2024-044322Наблюдать
Kernel: blkio memory leakage due to blkcg and some blkgs are not freed after they are made offline.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %linux · linux kernel11 янв. 2024 г.
- CVE-2024-3238821Наблюдать
Due to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP packets.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %kerlink · keros1 дек. 2025 г.
- CVE-2025-5292520Наблюдать
In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812.
СредняяCVSS 5,0Эксплойта нетEPSS 0 %onelogin · active directory connector2 июл. 2025 г.
- CVE-2025-5501418Наблюдать
The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the d
СредняяCVSS 4,7Эксплойта нетEPSS 0 %stardict · stardict4 авг. 2025 г.
- CVE-2023-3850917Наблюдать
XWiki Platform's obfuscated email addresses should not be sorted
СредняяCVSS 4,3Эксплойта нетEPSS 1 %xwiki · xwiki7 нояб. 2023 г.
- CVE-2025-6642217Наблюдать
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information.
СредняяCVSS 4,3Эксплойта нетEPSS 0 %tryton · trytond29 нояб. 2025 г.