İçeriğe atla
Noroxi

CWE-459 · 205 kayıt

Incomplete Cleanup

Bu sınıftaki CVE’ler

205 kayıt

  • CVE-2017-17090
    55Planlayın

    An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified As

    YüksekCVSS 7,5Kavram kanıtıEPSS %82

    digium · certified asterisk1 Ara 2017

  • CVE-2025-31650
    48Planlayın

    Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame

    YüksekCVSS 7,5Kavram kanıtıEPSS %61

    apache · tomcat28 Nis 2025

  • CVE-2022-1552
    40Planlayın

    A flaw was found in PostgreSQL.

    YüksekCVSS 8,8İstismar yokEPSS %16

    postgresql · postgresql31 Ağu 2022

  • CVE-2020-13451
    40Planlayın

    An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice co

    KritikCVSS 9,8İstismar yokEPSS %3

    thecodingmachine · gotenberg7 Oca 2021

  • CVE-2005-1744
    40Planlayın

    BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows t

    KritikCVSS 9,8İstismar yokEPSS %2

    bea · weblogic server24 May 2005

  • CVE-2021-45330
    39İzleyin

    An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and t

    KritikCVSS 9,8İstismar yokEPSS %1

    gitea · gitea9 Şub 2022

  • CVE-2022-45347
    39İzleyin

    Apache ShardingSphere-Proxy: MySQL authentication bypass

    KritikCVSS 9,8İstismar yokEPSS %1

    apache · shardingsphere22 Ara 2022

  • CVE-2021-32928
    39İzleyin

    The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Manager” that allows i

    KritikCVSS 9,8İstismar yokEPSS %1

    thalesgroup · sentinel ldk run-time environment16 Haz 2021

  • CVE-2021-45706
    39İzleyin

    An issue was discovered in the zeroize_derive crate before 1.1.1 for Rust.

    KritikCVSS 9,8İstismar yokEPSS %1

    zeroize derive project · zeroize derive26 Ara 2021

  • CVE-2021-36205
    39İzleyin

    Metasys session token

    KritikCVSS 9,8İstismar yokEPSS %1

    johnsoncontrols · metasys application and data server15 Nis 2022

  • CVE-2026-28268
    39İzleyin

    Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse

    KritikCVSS 9,8İstismar yokEPSS %1

    vikunja · vikunja27 Şub 2026

  • CVE-2018-18924
    38İzleyin

    The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" be

    YüksekCVSS 8,8Kavram kanıtıEPSS %9

    projeqtor · projeqtor4 Kas 2018

  • CVE-2026-34263
    38İzleyin

    Missing authentication check in SAP Commerce cloud configuration

    KritikCVSS 9,6İstismar yokEPSS %1

    sap_se · sap commerce cloud configuration11 May 2026

  • CVE-2019-25016
    36İzleyin

    In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed

    YüksekCVSS 8,8İstismar yokEPSS %3

    opendoas project · opendoas28 Oca 2021

  • CVE-2019-18191
    36İzleyin

    A privilege escalation vulnerability in the Trend Micro Deep Security as a Service Quick Setup cloud formation template could allow an authe

    YüksekCVSS 8,8İstismar yokEPSS %2

    trendmicro · deep security as a service16 Ara 2019

  • CVE-2023-36468
    36İzleyin

    Upgrading doesn't prevent exploiting vulnerable XWiki documents

    YüksekCVSS 8,8İstismar yokEPSS %2

    xwiki · xwiki29 Haz 2023

  • CVE-2024-28265
    36İzleyin

    IBOS v4.5.5 has an arbitrary file deletion vulnerability via \system\modules\dashboard\controllers\LoginController.php.

    KritikCVSS 9,1İstismar yokEPSS %0

    ibos · ibos1 Kas 2024

  • CVE-2026-85043
    36İzleyin

    Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via cra

    KritikCVSS 9,1İstismar yokEPSS %0

    google · chrome3 Eyl 2026

  • CVE-2025-6338
    36İzleyin

    Possible denial of service with multiple incoming connections to a Schannel based server with a TLS backend

    KritikCVSS 9,2İstismar yokEPSS %0

    qt · qt16 Eki 2025

  • CVE-2026-15390
    36İzleyin

    Out-of-bounds write in Das U-Boot

    KritikCVSS 9,0İstismar yok

    denx software engineering · das u-boot1 gün önce

  • CVE-2020-24489
    35İzleyin

    Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local ac

    YüksekCVSS 8,8İstismar yokEPSS %0

    intel · atom x5-e39309 Haz 2021

  • CVE-2026-3304
    34İzleyin

    Multer vulnerable to Denial of Service via incomplete cleanup

    YüksekCVSS 8,7Kavram kanıtıEPSS %1

    expressjs · multer27 Şub 2026

  • CVE-2026-52736
    34İzleyin

    ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cache

    YüksekCVSS 8,7İstismar yokEPSS %1

    zcashfoundation · zebra18 Ağu 2026

  • CVE-2025-21609
    34İzleyin

    SiYuan has an arbitrary file deletion vulnerability

    YüksekCVSS 8,7İstismar yokEPSS %1

    b3log · siyuan3 Oca 2025

  • CVE-2025-59781
    34İzleyin

    BIG-IP DNS cache vulnerability

    YüksekCVSS 8,7İstismar yokEPSS %0

    f5 · big-ip access policy manager15 Eki 2025

Tüm zafiyet sınıfları