CWE-402 · 24 kayıt
Transmission of Private Resources into a New Sphere ('Resource Leak')
Bu sınıftaki CVE’ler
24 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2021-23264İstismar yok | Transmission of Private Resources into a New Sphere ('Resource Leak') and Exposure of Resource to Wrong Sphere in Crafter Searchcraftercms · crafter cms · CWE-402 | Kritik9,1 | — | %1,2 | 2 Ara 2021 |
34İzleyin | CVE-2025-29925Kavram kanıtı | XWiki allows unregistered users to access private pages information through REST endpointxwiki · xwiki · CWE-402 | Yüksek8,7 | — | %0,9 | 19 Mar 2025 |
34İzleyin | GHSA-j9wr-49vq-rm5gİstismar yok | Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19Maven · com.vaadin:vaadin-bom · CWE-402 | Yüksek8,6 | — | — | 19 Nis 2021 |
32İzleyin | CVE-2025-48383İstismar yok | Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leakingcodingjoe · django-select2 · CWE-402 | Yüksek8,2 | — | %0,3 | 27 May 2025 |
32İzleyin | CVE-2025-32360İstismar yok | In Zammad 6.4.x before 6.4.2, there is information exposure.zammad · zammad · CWE-402 | Yüksek8,1 | — | %0,2 | 5 Nis 2025 |
31İzleyin | CVE-2021-31407İstismar yok | Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19vaadin · flow · CWE-402 | Yüksek7,5 | — | %2,4 | 23 Nis 2021 |
31İzleyin | CVE-2021-23263İstismar yok | Transmission of Private Resources into a New Sphere ('Resource Leak') in Crafter Enginecraftercms · crafter cms · CWE-402 | Yüksek7,5 | — | %1,7 | 2 Ara 2021 |
31İzleyin | CVE-2021-31410İstismar yok | Project sources exposure in Vaadin Designervaadin · designer · CWE-402 | Yüksek7,5 | — | %1,7 | 23 Nis 2021 |
30İzleyin | CVE-2022-3596İstismar yok | Instack-undercloud: rsync leaks information to undercloudredhat · openstack platform · CWE-402 | Yüksek7,5 | — | %1,1 | 20 Eyl 2023 |
30İzleyin | CVE-2023-34467İstismar yok | XWiki Platform may retrieve email addresses of all usersxwiki · xwiki · CWE-402 | Yüksek7,5 | — | %1,0 | 23 Haz 2023 |
30İzleyin | CVE-2024-29900İstismar yok | @electron/packager's build process memory potentially leaked into final executableopenjsf · packager · CWE-402 | Yüksek7,5 | — | %0,6 | 29 Mar 2024 |
30İzleyin | CVE-2025-67745İstismar yok | Myhoard logs backup encryption key in plain textaiven · myhoard · CWE-402 | Yüksek7,5 | — | %0,2 | 18 Ara 2025 |
28İzleyin | CVE-2024-47146İstismar yok | Ruijie Reyee OS Resource Leakruijienetworks · reyee os · CWE-402 | Yüksek7,1 | — | %0,3 | 6 Ara 2024 |
27İzleyin | CVE-2022-30231İstismar yok | A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6).siemens · sicam gridedge essential · CWE-402 | Orta6,9 | — | %0,6 | 14 Haz 2022 |
27İzleyin | CVE-2025-0502İstismar yok | Transmission of Private Resources into a New Sphere in Crafter Enginecraftercms · craftercms · CWE-402 | Orta6,9 | — | %0,4 | 15 Oca 2025 |
26İzleyin | CVE-2017-8442İstismar yok | Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configuratelastic · x-pack · CWE-402 | Orta6,5 | — | %0,9 | 7 Tem 2017 |
23İzleyin | CVE-2025-49618İstismar yok | In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint.plesk · obsidian · CWE-402 | Orta5,8 | — | %0,4 | 3 Tem 2025 |
22İzleyin | CVE-2023-4569İstismar yok | Kernel: information leak in nft_set_catchall_flush in net/netfilter/nf_tables_api.clinux · linux kernel · CWE-402 | Orta5,5 | — | %0,3 | 28 Ağu 2023 |
22İzleyin | CVE-2024-0443İstismar yok | Kernel: blkio memory leakage due to blkcg and some blkgs are not freed after they are made offline.linux · linux kernel · CWE-402 | Orta5,5 | — | %0,2 | 11 Oca 2024 |
21İzleyin | CVE-2024-32388İstismar yok | Due to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP packets.kerlink · keros · CWE-402 | Orta5,3 | — | %1,2 | 1 Ara 2025 |
20İzleyin | CVE-2025-52925İstismar yok | In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812.onelogin · active directory connector · CWE-402 | Orta5,0 | — | %0,2 | 2 Tem 2025 |
18İzleyin | CVE-2025-55014İstismar yok | The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dstardict · stardict · CWE-402 | Orta4,7 | — | %0,4 | 4 Ağu 2025 |
17İzleyin | CVE-2023-38509İstismar yok | XWiki Platform's obfuscated email addresses should not be sortedxwiki · xwiki · CWE-402 | Orta4,3 | — | %0,8 | 7 Kas 2023 |
17İzleyin | CVE-2025-66422İstismar yok | Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information.tryton · trytond · CWE-402 | Orta4,3 | — | %0,3 | 29 Kas 2025 |
- CVE-2021-2326436İzleyin
Transmission of Private Resources into a New Sphere ('Resource Leak') and Exposure of Resource to Wrong Sphere in Crafter Search
KritikCVSS 9,1İstismar yokEPSS %1craftercms · crafter cms2 Ara 2021
- CVE-2025-2992534İzleyin
XWiki allows unregistered users to access private pages information through REST endpoint
YüksekCVSS 8,7Kavram kanıtıEPSS %1xwiki · xwiki19 Mar 2025
- GHSA-j9wr-49vq-rm5g34İzleyin
Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19
YüksekCVSS 8,6İstismar yokMaven · com.vaadin:vaadin-bom19 Nis 2021
- CVE-2025-4838332İzleyin
Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking
YüksekCVSS 8,2İstismar yokEPSS %0codingjoe · django-select227 May 2025
- CVE-2025-3236032İzleyin
In Zammad 6.4.x before 6.4.2, there is information exposure.
YüksekCVSS 8,1İstismar yokEPSS %0zammad · zammad5 Nis 2025
- CVE-2021-3140731İzleyin
Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19
YüksekCVSS 7,5İstismar yokEPSS %2vaadin · flow23 Nis 2021
- CVE-2021-2326331İzleyin
Transmission of Private Resources into a New Sphere ('Resource Leak') in Crafter Engine
YüksekCVSS 7,5İstismar yokEPSS %2craftercms · crafter cms2 Ara 2021
- CVE-2021-3141031İzleyin
Project sources exposure in Vaadin Designer
YüksekCVSS 7,5İstismar yokEPSS %2vaadin · designer23 Nis 2021
- CVE-2022-359630İzleyin
Instack-undercloud: rsync leaks information to undercloud
YüksekCVSS 7,5İstismar yokEPSS %1redhat · openstack platform20 Eyl 2023
- CVE-2023-3446730İzleyin
XWiki Platform may retrieve email addresses of all users
YüksekCVSS 7,5İstismar yokEPSS %1xwiki · xwiki23 Haz 2023
- CVE-2024-2990030İzleyin
@electron/packager's build process memory potentially leaked into final executable
YüksekCVSS 7,5İstismar yokEPSS %1openjsf · packager29 Mar 2024
- CVE-2025-6774530İzleyin
Myhoard logs backup encryption key in plain text
YüksekCVSS 7,5İstismar yokEPSS %0aiven · myhoard18 Ara 2025
- CVE-2024-4714628İzleyin
Ruijie Reyee OS Resource Leak
YüksekCVSS 7,1İstismar yokEPSS %0ruijienetworks · reyee os6 Ara 2024
- CVE-2022-3023127İzleyin
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6).
OrtaCVSS 6,9İstismar yokEPSS %1siemens · sicam gridedge essential14 Haz 2022
- CVE-2025-050227İzleyin
Transmission of Private Resources into a New Sphere in Crafter Engine
OrtaCVSS 6,9İstismar yokEPSS %0craftercms · craftercms15 Oca 2025
- CVE-2017-844226İzleyin
Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configurat
OrtaCVSS 6,5İstismar yokEPSS %1elastic · x-pack7 Tem 2017
- CVE-2025-4961823İzleyin
In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint.
OrtaCVSS 5,8İstismar yokEPSS %0plesk · obsidian3 Tem 2025
- CVE-2023-456922İzleyin
Kernel: information leak in nft_set_catchall_flush in net/netfilter/nf_tables_api.c
OrtaCVSS 5,5İstismar yokEPSS %0linux · linux kernel28 Ağu 2023
- CVE-2024-044322İzleyin
Kernel: blkio memory leakage due to blkcg and some blkgs are not freed after they are made offline.
OrtaCVSS 5,5İstismar yokEPSS %0linux · linux kernel11 Oca 2024
- CVE-2024-3238821İzleyin
Due to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP packets.
OrtaCVSS 5,3İstismar yokEPSS %1kerlink · keros1 Ara 2025
- CVE-2025-5292520İzleyin
In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812.
OrtaCVSS 5,0İstismar yokEPSS %0onelogin · active directory connector2 Tem 2025
- CVE-2025-5501418İzleyin
The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the d
OrtaCVSS 4,7İstismar yokEPSS %0stardict · stardict4 Ağu 2025
- CVE-2023-3850917İzleyin
XWiki Platform's obfuscated email addresses should not be sorted
OrtaCVSS 4,3İstismar yokEPSS %1xwiki · xwiki7 Kas 2023
- CVE-2025-6642217İzleyin
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information.
OrtaCVSS 4,3İstismar yokEPSS %0tryton · trytond29 Kas 2025