Vulnerabilities > Incomplete Cleanup

DATE CVE VULNERABILITY TITLE RISK
2023-06-29 CVE-2023-36468 Incomplete Cleanup vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
low complexity
xwiki CWE-459
8.8
2023-06-20 CVE-2023-2400 Incomplete Cleanup vulnerability in Devolutions Server
Improper deletion of resource in the user management feature in Devolutions Server 2023.1.8 and earlier allows an administrator to view users vaults of deleted users via database access.
network
low complexity
devolutions CWE-459
2.7
2023-05-10 CVE-2022-40974 Incomplete Cleanup vulnerability in Intel Integrated Performance Primitives Cryptography
Incomplete cleanup in the Intel(R) IPP Cryptography software before version 2021.6 may allow a privileged user to potentially enable information disclosure via local access.
local
low complexity
intel CWE-459
5.5
2023-04-19 CVE-2023-20862 Incomplete Cleanup vulnerability in multiple products
In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions.
network
low complexity
vmware netapp CWE-459
6.3
2023-03-29 CVE-2023-0836 Incomplete Cleanup vulnerability in Haproxy
An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1.
network
low complexity
haproxy CWE-459
7.5
2023-03-26 CVE-2023-28859 Incomplete Cleanup vulnerability in Redis Redis-Py
redis-py before 4.4.4 and 4.5.x before 4.5.4 leaves a connection open after canceling an async Redis command at an inopportune time, and can send response data to the client of an unrelated request.
network
low complexity
redis CWE-459
6.5
2023-02-13 CVE-2022-45455 Incomplete Cleanup vulnerability in Acronis Agent, Cyber Protect and Cyber Protect Home Office
Local privilege escalation due to incomplete uninstallation cleanup.
local
low complexity
acronis CWE-459
7.8
2023-01-13 CVE-2023-22407 Incomplete Cleanup vulnerability in Juniper Junos
An Incomplete Cleanup vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS).
low complexity
juniper CWE-459
6.5
2022-12-22 CVE-2022-45347 Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session completely after client authentication failed, which allowed an attacker to execute normal commands by constructing a special MySQL client.
network
low complexity
CWE-459
critical
9.8
2022-11-14 CVE-2022-28764 Incomplete Cleanup vulnerability in Zoom Meetings, Rooms and VDI Windows Meeting Clients
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability.
local
low complexity
zoom CWE-459
3.3