CWE-459— Incomplete Cleanup
The product does not properly "clean up" and remove temporary or supporting resources after they have been used.— MITRE CWE catalog
221 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-459page 4 of 5
- CVE-2024-50385MEDIUMCVSS 6.5EG 6.52025-04-02
A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packe…
- CVE-2024-53869MEDIUMCVSS 5.5EG 5.52025-01-28
NVIDIA Unified Memory driver for Linux contains a vulnerability where an attacker could leak uninitialized memory. A successful exploit of this vulnerability might lead to information disclosure.
- CVE-2024-53881MEDIUMCVSS 5.5EG 5.52025-01-28
NVIDIA vGPU software contains a vulnerability in the host driver, where it can allow a guest to cause an interrupt storm on the host, which may lead to denial of service.
- CVE-2024-57975MEDIUMCVSS 5.5EG 5.52025-02-27
In the Linux kernel, the following vulnerability has been resolved: btrfs: do proper folio cleanup when run_delalloc_nocow() failed [BUG] With CONFIG_DEBUG_VM set, test case generic/476 has some chance to crash with the following VM_BUG_…
- CVE-2024-57976MEDIUMCVSS 5.5EG 5.52025-02-27
In the Linux kernel, the following vulnerability has been resolved: btrfs: do proper folio cleanup when cow_file_range() failed [BUG] When testing with COW fixup marked as BUG_ON() (this is involved with the new pin_user_pages*() change,…
- CVE-2024-6300LOWCVSS 3.7EG 3.72024-06-25
Incomplete cleanup when performing redactions in Conduit, allowing an attacker to check whether certain strings were present in the PDU before redaction
- CVE-2025-0032HIGHCVSS 7.2EG 7.22025-09-06
Improper cleanup in AMD CPU microcode patch loading could allow an attacker with local administrator privilege to load malicious CPU microcode, potentially resulting in loss of integrity of x86 instruction execution.
- CVE-2025-0473MEDIUMCVSS 6.5EG 6.52025-01-16
Vulnerability in the PMB platform that allows an attacker to persist temporary files on the server, affecting versions 4.0.10 and above. This vulnerability exists in the file upload functionality on the ‘/pmb/authorities/import/iimport_a…
- CVE-2025-0726HIGHCVSS 7.5EG 7.52025-02-21
In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause a denial of service by specially crafted packets. The core issue is missing closing of a file in case of an error condition, resul…
- CVE-2025-15331MEDIUMCVSS 4.3EG 4.32026-02-05
Tanium addressed an uncontrolled resource consumption vulnerability in Connect.
- CVE-2025-20293MEDIUMCVSS 5.3EG 5.32025-09-24
A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for Cloud (9800-CL) could allow an unauthenticated, remote attacker to access the public-key infrastructure (PKI) server th…
- CVE-2025-21609CRITICALCVSS 9.1EG 9.12025-01-03
SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability. The vulnerability exists in the `POST /api/history/getDocHistoryContent` endpoint. An attac…
- CVE-2025-21924MEDIUMCVSS 5.5EG 5.52025-04-01
In the Linux kernel, the following vulnerability has been resolved: net: hns3: make sure ptp clock is unregister and freed if hclge_ptp_get_cycle returns an error During the initialization of ptp, hclge_ptp_get_cycle might return an erro…
- CVE-2025-2260HIGHCVSS 7.5EG 7.52025-04-06
In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause a denial of service by specially crafted packets. The core issue is missing closing of a file in case of an error condition, resul…
- CVE-2025-29934MEDIUMCVSS 5.3EG 5.32025-11-21
A bug within some AMD CPUs could allow a local admin-privileged attacker to run a SEV-SNP guest using stale TLB entries, potentially resulting in loss of data integrity.
- CVE-2025-31650HIGHCVSS 7.5EG 8.52025-04-28
Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests co…
- CVE-2025-37908HIGHCVSS 7.8EG 7.82025-05-20
In the Linux kernel, the following vulnerability has been resolved: mm, slab: clean up slab->obj_exts always When memory allocation profiling is disabled at runtime or due to an error, shutdown_mem_profiling() is called: slab->obj_exts w…
- CVE-2025-38177MEDIUMCVSS 5.5EG 5.52025-07-04
In the Linux kernel, the following vulnerability has been resolved: sch_hfsc: make hfsc_qlen_notify() idempotent hfsc_qlen_notify() is not idempotent either and not friendly to its callers, like fq_codel_dequeue(). Let's make it idempote…
- CVE-2025-43711HIGHCVSS 8.1EG 8.12025-07-05
Tunnelblick 3.5beta06 before 7.0, when incompletely uninstalled, allows attackers to execute arbitrary code as root (upon the next boot) by dragging a crafted Tunnelblick.app file into /Applications.
- CVE-2025-55910MEDIUMCVSS 6.3EG 6.32025-09-19
CMSEasy v7.7.8.0 and before is vulnerable to Arbitrary file deletion in database_admin.php.
- CVE-2025-59781HIGHCVSS 7.5EG 7.52025-10-15
When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undisclosed DNS queries can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are no…
- CVE-2025-60730HIGHCVSS 7.6EG 7.62025-10-24
PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function
- CVE-2025-6338CRITICALCVSS 9.2EG 9.22025-10-16
There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of Service over a long period. This issue affects Qt from 5.15.0 through 6.8.3, from 6.9.0 before 6.9.2.
- CVE-2025-64775HIGHCVSS 7.5EG 7.52025-12-01
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.0, from 7.0.0 through 7.0.3. Users are recommended to upgrade to…
- CVE-2025-66467HIGHCVSS 8.0EG 8.02026-05-08
Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user creates a new bucket with the same name, the previous owners can gain unauthorized …
- CVE-2025-66675HIGHCVSS 8.2EG 8.22025-12-10
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3. Users are recommended to upgrade to…
- CVE-2026-0427MEDIUMCVSS 4.6EG 4.62026-05-15
Improper cleanup of shared register resources in GPU firmware could allow an admin-privileged attacker from a Guest Virtual machine (VM) to access these shared resources from another Guest VM, potentially resulting in the loss of confident…
- CVE-2026-11576HIGHCVSS 7.5EG 7.52026-06-19
The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx_file_close() even when the file …
- CVE-2026-19019MEDIUMCVSS 4.8EG 4.82026-08-06
A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager._setup_session_persistence of the file executor/app/core/workspace.py of the component Claude File Handler. The manipulation r…
- CVE-2026-19474HIGHCVSS 7.5EG 7.52026-08-15
@fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can leave completed temporary files on disk when a client disconnects while the parser is adv…
- CVE-2026-19730MEDIUMCVSS 4.2EG 4.22026-08-13
The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL default…
- CVE-2026-20712MEDIUMCVSS 4.0EG 4.02026-08-11
Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure…
- CVE-2026-21438MEDIUMCVSS 5.3EG 5.32026-02-12
webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memory consumption repeatedly creating and closing many WebTransport streams. Closed streams were not removed from an inter…
- CVE-2026-28196LOWCVSS 2.3EG 2.32026-02-25
In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk
- CVE-2026-28268CRITICALCVSS 9.8EG 9.82026-02-27
Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api that allows password reset tokens to be reused indefinitely. …
- CVE-2026-3304HIGHCVSS 7.5EG 7.52026-02-27
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaust…
- CVE-2026-33232HIGHCVSS 7.5EG 7.52026-05-19
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.4.2 through 0.6.51 are vulnerable to an unauthenticated Denial of Service (DoS) through the server due to…
- CVE-2026-34263CRITICALCVSS 9.6EG 9.62026-05-12
Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity,…
- CVE-2026-35361LOWCVSS 3.4EG 3.42026-04-22
The mknod utility in uutils coreutils fails to handle security labels atomically by creating device nodes before setting the SELinux context. If labeling fails, the utility attempts cleanup using std::fs::remove_dir, which cannot remove de…
- CVE-2026-42492HIGHCVSS 7.5EG 7.52026-07-28
Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To make this more robust, a new XEN_DOMCTL_get_domain_state was introduced. The management of the bitmap underlying that o…
- CVE-2026-43395MEDIUMCVSS 5.5EG 5.52026-05-08
In the Linux kernel, the following vulnerability has been resolved: drm/xe/sync: Cleanup partially initialized sync on parse failure xe_sync_entry_parse() can allocate references (syncobj, fence, chain fence, or user fence) before hittin…
- CVE-2026-5038HIGHCVSS 7.5EG 7.52026-06-15
Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orphaned partial files on disk because the Readable.pipe() cal…
- CVE-2026-52733MEDIUMCVSS 6.5EG 6.52026-07-02
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave stale Sapling and Orchard note-commitment subtree roots in Zebra state. In zebra-state/src/service/non_finalized_state/ch…
- CVE-2026-52736HIGHCVSS 8.7EG 8.72026-07-02
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remote unauthenticated P2P peer can stall a Zebra node by racing an invalid block body against the valid canonical body for the same block header hash. ZIP-244 permits the a…
- CVE-2026-53867MEDIUMCVSS 4.3EG 4.32026-06-12
Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remove them. Attackers can access orphaned image files through previously generated URLs, allowing unauthorized retrieval o…
- CVE-2026-63545LOWCVSS 2.4EG 2.42026-08-03
Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users.
- CVE-2026-67334LOWCVSS 3.8EG 3.82026-08-01
better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeSessionInDatabase is false. Attackers can reuse deleted user session…
- CVE-2026-67442LOWCVSS 2.0EG 2.02026-08-18
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.3, DELETE /api/roles removes role definitions through server/runtime/users/usrstorage.js but does not remove the deleted role identifier from each user'…
- CVE-2026-6830LOWCVSS 3.3EG 3.32026-04-21
nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before loading the next profile. Attackers or users can exploit ad…
- CVE-2026-68809MEDIUMCVSS 5.5EG 5.52026-08-11
Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
Map vulnerabilities like CWE-459 to your infrastructure
EchelonGraph correlates every CVE — across CWE-459 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →