The product does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release.
Volume of CVEs assigned to CWE-664 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
43 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27518CRITICAL Unauthenticated remote arbitrary code execution | Dec 13, 2022 | 9.8 | 72 | YES | NO |
CVE-2026-43503HIGH In the Linux kernel, the following vulnerability has been resolved:
net: skbuff: propagate shared-frag marker through frag-transfer helpers
Two frag-transfer helpers (__pskb_copy | May 23, 2026 | 8.8 | 46 | NO | NO |
CVE-2026-20158HIGH As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This revi | Jul 15, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-8517HIGH Object lifecycle issue in WebShare in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbit | May 14, 2026 | 8.8 | 32 | NO | NO |
CVE-2019-5816HIGH Process lifetime issue in Chrome in Google Chrome on Android prior to 74.0.3729.108 allowed a remote attacker to potentially persist an exploited process via a crafted HTML page. | Jun 27, 2019 | 8.8 | 27 | NO | NO |
CVE-2022-2191HIGH In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths | Jul 7, 2022 | 7.5 | 26 | NO | NO |
CVE-2022-20856HIGH A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) Mobility messages in Cisco IOS XE Wireless Controller Software for the Catalyst 900 | Sep 30, 2022 | 7.5 | 25 | NO | NO |
CVE-2026-8582MEDIUM Object lifecycle issue in Dawn in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML | May 14, 2026 | 5.3 | 24 | NO | NO |
CVE-2024-7889HIGH Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows | Sep 11, 2024 | 7.3 | 24 | NO | NO |
CVE-2022-32846HIGH A logic issue was addressed with improved state management. This issue is fixed in Apple Music 3.9.10 for Android. An app may be able to access user-sensitive data. | Feb 27, 2023 | 7.5 | 24 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.