CWE-459 · 205 kayıt
Incomplete Cleanup
Bu sınıftaki CVE’ler
205 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
55Planlayın | CVE-2017-17090Kavram kanıtı | An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asdigium · certified asterisk · CWE-459 | Yüksek7,5 | — | %82,2 | 1 Ara 2017 |
48Planlayın | CVE-2025-31650Kavram kanıtı | Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frameapache · tomcat · CWE-459 | Yüksek7,5 | — | %61,0 | 28 Nis 2025 |
40Planlayın | CVE-2022-1552İstismar yok | A flaw was found in PostgreSQL.postgresql · postgresql · CWE-459 | Yüksek8,8 | — | %16,0 | 31 Ağu 2022 |
40Planlayın | CVE-2020-13451İstismar yok | An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice cothecodingmachine · gotenberg · CWE-459 | Kritik9,8 | — | %3,0 | 7 Oca 2021 |
40Planlayın | CVE-2005-1744İstismar yok | BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows tbea · weblogic server · CWE-459 | Kritik9,8 | — | %2,1 | 24 May 2005 |
39İzleyin | CVE-2021-45330İstismar yok | An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and tgitea · gitea · CWE-459 | Kritik9,8 | — | %1,4 | 9 Şub 2022 |
39İzleyin | CVE-2022-45347İstismar yok | Apache ShardingSphere-Proxy: MySQL authentication bypassapache · shardingsphere · CWE-459 | Kritik9,8 | — | %1,4 | 22 Ara 2022 |
39İzleyin | CVE-2021-32928İstismar yok | The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Manager” that allows ithalesgroup · sentinel ldk run-time environment · CWE-459 | Kritik9,8 | — | %1,3 | 16 Haz 2021 |
39İzleyin | CVE-2021-45706İstismar yok | An issue was discovered in the zeroize_derive crate before 1.1.1 for Rust.zeroize derive project · zeroize derive · CWE-459 | Kritik9,8 | — | %1,2 | 26 Ara 2021 |
39İzleyin | CVE-2021-36205İstismar yok | Metasys session tokenjohnsoncontrols · metasys application and data server · CWE-459 | Kritik9,8 | — | %1,0 | 15 Nis 2022 |
39İzleyin | CVE-2026-28268İstismar yok | Vikunja Vulnerable to Account Takeover via Password Reset Token Reusevikunja · vikunja · CWE-459 | Kritik9,8 | — | %0,9 | 27 Şub 2026 |
38İzleyin | CVE-2018-18924Kavram kanıtı | The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" beprojeqtor · projeqtor · CWE-459 | Yüksek8,8 | — | %9,5 | 4 Kas 2018 |
38İzleyin | CVE-2026-34263İstismar yok | Missing authentication check in SAP Commerce cloud configurationsap_se · sap commerce cloud configuration · CWE-459 | Kritik9,6 | — | %0,6 | 11 May 2026 |
36İzleyin | CVE-2019-25016İstismar yok | In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowedopendoas project · opendoas · CWE-459 | Yüksek8,8 | — | %2,7 | 28 Oca 2021 |
36İzleyin | CVE-2019-18191İstismar yok | A privilege escalation vulnerability in the Trend Micro Deep Security as a Service Quick Setup cloud formation template could allow an authetrendmicro · deep security as a service · CWE-459 | Yüksek8,8 | — | %2,2 | 16 Ara 2019 |
36İzleyin | CVE-2023-36468İstismar yok | Upgrading doesn't prevent exploiting vulnerable XWiki documentsxwiki · xwiki · CWE-459 | Yüksek8,8 | — | %1,9 | 29 Haz 2023 |
36İzleyin | CVE-2024-28265İstismar yok | IBOS v4.5.5 has an arbitrary file deletion vulnerability via \system\modules\dashboard\controllers\LoginController.php.ibos · ibos · CWE-459 | Kritik9,1 | — | %0,5 | 1 Kas 2024 |
36İzleyin | CVE-2026-85043İstismar yok | Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via cragoogle · chrome · CWE-459 | Kritik9,1 | — | %0,4 | 3 Eyl 2026 |
36İzleyin | CVE-2025-6338İstismar yok | Possible denial of service with multiple incoming connections to a Schannel based server with a TLS backendqt · qt · CWE-459 | Kritik9,2 | — | %0,4 | 16 Eki 2025 |
36İzleyin | CVE-2026-15390İstismar yok | Out-of-bounds write in Das U-Bootdenx software engineering · das u-boot · CWE-459 | Kritik9,0 | — | — | 1 gün önce |
35İzleyin | CVE-2020-24489İstismar yok | Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local acintel · atom x5-e3930 · CWE-459 | Yüksek8,8 | — | %0,4 | 9 Haz 2021 |
34İzleyin | CVE-2026-3304Kavram kanıtı | Multer vulnerable to Denial of Service via incomplete cleanupexpressjs · multer · CWE-459 | Yüksek8,7 | — | %0,9 | 27 Şub 2026 |
34İzleyin | CVE-2026-52736İstismar yok | ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cachezcashfoundation · zebra · CWE-459 | Yüksek8,7 | — | %0,6 | 18 Ağu 2026 |
34İzleyin | CVE-2025-21609İstismar yok | SiYuan has an arbitrary file deletion vulnerabilityb3log · siyuan · CWE-459 | Yüksek8,7 | — | %0,6 | 3 Oca 2025 |
34İzleyin | CVE-2025-59781İstismar yok | BIG-IP DNS cache vulnerabilityf5 · big-ip access policy manager · CWE-459 | Yüksek8,7 | — | %0,3 | 15 Eki 2025 |
- CVE-2017-1709055Planlayın
An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified As
YüksekCVSS 7,5Kavram kanıtıEPSS %82digium · certified asterisk1 Ara 2017
- CVE-2025-3165048Planlayın
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
YüksekCVSS 7,5Kavram kanıtıEPSS %61apache · tomcat28 Nis 2025
- CVE-2022-155240Planlayın
A flaw was found in PostgreSQL.
YüksekCVSS 8,8İstismar yokEPSS %16postgresql · postgresql31 Ağu 2022
- CVE-2020-1345140Planlayın
An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice co
KritikCVSS 9,8İstismar yokEPSS %3thecodingmachine · gotenberg7 Oca 2021
- CVE-2005-174440Planlayın
BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows t
KritikCVSS 9,8İstismar yokEPSS %2bea · weblogic server24 May 2005
- CVE-2021-4533039İzleyin
An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and t
KritikCVSS 9,8İstismar yokEPSS %1gitea · gitea9 Şub 2022
- CVE-2022-4534739İzleyin
Apache ShardingSphere-Proxy: MySQL authentication bypass
KritikCVSS 9,8İstismar yokEPSS %1apache · shardingsphere22 Ara 2022
- CVE-2021-3292839İzleyin
The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Manager” that allows i
KritikCVSS 9,8İstismar yokEPSS %1thalesgroup · sentinel ldk run-time environment16 Haz 2021
- CVE-2021-4570639İzleyin
An issue was discovered in the zeroize_derive crate before 1.1.1 for Rust.
KritikCVSS 9,8İstismar yokEPSS %1zeroize derive project · zeroize derive26 Ara 2021
- CVE-2021-3620539İzleyin
Metasys session token
KritikCVSS 9,8İstismar yokEPSS %1johnsoncontrols · metasys application and data server15 Nis 2022
- CVE-2026-2826839İzleyin
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse
KritikCVSS 9,8İstismar yokEPSS %1vikunja · vikunja27 Şub 2026
- CVE-2018-1892438İzleyin
The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" be
YüksekCVSS 8,8Kavram kanıtıEPSS %9projeqtor · projeqtor4 Kas 2018
- CVE-2026-3426338İzleyin
Missing authentication check in SAP Commerce cloud configuration
KritikCVSS 9,6İstismar yokEPSS %1sap_se · sap commerce cloud configuration11 May 2026
- CVE-2019-2501636İzleyin
In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed
YüksekCVSS 8,8İstismar yokEPSS %3opendoas project · opendoas28 Oca 2021
- CVE-2019-1819136İzleyin
A privilege escalation vulnerability in the Trend Micro Deep Security as a Service Quick Setup cloud formation template could allow an authe
YüksekCVSS 8,8İstismar yokEPSS %2trendmicro · deep security as a service16 Ara 2019
- CVE-2023-3646836İzleyin
Upgrading doesn't prevent exploiting vulnerable XWiki documents
YüksekCVSS 8,8İstismar yokEPSS %2xwiki · xwiki29 Haz 2023
- CVE-2024-2826536İzleyin
IBOS v4.5.5 has an arbitrary file deletion vulnerability via \system\modules\dashboard\controllers\LoginController.php.
KritikCVSS 9,1İstismar yokEPSS %0ibos · ibos1 Kas 2024
- CVE-2026-8504336İzleyin
Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via cra
KritikCVSS 9,1İstismar yokEPSS %0google · chrome3 Eyl 2026
- CVE-2025-633836İzleyin
Possible denial of service with multiple incoming connections to a Schannel based server with a TLS backend
KritikCVSS 9,2İstismar yokEPSS %0qt · qt16 Eki 2025
- CVE-2026-1539036İzleyin
Out-of-bounds write in Das U-Boot
KritikCVSS 9,0İstismar yokdenx software engineering · das u-boot1 gün önce
- CVE-2020-2448935İzleyin
Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local ac
YüksekCVSS 8,8İstismar yokEPSS %0intel · atom x5-e39309 Haz 2021
- CVE-2026-330434İzleyin
Multer vulnerable to Denial of Service via incomplete cleanup
YüksekCVSS 8,7Kavram kanıtıEPSS %1expressjs · multer27 Şub 2026
- CVE-2026-5273634İzleyin
ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cache
YüksekCVSS 8,7İstismar yokEPSS %1zcashfoundation · zebra18 Ağu 2026
- CVE-2025-2160934İzleyin
SiYuan has an arbitrary file deletion vulnerability
YüksekCVSS 8,7İstismar yokEPSS %1b3log · siyuan3 Oca 2025
- CVE-2025-5978134İzleyin
BIG-IP DNS cache vulnerability
YüksekCVSS 8,7İstismar yokEPSS %0f5 · big-ip access policy manager15 Eki 2025