Перейти к содержимому
Noroxi

CWE-402 · 24 записей

Transmission of Private Resources into a New Sphere ('Resource Leak')

CVE этого класса

24 записей

  • CVE-2021-23264
    36Наблюдать

    Transmission of Private Resources into a New Sphere ('Resource Leak') and Exposure of Resource to Wrong Sphere in Crafter Search

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    craftercms · crafter cms2 дек. 2021 г.

  • CVE-2025-29925
    34Наблюдать

    XWiki allows unregistered users to access private pages information through REST endpoint

    ВысокаяCVSS 8,7Proof of conceptEPSS 1 %

    xwiki · xwiki19 мар. 2025 г.

  • GHSA-j9wr-49vq-rm5g
    34Наблюдать

    Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19

    ВысокаяCVSS 8,6Эксплойта нет

    Maven · com.vaadin:vaadin-bom19 апр. 2021 г.

  • CVE-2025-48383
    32Наблюдать

    Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking

    ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %

    codingjoe · django-select227 мая 2025 г.

  • CVE-2025-32360
    32Наблюдать

    In Zammad 6.4.x before 6.4.2, there is information exposure.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    zammad · zammad5 апр. 2025 г.

  • CVE-2021-31407
    31Наблюдать

    Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    vaadin · flow23 апр. 2021 г.

  • CVE-2021-23263
    31Наблюдать

    Transmission of Private Resources into a New Sphere ('Resource Leak') in Crafter Engine

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    craftercms · crafter cms2 дек. 2021 г.

  • CVE-2021-31410
    31Наблюдать

    Project sources exposure in Vaadin Designer

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    vaadin · designer23 апр. 2021 г.

  • CVE-2022-3596
    30Наблюдать

    Instack-undercloud: rsync leaks information to undercloud

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    redhat · openstack platform20 сент. 2023 г.

  • CVE-2023-34467
    30Наблюдать

    XWiki Platform may retrieve email addresses of all users

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    xwiki · xwiki23 июн. 2023 г.

  • CVE-2024-29900
    30Наблюдать

    @electron/packager's build process memory potentially leaked into final executable

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    openjsf · packager29 мар. 2024 г.

  • CVE-2025-67745
    30Наблюдать

    Myhoard logs backup encryption key in plain text

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    aiven · myhoard18 дек. 2025 г.

  • CVE-2024-47146
    28Наблюдать

    Ruijie Reyee OS Resource Leak

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    ruijienetworks · reyee os6 дек. 2024 г.

  • CVE-2022-30231
    27Наблюдать

    A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6).

    СредняяCVSS 6,9Эксплойта нетEPSS 1 %

    siemens · sicam gridedge essential14 июн. 2022 г.

  • CVE-2025-0502
    27Наблюдать

    Transmission of Private Resources into a New Sphere in Crafter Engine

    СредняяCVSS 6,9Эксплойта нетEPSS 0 %

    craftercms · craftercms15 янв. 2025 г.

  • CVE-2017-8442
    26Наблюдать

    Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configurat

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    elastic · x-pack7 июл. 2017 г.

  • CVE-2025-49618
    23Наблюдать

    In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint.

    СредняяCVSS 5,8Эксплойта нетEPSS 0 %

    plesk · obsidian3 июл. 2025 г.

  • CVE-2023-4569
    22Наблюдать

    Kernel: information leak in nft_set_catchall_flush in net/netfilter/nf_tables_api.c

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    linux · linux kernel28 авг. 2023 г.

  • CVE-2024-0443
    22Наблюдать

    Kernel: blkio memory leakage due to blkcg and some blkgs are not freed after they are made offline.

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    linux · linux kernel11 янв. 2024 г.

  • CVE-2024-32388
    21Наблюдать

    Due to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP packets.

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    kerlink · keros1 дек. 2025 г.

  • CVE-2025-52925
    20Наблюдать

    In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812.

    СредняяCVSS 5,0Эксплойта нетEPSS 0 %

    onelogin · active directory connector2 июл. 2025 г.

  • CVE-2025-55014
    18Наблюдать

    The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the d

    СредняяCVSS 4,7Эксплойта нетEPSS 0 %

    stardict · stardict4 авг. 2025 г.

  • CVE-2023-38509
    17Наблюдать

    XWiki Platform's obfuscated email addresses should not be sorted

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    xwiki · xwiki7 нояб. 2023 г.

  • CVE-2025-66422
    17Наблюдать

    Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information.

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    tryton · trytond29 нояб. 2025 г.

Все классы уязвимостей