CWE-672
73 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-672page 2 of 2
- CVE-2024-56674MEDIUMCVSS 5.5EG 5.52024-12-27
In the Linux kernel, the following vulnerability has been resolved: virtio_net: correct netdev_tx_reset_queue() invocation point When virtnet_close is followed by virtnet_open, some TX completions can possibly remain unconsumed, until th…
- CVE-2024-57929HIGHCVSS 7.1EG 7.12025-01-19
In the Linux kernel, the following vulnerability has been resolved: dm array: fix releasing a faulty array block twice in dm_array_cursor_end When dm_bm_read_lock() fails due to locking or checksum errors, it releases the faulty block im…
- CVE-2025-10060MEDIUMCVSS 6.5EG 6.52025-09-05
MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, potentially causing an invariant failure and server crash during commit. This issue may be triggered by improper WriteUnitOfWork s…
- CVE-2025-21117MEDIUMCVSS 6.6EG 6.62025-02-05
Dell Avamar, version 19.4 or later, contains an access token reuse vulnerability in the AUI. A low privileged local attacker could potentially exploit this vulnerability, leading to fully impersonating the user.
- CVE-2025-22149LOWCVSS 2.1EG 0.02025-01-09
JWK Set (JSON Web Key Set) is a JWK and JWK Set Go implementation. Prior to 0.6.0, the project's provided HTTP client's local JWK Set cache should do a full replacement when the goroutine refreshes the remote JWK Set. The current behavior …
- CVE-2025-2517LOWCVSS 2.3EG 0.02025-04-21
Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager.
- CVE-2025-30351LOWCVSS 3.5EG 3.52025-03-26
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.10.0 and prior to version 11.5.0, a suspended user can use the token generated in session auth mode to access the API despite their sta…
- CVE-2025-31253HIGHCVSS 7.1EG 7.12025-05-12
This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5. Muting the microphone during a FaceTime call may not result in audio being silenced.
- CVE-2025-38290MEDIUMCVSS 5.5EG 5.52025-07-10
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix node corruption in ar->arvifs list In current WLAN recovery code flow, ath12k_core_halt() only reinitializes the "arvifs" list head. This will cause th…
- CVE-2025-39698MEDIUMCVSS 5.5EG 8.82025-09-05
In the Linux kernel, the following vulnerability has been resolved: io_uring/futex: ensure io_futex_wait() cleans up properly on failure The io_futex_data is allocated upfront and assigned to the io_kiocb async_data field, but the reques…
- CVE-2025-53901LOWCVSS 3.5EG 3.52025-07-18
Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.4, 33.0.2, and 34.0.2, a bug in Wasmtime's implementation of the WASIp1 set of import functions can lead to a WebAssembly guest inducing a panic in the host (embedder). The spec…
- CVE-2025-55669HIGHCVSS 7.5EG 7.52025-10-15
When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which…
- CVE-2025-58149HIGHCVSS 7.5EG 7.52025-10-31
When passing through PCI devices, the detach logic in libxl won't remove access permissions to any 64bit memory BARs the device might have. As a result a domain can still have access any 64bit memory BAR when such device is no longer assi…
- CVE-2025-6031HIGHCVSS 7.5EG 7.52025-06-12
Amazon Cloud Cam is a home security camera that was deprecated on December 2, 2022, is end of life, and is no longer actively supported. When a user powers on the Amazon Cloud Cam, the device attempts to connect to a remote service infra…
- CVE-2025-69415HIGHCVSS 7.1EG 7.12026-01-02
In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is currently associated with an account.
- CVE-2026-1237LOWCVSS 2.1EG 0.02026-01-28
Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to update database records can mint an invalid macaroon that is incorrectly validated by the juju contro…
- CVE-2026-32244MEDIUMCVSS 5.3EG 5.32026-05-19
Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, outdated cached AI summaries can leak removed content to anonymous and unprivileged users who cannot regenerate summa…
- CVE-2026-33278CRITICALCVSS 9.8EG 9.82026-05-20
NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwri…
- CVE-2026-33463MEDIUMCVSS 5.3EG 5.32026-05-28
Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can lead to unauthorized information disclosure. A logic error in how expiration timestamps were validated allowed a time-bounded access token to remain usable bey…
- CVE-2026-4053LOWCVSS 3.1EG 3.12026-05-15
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, and pin status after the edit window has …
- CVE-2026-42791LOWCVSS 3.7EG 3.72026-05-27
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows forged OCSP responses signed with an expired responder certificate to be accepted as valid. OCSP response verification in pubkey_ocsp:verif…
- CVE-2026-43585HIGHCVSS 8.1EG 8.12026-05-06
OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain valid after SecretRef rotation. Gateway HTTP and WebSocket handlers fail to re-resolve authentication per-request, enabling…
- CVE-2026-45005MEDIUMCVSS 6.0EG 6.02026-05-11
OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to remain valid after rotation and reload. Attackers with previously valid webhook route secrets can continue authenticating…
Map vulnerabilities like CWE-672 to your infrastructure
EchelonGraph correlates every CVE — across CWE-672 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →