CWE-459— Incomplete Cleanup
The product does not properly "clean up" and remove temporary or supporting resources after they have been used.— MITRE CWE catalog
237 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-459page 5 of 5
- CVE-2018-17467MEDIUMCVSS 4.3EG 4.32018-11-14
Insufficiently quick clearing of stale rendered content in Navigation in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- CVE-2021-34421MEDIUMCVSS 3.7EG 4.32021-11-11
The Keybase Client for Android before version 5.8.0 and the Keybase Client for iOS before version 5.8.0 fails to properly remove exploded messages initiated by a user if the receiving user places the chat session in the background while th…
- CVE-2026-106262MEDIUMCVSS 4.2EG 4.22026-10-06
Incomplete cleanup in GetUserMedia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security…
- CVE-2026-19730MEDIUMCVSS 4.2EG 4.22026-08-13
The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL default…
- CVE-2018-12332MEDIUMCVSS 4.2EG 4.22018-06-17
Incomplete Cleanup vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys via a compromised host PC after a reset.
- CVE-2026-20712MEDIUMCVSS 4.0EG 4.02026-08-11
Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure…
- CVE-2024-45445MEDIUMCVSS 4.0EG 4.02024-09-04
Vulnerability of resources not being closed or released in the keystore module Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2026-67334LOWCVSS 3.8EG 3.82026-08-01
better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeSessionInDatabase is false. Attackers can reuse deleted user session…
- CVE-2022-2307LOWCVSS 3.5EG 3.82022-08-05
A lack of cascading deletes in GitLab CE/EE affecting all versions starting from 13.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious Group Owner to retain a us…
- CVE-2024-6300LOWCVSS 3.7EG 3.72024-06-25
Incomplete cleanup when performing redactions in Conduit, allowing an attacker to check whether certain strings were present in the PDU before redaction
- CVE-2026-78600LOWCVSS 3.5EG 3.52026-09-02
Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, …
- CVE-2026-9693LOWCVSS 3.5EG 3.52026-08-17
Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view…
- CVE-2026-35361LOWCVSS 3.4EG 3.42026-04-22
The mknod utility in uutils coreutils fails to handle security labels atomically by creating device nodes before setting the SELinux context. If labeling fails, the utility attempts cleanup using std::fs::remove_dir, which cannot remove de…
- CVE-2026-6830LOWCVSS 3.3EG 3.32026-04-21
nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before loading the next profile. Attackers or users can exploit ad…
- CVE-2024-1048LOWCVSS 3.3EG 3.32024-02-06
A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed…
- CVE-2022-43477LOWCVSS 3.3EG 3.32023-11-14
Incomplete cleanup for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2022-28764LOWCVSS 3.3EG 3.32022-11-14
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the u…
- CVE-2019-8730LOWCVSS 3.3EG 3.32019-12-18
The contents of locked notes sometimes appeared in search results. This issue was addressed with improved data cleanup. This issue is fixed in macOS Catalina 10.15. A local user may be able to view a user’s locked notes.
- CVE-2024-21977LOWCVSS 3.2EG 3.22025-09-05
Incomplete cleanup after loading a CPU microcode patch may allow a privileged attacker to degrade the entropy of the RDRAND instruction, potentially resulting in loss of integrity for SEV-SNP guests.
- CVE-2023-29184LOWCVSS 3.2EG 3.22025-06-10
An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 allows a VDOM privileged attacker to add SSH key files on the system silently via crafted CLI r…
- CVE-2026-91730LOWCVSS 3.1EG 3.12026-09-15
Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain cross-origin data via a crafted HTML page. (Chromium s…
- CVE-2026-82237LOWCVSS 3.1EG 3.12026-08-28
filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cleanup). The share record is keyed by path, so it survives the rename and remains dormant (returning 404 while the path …
- CVE-2026-82236LOWCVSS 3.1EG 3.12026-08-28
File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can access the surviving share link to retrieve new unrelated content uploaded to th…
- CVE-2026-78903LOWCVSS 3.1EG 3.12026-08-25
Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2022-29160LOWCVSS 2.8EG 2.82022-05-20
Nextcloud Android is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.0, sensitive tokens, images, and user related details exist after deletion of a user account. This could result in misuse of …
- CVE-2023-2400LOWCVSS 2.7EG 2.72023-06-20
Improper deletion of resource in the user management feature in Devolutions Server 2023.1.8 and earlier allows an administrator to view users vaults of deleted users via database access.
- CVE-2026-75945LOWCVSS 2.6EG 2.62026-09-14
A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.
- CVE-2026-75944LOWCVSS 2.6EG 2.62026-09-14
A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access control …
- CVE-2026-75943LOWCVSS 2.6EG 2.62026-09-14
A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass wit…
- CVE-2026-63545LOWCVSS 2.4EG 2.42026-08-03
Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users.
- CVE-2019-8732LOWCVSS 2.4EG 2.42020-10-27
The issue was addressed with improved data deletion. This issue is fixed in iOS 13. Deleted calls remained visible on the device.
- CVE-2019-8548LOWCVSS 2.4EG 2.42019-12-18
An issue existed where partially entered passcodes may not clear when the device went to sleep. This issue was addressed by clearing the passcode when a locked device sleeps. This issue is fixed in watchOS 5.2. A partially entered passcode…
- CVE-2026-28196LOWCVSS 2.3EG 2.32026-02-25
In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk
- CVE-2026-67442LOWCVSS 2.0EG 2.02026-08-18
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.3, DELETE /api/roles removes role definitions through server/runtime/users/usrstorage.js but does not remove the deleted role identifier from each user'…
- CVE-2023-20518LOWCVSS 1.9EG 1.92024-08-13
Incomplete cleanup in the ASP may expose the Master Encryption Key (MEK) to a privileged attacker with access to the BIOS menu or UEFI shell and a memory exfiltration vulnerability, potentially resulting in loss of confidentiality.
- CVE-2022-46298LOWCVSS 1.9EG 1.92023-11-14
Incomplete cleanup for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access.
- CVE-2022-40974LOWCVSS 1.8EG 1.82023-05-10
Incomplete cleanup in the Intel(R) IPP Cryptography software before version 2021.6 may allow a privileged user to potentially enable information disclosure via local access.
Map vulnerabilities like CWE-459 to your infrastructure
EchelonGraph correlates every CVE — across CWE-459 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →