CWE-772

High likelihood

Missing Release of Resource after Effective Lifetime

Parent: CWE-404 - Improper Resource Shutdown or Release

The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.

472 vulnerabilities with CWE-772
CVE-2026-32874 HIGH
UltraJSON 5.4.0-5.11.0 - Large Integer Memory Leak Denial of Service
CVSS 7.5
CVE-2026-2261 HIGH
FreeBSD >=15.0-RELEASE <p3 - Denial of Service via Socket Descriptor Leak
CVSS 7.5
CVE-2026-26999 HIGH
Traefik < 2.11.38 - Unauthenticated Denial of Service via TLS Handshake Stall
CVSS 7.5
CVE-2026-1605 HIGH
Eclipse Jetty 12.0.0-12.0.31/12.1.0-12.0.5 - Memory Corruption
CVSS 7.5
CVE-2026-20082 HIGH
Cisco Adaptive Security Appliance Software 9.20.4.14-9.20.4.18 - Unauthenticated Denial of Service via TCP SYN Flood
CVSS 8.6
CVE-2026-2359 HIGH
Multer < 2.1.0 - Denial of Service via Connection Drop During File Upload
CVSS 7.5
CVE-2026-23219 MEDIUM
Linux Kernel 6.10-6.12.69, 6.13-6.18.9 - Use-After-Free in memcg_alloc_abort_single
CVSS 5.5
CVE-2026-23185 HIGH
Linux Kernel 6.17-6.18.10 - Use-After-Free in iwlwifi mlo_scan_start_wk
CVSS 7.8
CVE-2026-21720 HIGH
Grafana 3.0.0-11.6.8, 12.0.0-12.0.7, 12.1.0-12.1.4, 12.2.0-12.2.2, 12.3.0 - Resource Consumption via Gravatar
CVSS 7.5
CVE-2026-21874 MEDIUM
NiceGUI 2.10.0-3.4.1 - Unauthenticated Resource Exhaustion via Redis Connection Leak
CVSS 5.3
CVE-2025-71232 MEDIUM
Linux Kernel - Use-After-Free in qla2xxx SCSI Driver
CVSS 5.5
CVE-2025-14969 MEDIUM
hibernate-reactive-core < 4.2.1 - Denial of Service via Premature HTTP Connection Closure
CVSS 4.3
CVE-2025-65947 HIGH
thread-amount <0.2.2 - Resource Leak
CVE-2025-64734 LOW
Command Centre Server <9.30.251028a-9.10.251028a - DoS
CVSS 2.4
CVE-2025-54983 MEDIUM
Zscaler Client Connector <4.6.0.216-<4.7.0.47 - Use After Free
CVSS 5.2
CVE-2025-62723 MEDIUM
FlashMQ < 1.23.2 - Authenticated Resource Exhaustion via Unreleased QoS Message Sessions
CVSS 4.3
CVE-2025-36128 HIGH
IBM MQ 9.1-9.4 - Denial of Service via Slowloris-Type Attack
CVSS 7.5
CVE-2025-61670 LOW
Wasmtime 37.0.0-37.0.1 - Memory Leak in C/C++ API via anyref and externref Handling
CVSS 3.3
CVE-2025-30256 HIGH
Tenda AC6 V5.0 V02.03.01.110 - Denial of Service via HTTP Header Parsing
CVSS 8.6
CVE-2025-36071 MEDIUM
IBM Db2 11.5.0-11.5.9 and 12.1.0-12.1.2 - Denial of Service via Specially Crafted Query
CVSS 6.5
CVE-2025-44003 MEDIUM
Gallagher T-Series Reader <9.20.250213a, <9.10.2692(MR5), <9.00.337...
CVSS 4.3
CVE-2025-0036 LOW
AMD Versal Adaptive SoC - Memory Corruption
CVSS 3.2
CVE-2025-3864 LOW
Hackney < 1.24.0 - Denial of Service via HTTP Connection Pool Exhaustion
CVE-2025-27421 HIGH
Abacus < 1.4.0 - Denial of Service via SSE Connection Goroutine Leak
CVSS 7.5
CVE-2025-22891 HIGH
BIG-IP Policy Enforcement Manager 15.1.0-15.1.10.6.0.11.6 - Denial of Service via Diameter Endpoint Profile
CVSS 7.5
Details
Vulnerabilities 472
Exploit Likelihood High