Перейти к содержимому
Noroxi

CWE-459 · 205 записей

Incomplete Cleanup

CVE этого класса

205 записей

  • CVE-2017-17090
    55В плане

    An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified As

    ВысокаяCVSS 7,5Proof of conceptEPSS 82 %

    digium · certified asterisk1 дек. 2017 г.

  • CVE-2025-31650
    48В плане

    Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame

    ВысокаяCVSS 7,5Proof of conceptEPSS 61 %

    apache · tomcat28 апр. 2025 г.

  • CVE-2022-1552
    40В плане

    A flaw was found in PostgreSQL.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 16 %

    postgresql · postgresql31 авг. 2022 г.

  • CVE-2020-13451
    40В плане

    An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice co

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    thecodingmachine · gotenberg7 янв. 2021 г.

  • CVE-2005-1744
    40В плане

    BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows t

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    bea · weblogic server24 мая 2005 г.

  • CVE-2021-45330
    39Наблюдать

    An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and t

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    gitea · gitea9 февр. 2022 г.

  • CVE-2022-45347
    39Наблюдать

    Apache ShardingSphere-Proxy: MySQL authentication bypass

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    apache · shardingsphere22 дек. 2022 г.

  • CVE-2021-32928
    39Наблюдать

    The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Manager” that allows i

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    thalesgroup · sentinel ldk run-time environment16 июн. 2021 г.

  • CVE-2021-45706
    39Наблюдать

    An issue was discovered in the zeroize_derive crate before 1.1.1 for Rust.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    zeroize derive project · zeroize derive26 дек. 2021 г.

  • CVE-2021-36205
    39Наблюдать

    Metasys session token

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    johnsoncontrols · metasys application and data server15 апр. 2022 г.

  • CVE-2026-28268
    39Наблюдать

    Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    vikunja · vikunja27 февр. 2026 г.

  • CVE-2018-18924
    38Наблюдать

    The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" be

    ВысокаяCVSS 8,8Proof of conceptEPSS 9 %

    projeqtor · projeqtor4 нояб. 2018 г.

  • CVE-2026-34263
    38Наблюдать

    Missing authentication check in SAP Commerce cloud configuration

    КритическаяCVSS 9,6Эксплойта нетEPSS 1 %

    sap_se · sap commerce cloud configuration11 мая 2026 г.

  • CVE-2019-25016
    36Наблюдать

    In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    opendoas project · opendoas28 янв. 2021 г.

  • CVE-2019-18191
    36Наблюдать

    A privilege escalation vulnerability in the Trend Micro Deep Security as a Service Quick Setup cloud formation template could allow an authe

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    trendmicro · deep security as a service16 дек. 2019 г.

  • CVE-2023-36468
    36Наблюдать

    Upgrading doesn't prevent exploiting vulnerable XWiki documents

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    xwiki · xwiki29 июн. 2023 г.

  • CVE-2024-28265
    36Наблюдать

    IBOS v4.5.5 has an arbitrary file deletion vulnerability via \system\modules\dashboard\controllers\LoginController.php.

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    ibos · ibos1 нояб. 2024 г.

  • CVE-2026-85043
    36Наблюдать

    Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via cra

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    google · chrome3 сент. 2026 г.

  • CVE-2025-6338
    36Наблюдать

    Possible denial of service with multiple incoming connections to a Schannel based server with a TLS backend

    КритическаяCVSS 9,2Эксплойта нетEPSS 0 %

    qt · qt16 окт. 2025 г.

  • CVE-2026-15390
    36Наблюдать

    Out-of-bounds write in Das U-Boot

    КритическаяCVSS 9,0Эксплойта нет

    denx software engineering · das u-boot1 день назад

  • CVE-2020-24489
    35Наблюдать

    Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local ac

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    intel · atom x5-e39309 июн. 2021 г.

  • CVE-2026-3304
    34Наблюдать

    Multer vulnerable to Denial of Service via incomplete cleanup

    ВысокаяCVSS 8,7Proof of conceptEPSS 1 %

    expressjs · multer27 февр. 2026 г.

  • CVE-2026-52736
    34Наблюдать

    ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cache

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    zcashfoundation · zebra18 авг. 2026 г.

  • CVE-2025-21609
    34Наблюдать

    SiYuan has an arbitrary file deletion vulnerability

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    b3log · siyuan3 янв. 2025 г.

  • CVE-2025-59781
    34Наблюдать

    BIG-IP DNS cache vulnerability

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    f5 · big-ip access policy manager15 окт. 2025 г.

Все классы уязвимостей