The product does not properly "clean up" and remove temporary or supporting resources after they have been used.
189 vulnerabilities with CWE-459
CVE-2026-5038
MEDIUM
multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads
CVSS 5.3
CVE-2026-53867
MEDIUM
Capgo < 12.128.2 - Orphaned File Retention via Profile Image Replacement
CVSS 4.3
CVE-2026-33232
HIGH
AutoGPT: Unauthenticated DoS via Disk Space Exhaustion
CVSS 7.5
CVE-2026-0427
MEDIUM
AMD Instinct MI210/MI300X/MI325X >=GIM 8.2.0.K - Incomplete Cleanup of Shared Register Resources
CVE-2026-34263
CRITICAL
Missing authentication check in SAP Commerce cloud configuration
CVSS 9.6
CVE-2026-43395
MEDIUM
drm/xe/sync: Cleanup partially initialized sync on parse failure
CVSS 5.5
CVE-2026-35361
LOW
uutils coreutils mknod Security Label Inconsistency and Broken Cleanup on SELinux Systems
CVSS 3.4
CVE-2026-6830
LOW
Nesquena Hermes WebUI Environment Variable Credential Leakage via Profile Switch
CVSS 3.3
CVE-2026-28268
CRITICAL
Vikunja < 2.1.0 - Persistent Account Takeover via Password Reset Token Reuse
CVSS 9.8
CVE-2026-3304
HIGH
Multer < 2.1.0 - Denial of Service via Malformed Request Handling
CVSS 7.5
CVE-2026-28196
LOW
JetBrains TeamCity <2025.11.3 - Info Disclosure
CVSS 2.3
CVE-2026-21438
MEDIUM
webtransport-go < 0.10.0 - Denial of Service via Unbounded Memory Consumption
CVSS 5.3
CVE-2025-66467
HIGH
Apache CloudStack: MinIO policy remains intact on bucket deletion
CVSS 8.0
CVE-2025-15331
MEDIUM
Tanium Connect 5.22.0-5.22.99 - Uncontrolled Resource Consumption
CVSS 4.3
CVE-2025-66675
HIGH
Apache Struts 2.0.0-6.7.4, 7.0.0-7.0.3 - Denial of Service via Multipart Request File Leak
CVSS 8.2
CVE-2025-64775
HIGH
Apache Struts 2.0.0-6.7.0 and 7.0.0-7.0.3 - Denial of Service via Multipart Request Processing
CVSS 7.5
CVE-2025-29934
MEDIUM
AMD EPYC 9004/9005/8004/Embedded 7003/9004/9005/8004 Series Processors - Incomplete Cleanup via Stale TLB Entries
CVSS 5.3
CVE-2025-60730
HIGH
PerfreeBlog v4.0.11 - Path Traversal
CVSS 7.6
CVE-2025-6338
CRITICAL
Qt <6.9.2 - Denial of Service
CVE-2025-59781
HIGH
F5 BIG-IP - Denial of Service via DNS Cache Memory Exhaustion
CVSS 7.5
CVE-2025-20293
MEDIUM
Cisco IOS XE Software - Unauthenticated PKI Server Access via Incomplete Day One Setup Cleanup
CVSS 5.3
CVE-2025-55910
MEDIUM
CMSEasy < 7.7.8.0 - Arbitrary File Deletion via database_admin.php
CVSS 6.3
CVE-2025-0032
HIGH
AMD CPU microcode - Privilege Escalation
CVSS 7.2
CVE-2025-43711
HIGH
Tunnelblick 3.5beta06-7.0 - Unauthenticated Arbitrary Code Execution via Crafted Application Bundle
CVSS 8.1
CVE-2025-38177
MEDIUM
Linux Kernel - Incomplete Cleanup in sch_hfsc
CVSS 5.5
Details
Vulnerabilities
189