CWE-459: CWE-459

36
Total CVEs
5
Critical
15
High
7.0
Avg CVSS

Yearly Trend

2026
1
2025
17
2024
9
2023
2
2022
4

Top Affected Vendors

1 Linux 11
2 Eclipse 2
3 Apache 2
4 Intel 2
5 Netapp 2
6 Debian 2
7 Perfree 1
8 St 1
9 Ibos 1
10 Johnsoncontrols 1

All CWE-459 CVEs (36)

CVE-2023-36468
9.9

XWiki Platform retains vulnerable old document revisions after upgrades, allowing attackers to exploit previously fixed vulnerabilities by accessing s...

Jun 29, 2023
CVE-2021-45330
9.8

This vulnerability in Gitea allows a malicious user to maintain access to a session even after logout due to improper cookie deletion on the client si...

Feb 9, 2022
CVE-2021-32928
9.8

This vulnerability in Sentinel LDK Run-Time Environment installer versions 7.6 and prior leaves TCP Port 1947 open after uninstallation, allowing unau...

Jun 16, 2021
CVE-2025-21609
9.1

SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability in the POST /api/history/getDocHistoryContent endpoint. Attackers can craft pa...

Jan 3, 2025
CVE-2024-28265
9.1

IBOS v4.5.5 contains an arbitrary file deletion vulnerability in the LoginController.php component. This allows attackers to delete arbitrary files on...

Nov 1, 2024
CVE-2020-24489
8.8

This vulnerability in Intel VT-d (Virtualization Technology for Directed I/O) allows an authenticated attacker with local access to potentially escala...

Jun 9, 2021
CVE-2025-66675
8.2

This CVE describes a Denial of Service vulnerability in Apache Struts where specially crafted multipart requests can cause file leaks leading to disk ...

Dec 10, 2025
CVE-2025-43711
8.1

This vulnerability in Tunnelblick allows attackers to execute arbitrary code with root privileges when a user drags a malicious Tunnelblick.app file i...

Jul 5, 2025
CVE-2021-36205
8.1

CVE-2021-36205 is an authentication bypass vulnerability in Johnson Controls Metasys products where session tokens are not properly cleared on logout....

Apr 15, 2022
CVE-2025-37908
7.8

A Linux kernel memory management vulnerability where slab object extensions aren't properly cleaned up when memory allocation profiling is disabled. T...

May 20, 2025
CVE-2022-0646
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's MCTP subsystem that occurs when cancel_work_sync is triggered after unregister...

Feb 18, 2022
CVE-2025-60730
7.6

PerfreeBlog v4.0.11 contains an arbitrary file deletion vulnerability in the unInstallTheme function that allows attackers to delete files on the serv...

Oct 24, 2025
CVE-2025-64775
7.5

This vulnerability in Apache Struts allows attackers to cause a denial of service through disk exhaustion by exploiting a file leak in multipart reque...

Dec 1, 2025
CVE-2025-2260
7.5

This vulnerability in Eclipse ThreadX NetX Duo's HTTP server allows attackers to cause denial of service through specially crafted packets. The issue ...

Apr 6, 2025
CVE-2025-0726
7.5

A denial-of-service vulnerability in Eclipse ThreadX NetX Duo's HTTP server allows attackers to exhaust file handles by sending specially crafted pack...

Feb 21, 2025
CVE-2022-1473
7.5

A memory leak vulnerability in OpenSSL's OPENSSL_LH_flush() function causes unbounded memory growth when processing certificates or keys. This affects...

May 3, 2022
CVE-2021-37089
7.5

This vulnerability in Huawei smartphones running HarmonyOS involves incomplete cleanup of kernel resources, which could allow an attacker to cause a k...

Dec 7, 2021
CVE-2024-20303
7.4

An unauthenticated attacker on the same wireless network can send continuous mDNS packets to Cisco IOS XE Wireless LAN Controllers, causing high CPU u...

Mar 27, 2024
CVE-2025-0032
7.2

This vulnerability allows attackers with local administrator privileges to load malicious CPU microcode on affected AMD processors, potentially compro...

Sep 6, 2025
CVE-2021-47110
7.1

A memory corruption vulnerability in the Linux kernel's KVM subsystem where kvmclock is not properly disabled on all CPUs during system shutdown. This...

Mar 15, 2024
CVE-2024-50384
6.5

A denial of service vulnerability in STMicroelectronics X-CUBE-AZRTOS-WL NetX Component HTTP server allows attackers to crash the server by sending sp...

Apr 2, 2025
CVE-2025-0473
6.5

This vulnerability in the PMB platform allows attackers to persist temporary files on the server by intercepting and preventing the cleanup request af...

Jan 16, 2025
CVE-2024-47693
6.5

This CVE describes a resource cleanup vulnerability in the Linux kernel's InfiniBand subsystem. When ib_cache_update() fails during device initializat...

Oct 21, 2024
CVE-2023-28859
6.5

This vulnerability in redis-py allows data leakage across AsyncIO connections when async Redis commands are canceled at specific times. It affects app...

Mar 26, 2023
CVE-2025-38177
5.5

This CVE addresses a non-idempotent function in the Linux kernel's HFSC (Hierarchical Fair Service Curve) queuing discipline that could cause kernel i...

Jul 4, 2025
CVE-2023-52929
5.5

This CVE describes a memory leak vulnerability in the Linux kernel's nvmem (non-volatile memory) subsystem. When device registration fails during nvme...

Mar 27, 2025
CVE-2024-57976
5.5

A race condition vulnerability in the Linux kernel's Btrfs filesystem when handling copy-on-write operations during out-of-space conditions. This can ...

Feb 27, 2025
CVE-2024-53869
5.5

The NVIDIA Unified Memory driver for Linux contains a vulnerability where an attacker could leak uninitialized memory, potentially exposing sensitive ...

Jan 28, 2025
CVE-2022-49012
5.5

This CVE describes a resource leak vulnerability in the Linux kernel's AFS (Andrew File System) implementation. A coding error in afs_put_server preve...

Oct 21, 2024
CVE-2024-49851
5.5

A vulnerability in the Linux kernel's TPM (Trusted Platform Module) subsystem allows transient handles to be leaked when TPM command transmission fail...

Oct 21, 2024
CVE-2021-47365
5.5

This CVE describes a memory leak vulnerability in the Linux kernel's AFS (Andrew File System) implementation. When writeback operations fail, the kern...

May 21, 2024
CVE-2024-35959
5.5

This CVE describes a race condition vulnerability in the Linux kernel's mlx5e network driver where the cleanup flow fails to properly acquire a lock d...

May 20, 2024
CVE-2023-45846
5.5

This vulnerability in Intel Power Gadget for macOS allows authenticated local users to cause denial of service through incomplete cleanup of resources...

May 16, 2024
CVE-2025-29934
5.3

A vulnerability in some AMD CPUs allows a local administrator to run a SEV-SNP guest using stale TLB entries, potentially compromising data integrity....

Nov 21, 2025
CVE-2025-20293
5.3

A vulnerability in Cisco IOS XE Software for Catalyst 9800-CL wireless controllers allows unauthenticated remote attackers to access the PKI server af...

Sep 24, 2025
CVE-2025-15331
4.3

CVE-2025-15331 is an uncontrolled resource consumption vulnerability in Tanium Connect that could allow attackers to cause denial of service by exhaus...

Feb 5, 2026

About CWE-459 (CWE-459)

Our database tracks 36 CVEs classified as CWE-459, with 5 rated critical and 15 rated high severity. The average CVSS score for CWE-459 vulnerabilities is 7.0.

External reference: View CWE-459 on MITRE CWE →

Monitor CWE-459 Vulnerabilities

Get alerted when new CWE-459 CVEs affect your infrastructure.

Start Monitoring Free