CWE-459— Incomplete Cleanup
The product does not properly "clean up" and remove temporary or supporting resources after they have been used.— MITRE CWE catalog
237 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-459page 1 of 5
- CVE-2023-36468CRITICALCVSS 9.9EG 9.92023-06-29
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an XWiki installation is upgraded and that upgrade contains a fix for a bug in a document, just a new version of that document is…
- CVE-2026-28268CRITICALCVSS 9.8EG 9.82026-02-27
Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api that allows password reset tokens to be reused indefinitely. …
- CVE-2022-45347CRITICALCVSS 9.8EG 9.82022-12-22
Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session completely after client authentication failed, which allowed an attacker to execute normal commands by constructing a speci…
- CVE-2021-45330CRITICALCVSS 9.8EG 9.82022-02-09
An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse.
- CVE-2021-45706CRITICALCVSS 9.8EG 9.82021-12-27
An issue was discovered in the zeroize_derive crate before 1.1.1 for Rust. Dropped memory is not zeroed out for an enum.
- CVE-2021-32928CRITICALCVSS 9.8EG 9.82021-06-16
The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Manager” that allows incoming connections from private networks using TCP Port 1947. While uninstalling, the uninstal…
- CVE-2020-13451CRITICALCVSS 9.8EG 9.82021-01-07
An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files and execute arbitrary code via macros.
- CVE-2021-36205CRITICALCVSS 8.1EG 9.82022-04-15
Under certain circumstances the session token is not cleared on logout.
- CVE-2026-106375CRITICALCVSS 9.6EG 9.62026-10-06
Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-34263CRITICALCVSS 9.6EG 9.62026-05-12
Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity,…
- CVE-2025-6338CRITICALCVSS 9.2EG 9.22025-10-16
There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of Service over a long period. This issue affects Qt from 5.15.0 through 6.8.3, from 6.9.0 before 6.9.2.
- CVE-2026-106294CRITICALCVSS 9.1EG 9.12026-10-06
Incomplete cleanup in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)
- CVE-2026-85043CRITICALCVSS 9.1EG 9.12026-09-03
Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: High)
- CVE-2025-21609CRITICALCVSS 9.1EG 9.12025-01-03
SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability. The vulnerability exists in the `POST /api/history/getDocHistoryContent` endpoint. An attac…
- CVE-2024-28265CRITICALCVSS 9.1EG 9.12024-11-01
IBOS v4.5.5 has an arbitrary file deletion vulnerability via \system\modules\dashboard\controllers\LoginController.php.
- CVE-2026-15390CRITICALCVSS 9.0EG 9.02026-09-29
Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP pa…
- CVE-2017-17090HIGHCVSS 7.5EG 8.92017-12-02
An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the chan_skinny (aka SCCP protocol) channel driver is flooded with…
- CVE-2026-106203HIGHCVSS 8.8EG 8.82026-10-06
Incomplete cleanup in Autofill in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
- CVE-2022-1552HIGHCVSS 8.8EG 8.82022-08-31
A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW, CLUSTER, and pg_amc…
- CVE-2020-24489HIGHCVSS 8.8EG 8.82021-06-09
Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2019-25016HIGHCVSS 8.8EG 8.82021-01-28
In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed the user to execute any command. Rules that only allowed to authenticated user to execute specific…
- CVE-2019-18191HIGHCVSS 8.8EG 8.82019-12-16
A privilege escalation vulnerability in the Trend Micro Deep Security as a Service Quick Setup cloud formation template could allow an authenticated entity with certain unrestricted AWS execution privileges to escalate to full privileges w…
- CVE-2018-18924HIGHCVSS 8.8EG 8.82018-11-04
The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" because rejected files remain on the server, with predictable filenames, after a "This file is not a …
- CVE-2026-106366HIGHEG 8.82026-10-06
Incomplete cleanup in CustomTabs in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-52736HIGHCVSS 8.7EG 8.72026-07-02
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remote unauthenticated P2P peer can stall a Zebra node by racing an invalid block body against the valid canonical body for the same block header hash. ZIP-244 permits the a…
- CVE-2025-31650HIGHCVSS 7.5EG 8.52025-04-28
Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests co…
- CVE-2026-95326HIGHCVSS 8.4EG 8.42026-09-29
Incomplete cleanup in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
- CVE-2022-27639HIGHCVSS 5.4EG 8.42022-11-11
Incomplete cleanup in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via adjacent access.
- CVE-2025-66675HIGHCVSS 8.2EG 8.22025-12-10
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3. Users are recommended to upgrade to…
- CVE-2022-39368HIGHCVSS 8.2EG 8.22022-11-10
Eclipse Californium is a Java implementation of RFC7252 - Constrained Application Protocol for IoT Cloud services. In versions prior to 3.7.0, and 2.7.4, Californium is vulnerable to a Denial of Service. Failing handshakes don't cleanup co…
- CVE-2025-66467HIGHCVSS 8.1EG 8.12026-05-08
Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user creates a new bucket with the same name, the previous owners can gain unauthorized …
- CVE-2025-43711HIGHCVSS 8.1EG 8.12025-07-05
Tunnelblick 3.5beta06 before 7.0, when incompletely uninstalled, allows attackers to execute arbitrary code as root (upon the next boot) by dragging a crafted Tunnelblick.app file into /Applications.
- CVE-2021-22428HIGHCVSS 8.1EG 8.12021-08-02
There is an Incomplete Cleanup Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to authentication bypass.
- CVE-2021-39327HIGHCVSS 5.3EG 8.12021-09-17
The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the site, in addition to …
- CVE-2026-107914HIGHCVSS 7.8EG 7.82026-10-09
Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive. This vulnerability is mitigated by the fact that an export must have been previously requested …
- CVE-2026-7639HIGHCVSS 7.8EG 7.82026-07-10
Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use after free, which helps in facilitating unprivileged memory access from a shader code. Triggering failure path in the MM…
- CVE-2025-37908HIGHCVSS 7.8EG 7.82025-05-20
In the Linux kernel, the following vulnerability has been resolved: mm, slab: clean up slab->obj_exts always When memory allocation profiling is disabled at runtime or due to an error, shutdown_mem_profiling() is called: slab->obj_exts w…
- CVE-2022-45455HIGHCVSS 7.8EG 7.82023-02-13
Local privilege escalation due to incomplete uninstallation cleanup. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107, Acronis Agent (Windows) before build 30025, Acronis Cyber Protect 15 …
- CVE-2022-3238HIGHCVSS 7.8EG 7.82022-11-14
A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to crash or potentially escalate their privileges on the system.
- CVE-2022-0646HIGHCVSS 7.8EG 7.82022-02-18
A flaw use after free in the Linux kernel Management Component Transport Protocol (MCTP) subsystem was found in the way user triggers cancel_work_sync after the unregister_netdev during removing device. A local user could use this flaw to …
- CVE-2020-5987HIGHCVSS 7.8EG 7.82020-10-02
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin in which guest-supplied parameters remain writable by the guest after the plugin has validated them, which may lead to the guest being able to pass invalid parameters t…
- CVE-2020-0183HIGHCVSS 7.8EG 7.82020-06-11
In handleMessage of BluetoothManagerService, there is an incomplete reset. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersion…
- CVE-2018-19961HIGHCVSS 7.8EG 7.82018-12-08
An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes.
- CVE-2018-18281HIGHCVSS 7.8EG 7.82018-10-30
Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes after dropping pagetable locks. If a syscall such as ftruncate() removes entries from the pagetables of a task that is in the middle of mremap(), a stale TLB entry c…
- CVE-2025-60730HIGHCVSS 7.6EG 7.62025-10-24
PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function
- CVE-2026-87776HIGHCVSS 7.5EG 7.52026-09-11
compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never destroye…
- CVE-2026-77037HIGHCVSS 7.5EG 7.52026-08-28
multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is aborted or truncated before the write stream finishes, multer's disk storage engine removes the visible file but does not cl…
- CVE-2026-19474HIGHCVSS 7.5EG 7.52026-08-15
@fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can leave completed temporary files on disk when a client disconnects while the parser is adv…
- CVE-2026-42492HIGHCVSS 7.5EG 7.52026-07-28
Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To make this more robust, a new XEN_DOMCTL_get_domain_state was introduced. The management of the bitmap underlying that o…
- CVE-2026-11576HIGHCVSS 7.5EG 7.52026-06-19
The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx_file_close() even when the file …
Map vulnerabilities like CWE-459 to your infrastructure
EchelonGraph correlates every CVE — across CWE-459 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →