The product does not properly "clean up" and remove temporary or supporting resources after they have been used.
Volume of CVEs assigned to CWE-459 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
191 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-39327MEDIUM The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which | Sep 17, 2021 | 5.3 | 82 | NO | YES |
CVE-2017-17090HIGH An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the cha | Dec 2, 2017 | 7.5 | 79 | NO | YES |
CVE-2025-31650HIGH Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request whic | Apr 28, 2025 | 7.5 | 75 | NO | YES |
CVE-2018-18924HIGH The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" because rejected files remain on the serve | Nov 4, 2018 | 8.8 | 42 | NO | YES |
CVE-2026-34263CRITICAL Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in arbitrary server-side code execu | May 12, 2026 | 9.6 | 41 | NO | NO |
CVE-2026-28268CRITICAL Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api th | Feb 27, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-7639HIGH Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use after free, which helps in facilitating unprivileged memory acce | Jul 10, 2026 | 7.8 | 32 | NO | NO |
CVE-2025-66467HIGH Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user creates a new bucket wit | May 8, 2026 | 8.1 | 32 | NO | NO |
CVE-2026-11576HIGH The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path | Jun 19, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-5038HIGH Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orp | Jun 15, 2026 | 7.5 | 30 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.