CWE-672 · 65 записей
Operation on a Resource after Expiration or Release
CVE этого класса
65 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2019-17638Proof of concept | In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produceeclipse · jetty · CWE-672 | Критическая9,4 | — | 11,1 % | 9 июл. 2020 г. |
40В плане | CVE-2020-24030Proof of concept | ForLogic Qualiex v1 and v3 has weak token expiration.forlogic · qualiex · CWE-672 | Критическая9,8 | — | 2,7 % | 2 сент. 2020 г. |
40В плане | CVE-2020-12043Эксплойта нет | The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the Wbaxter · sigma spectrum infusion system firmware · CWE-672 | Критическая9,8 | — | 2,1 % | 29 июн. 2020 г. |
39Наблюдать | CVE-2024-47571Эксплойта нет | An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper accfortinet · fortimanager · CWE-672 | Критическая9,8 | — | 0,9 % | 14 янв. 2025 г. |
36Наблюдать | CVE-2020-11027Proof of concept | Password reset links invalidation issue in WordPresswordpress · wordpress · CWE-672 | Высокая8,1 | — | 13,6 % | 30 апр. 2020 г. |
36Наблюдать | CVE-2026-43585Эксплойта нет | OpenClaw < 2026.4.15 - Bearer Token Validation Bypass via Stale SecretRef Resolutionopenclaw · openclaw · CWE-672 | Критическая9,2 | — | 0,8 % | 6 мая 2026 г. |
36Наблюдать | CVE-2013-10075Эксплойта нет | Apache::Session versions through 1.94 for Perl re-creates deleted sessionschorny · apache\ · CWE-672 | Критическая9,1 | — | 0,4 % | 8 мая 2026 г. |
35Наблюдать | CVE-2021-23995Эксплойта нет | When Responsive Design Mode was enabled, it used references to objects that were previously freed.mozilla · firefox · CWE-672 | Высокая8,8 | — | 1,2 % | 24 июн. 2021 г. |
35Наблюдать | CVE-2022-22755Эксплойта нет | By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScript (within thmozilla · firefox · CWE-672 | Высокая8,8 | — | 0,6 % | 22 дек. 2022 г. |
34Наблюдать | CVE-2025-55669Эксплойта нет | BIG-IP HTTP/2 vulnerabilityf5 · big-ip application security manager · CWE-672 | Высокая8,7 | — | 0,4 % | 15 окт. 2025 г. |
32Наблюдать | CVE-2026-31875Эксплойта нет | Parse Server MFA recovery codes not consumed after useparseplatform · parse-server · CWE-672 | Высокая8,2 | — | 0,5 % | 11 мар. 2026 г. |
32Наблюдать | CVE-2026-2379Эксплойта нет | Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is Disabledarista networks · eos · CWE-672 | Высокая8,2 | — | 0,2 % | 5 июн. 2026 г. |
32Наблюдать | GHSA-m8wm-r5vq-qjpgЭксплойта нет | Duplicate Advisory: OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotationnpm · openclaw · CWE-672 | Высокая8,1 | — | — | 6 мая 2026 г. |
31Наблюдать | CVE-2021-37204Эксплойта нет | A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC Drive Controller family (All versionsiemens · simatic drive controller cpu 1504d tf firmware · CWE-672 | Высокая7,5 | — | 2,2 % | 9 февр. 2022 г. |
31Наблюдать | CVE-2021-37185Эксплойта нет | A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller Csiemens · simatic drive controller cpu 1504d tf firmware · CWE-672 | Высокая7,5 | — | 2,1 % | 9 февр. 2022 г. |
31Наблюдать | CVE-2019-15791Proof of concept | Reference count underflow in shiftfslinux · linux kernel · CWE-672 | Высокая7,8 | — | 1,3 % | 23 апр. 2020 г. |
31Наблюдать | CVE-2017-0544Эксплойта нет | An elevation of privilege vulnerability in CameraBase could enable a local malicious application to execute arbitrary code.google · android · CWE-672 | Высокая7,8 | — | 0,9 % | 7 апр. 2017 г. |
31Наблюдать | CVE-2020-25221Эксплойта нет | get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference countilinux · linux kernel · CWE-672 | Высокая7,8 | — | 0,7 % | 10 сент. 2020 г. |
31Наблюдать | CVE-2023-34326Эксплойта нет | x86/AMD: missing IOMMU TLB flushingxen · xen · CWE-672 | Высокая7,8 | — | 0,3 % | 5 янв. 2024 г. |
31Наблюдать | CVE-2017-14895Эксплойта нет | In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, after a subsystem reset, iwpgoogle · android · CWE-672 | Высокая7,8 | — | 0,3 % | 5 дек. 2017 г. |
30Наблюдать | CVE-2022-22197Эксплойта нет | Junos OS and Junos OS Evolved: An rpd core will be observed with proxy BGP route-target filtering enabled and certain route add and delete event happeningjuniper · junos os evolved · CWE-672 | Высокая7,5 | — | 1,1 % | 14 апр. 2022 г. |
30Наблюдать | CVE-2022-30256Эксплойта нет | An issue was discovered in MaraDNS Deadwood through 3.5.0021 that allows variant V1 of unintended domain name resolution.maradns · maradns · CWE-672 | Высокая7,5 | — | 1,0 % | 18 нояб. 2022 г. |
30Наблюдать | CVE-2022-22332Эксплойта нет | IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for thibm · partner engagement manager · CWE-672 | Высокая7,5 | — | 0,8 % | 1 апр. 2022 г. |
30Наблюдать | CVE-2026-68481Эксплойта нет | Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProviderapache · cxf · CWE-672 | Высокая7,5 | — | 0,7 % | 6 авг. 2026 г. |
30Наблюдать | CVE-2025-58149Эксплойта нет | Incorrect removal of permissions on PCI device unplugxen · xen · CWE-672 | Высокая7,5 | — | 0,4 % | 31 окт. 2025 г. |
- CVE-2019-1763840В плане
In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce
КритическаяCVSS 9,4Proof of conceptEPSS 11 %eclipse · jetty9 июл. 2020 г.
- CVE-2020-2403040В плане
ForLogic Qualiex v1 and v3 has weak token expiration.
КритическаяCVSS 9,8Proof of conceptEPSS 3 %forlogic · qualiex2 сент. 2020 г.
- CVE-2020-1204340В плане
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the W
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %baxter · sigma spectrum infusion system firmware29 июн. 2020 г.
- CVE-2024-4757139Наблюдать
An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper acc
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %fortinet · fortimanager14 янв. 2025 г.
- CVE-2020-1102736Наблюдать
Password reset links invalidation issue in WordPress
ВысокаяCVSS 8,1Proof of conceptEPSS 14 %wordpress · wordpress30 апр. 2020 г.
- CVE-2026-4358536Наблюдать
OpenClaw < 2026.4.15 - Bearer Token Validation Bypass via Stale SecretRef Resolution
КритическаяCVSS 9,2Эксплойта нетEPSS 1 %openclaw · openclaw6 мая 2026 г.
- CVE-2013-1007536Наблюдать
Apache::Session versions through 1.94 for Perl re-creates deleted sessions
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %chorny · apache\8 мая 2026 г.
- CVE-2021-2399535Наблюдать
When Responsive Design Mode was enabled, it used references to objects that were previously freed.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mozilla · firefox24 июн. 2021 г.
- CVE-2022-2275535Наблюдать
By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScript (within th
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mozilla · firefox22 дек. 2022 г.
- CVE-2025-5566934Наблюдать
BIG-IP HTTP/2 vulnerability
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %f5 · big-ip application security manager15 окт. 2025 г.
- CVE-2026-3187532Наблюдать
Parse Server MFA recovery codes not consumed after use
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %parseplatform · parse-server11 мар. 2026 г.
- CVE-2026-237932Наблюдать
Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is Disabled
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %arista networks · eos5 июн. 2026 г.
- GHSA-m8wm-r5vq-qjpg32Наблюдать
Duplicate Advisory: OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation
ВысокаяCVSS 8,1Эксплойта нетnpm · openclaw6 мая 2026 г.
- CVE-2021-3720431Наблюдать
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC Drive Controller family (All version
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %siemens · simatic drive controller cpu 1504d tf firmware9 февр. 2022 г.
- CVE-2021-3718531Наблюдать
A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller C
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %siemens · simatic drive controller cpu 1504d tf firmware9 февр. 2022 г.
- CVE-2019-1579131Наблюдать
Reference count underflow in shiftfs
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %linux · linux kernel23 апр. 2020 г.
- CVE-2017-054431Наблюдать
An elevation of privilege vulnerability in CameraBase could enable a local malicious application to execute arbitrary code.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %google · android7 апр. 2017 г.
- CVE-2020-2522131Наблюдать
get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counti
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %linux · linux kernel10 сент. 2020 г.
- CVE-2023-3432631Наблюдать
x86/AMD: missing IOMMU TLB flushing
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %xen · xen5 янв. 2024 г.
- CVE-2017-1489531Наблюдать
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, after a subsystem reset, iwp
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %google · android5 дек. 2017 г.
- CVE-2022-2219730Наблюдать
Junos OS and Junos OS Evolved: An rpd core will be observed with proxy BGP route-target filtering enabled and certain route add and delete event happening
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %juniper · junos os evolved14 апр. 2022 г.
- CVE-2022-3025630Наблюдать
An issue was discovered in MaraDNS Deadwood through 3.5.0021 that allows variant V1 of unintended domain name resolution.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %maradns · maradns18 нояб. 2022 г.
- CVE-2022-2233230Наблюдать
IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for th
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %ibm · partner engagement manager1 апр. 2022 г.
- CVE-2026-6848130Наблюдать
Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %apache · cxf6 авг. 2026 г.
- CVE-2025-5814930Наблюдать
Incorrect removal of permissions on PCI device unplug
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %xen · xen31 окт. 2025 г.