Перейти к содержимому
Noroxi

CWE-672 · 65 записей

Operation on a Resource after Expiration or Release

CVE этого класса

65 записей

  • CVE-2019-17638
    40В плане

    In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce

    КритическаяCVSS 9,4Proof of conceptEPSS 11 %

    eclipse · jetty9 июл. 2020 г.

  • CVE-2020-24030
    40В плане

    ForLogic Qualiex v1 and v3 has weak token expiration.

    КритическаяCVSS 9,8Proof of conceptEPSS 3 %

    forlogic · qualiex2 сент. 2020 г.

  • CVE-2020-12043
    40В плане

    The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the W

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    baxter · sigma spectrum infusion system firmware29 июн. 2020 г.

  • CVE-2024-47571
    39Наблюдать

    An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper acc

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    fortinet · fortimanager14 янв. 2025 г.

  • CVE-2020-11027
    36Наблюдать

    Password reset links invalidation issue in WordPress

    ВысокаяCVSS 8,1Proof of conceptEPSS 14 %

    wordpress · wordpress30 апр. 2020 г.

  • CVE-2026-43585
    36Наблюдать

    OpenClaw < 2026.4.15 - Bearer Token Validation Bypass via Stale SecretRef Resolution

    КритическаяCVSS 9,2Эксплойта нетEPSS 1 %

    openclaw · openclaw6 мая 2026 г.

  • CVE-2013-10075
    36Наблюдать

    Apache::Session versions through 1.94 for Perl re-creates deleted sessions

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    chorny · apache\8 мая 2026 г.

  • CVE-2021-23995
    35Наблюдать

    When Responsive Design Mode was enabled, it used references to objects that were previously freed.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    mozilla · firefox24 июн. 2021 г.

  • CVE-2022-22755
    35Наблюдать

    By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScript (within th

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    mozilla · firefox22 дек. 2022 г.

  • CVE-2025-55669
    34Наблюдать

    BIG-IP HTTP/2 vulnerability

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    f5 · big-ip application security manager15 окт. 2025 г.

  • CVE-2026-31875
    32Наблюдать

    Parse Server MFA recovery codes not consumed after use

    ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %

    parseplatform · parse-server11 мар. 2026 г.

  • CVE-2026-2379
    32Наблюдать

    Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is Disabled

    ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %

    arista networks · eos5 июн. 2026 г.

  • GHSA-m8wm-r5vq-qjpg
    32Наблюдать

    Duplicate Advisory: OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation

    ВысокаяCVSS 8,1Эксплойта нет

    npm · openclaw6 мая 2026 г.

  • CVE-2021-37204
    31Наблюдать

    A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC Drive Controller family (All version

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    siemens · simatic drive controller cpu 1504d tf firmware9 февр. 2022 г.

  • CVE-2021-37185
    31Наблюдать

    A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller C

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    siemens · simatic drive controller cpu 1504d tf firmware9 февр. 2022 г.

  • CVE-2019-15791
    31Наблюдать

    Reference count underflow in shiftfs

    ВысокаяCVSS 7,8Proof of conceptEPSS 1 %

    linux · linux kernel23 апр. 2020 г.

  • CVE-2017-0544
    31Наблюдать

    An elevation of privilege vulnerability in CameraBase could enable a local malicious application to execute arbitrary code.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    google · android7 апр. 2017 г.

  • CVE-2020-25221
    31Наблюдать

    get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counti

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    linux · linux kernel10 сент. 2020 г.

  • CVE-2023-34326
    31Наблюдать

    x86/AMD: missing IOMMU TLB flushing

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    xen · xen5 янв. 2024 г.

  • CVE-2017-14895
    31Наблюдать

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, after a subsystem reset, iwp

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    google · android5 дек. 2017 г.

  • CVE-2022-22197
    30Наблюдать

    Junos OS and Junos OS Evolved: An rpd core will be observed with proxy BGP route-target filtering enabled and certain route add and delete event happening

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    juniper · junos os evolved14 апр. 2022 г.

  • CVE-2022-30256
    30Наблюдать

    An issue was discovered in MaraDNS Deadwood through 3.5.0021 that allows variant V1 of unintended domain name resolution.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    maradns · maradns18 нояб. 2022 г.

  • CVE-2022-22332
    30Наблюдать

    IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for th

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    ibm · partner engagement manager1 апр. 2022 г.

  • CVE-2026-68481
    30Наблюдать

    Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    apache · cxf6 авг. 2026 г.

  • CVE-2025-58149
    30Наблюдать

    Incorrect removal of permissions on PCI device unplug

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    xen · xen31 окт. 2025 г.

Все классы уязвимостей