The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.
Volume of CVEs assigned to CWE-672 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
83 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-23638MEDIUM Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error re | Jan 24, 2024 | 6.5 | 51 | NO | NO |
CVE-2026-33278CRITICAL NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a resu | May 20, 2026 | 9.8 | 43 | NO | NO |
CVE-2020-11027HIGH In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user | Apr 30, 2020 | 8.1 | 40 | NO | YES |
CVE-2026-23111HIGH In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()
nft_map_catchall_activate() ha | Feb 13, 2026 | 7.8 | 37 | NO | NO |
CVE-2026-43585CRITICAL OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain valid after SecretRef rotation. Gateway HTTP and WebSocket handl | May 6, 2026 | 9.8 | 36 | NO | NO |
CVE-2009-3547HIGH Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privi | Nov 4, 2009 | 7.0 | 36 | NO | YES |
CVE-2013-10075CRITICAL Apache::Session versions through 1.94 for Perl re-creates deleted sessions.
The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a sessi | May 8, 2026 | 9.1 | 35 | NO | NO |
CVE-2019-17638CRITICAL In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP 431 error. When this happens, t | Jul 9, 2020 | 9.4 | 35 | NO | NO |
CVE-2019-15791HIGH In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() installs an fd referencing a file from the l | Apr 24, 2020 | 7.8 | 35 | NO | YES |
CVE-2019-15794MEDIUM Overlayfs in the Linux kernel and shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, both replace vma->vm_file in their mmap handle | Apr 24, 2020 | 6.7 | 32 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.