CWE-459
Incomplete Cleanup
Description
The product does not properly "clean up" and remove temporary or supporting resources after they have been used.
Hierarchy (View 1000)
CVEs mapped to this weakness (222)
page 10 of 12| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-6300 | Low | 0.24 | 3.7 | 0.00 | Jun 25, 2024 | Incomplete cleanup when performing redactions in Conduit, allowing an attacker to check whether certain strings were present in the PDU before redaction | ||
| CVE-2021-34421 | Low | 0.24 | 3.7 | 0.01 | Nov 11, 2021 | The Keybase Client for Android before version 5.8.0 and the Keybase Client for iOS before version 5.8.0 fails to properly remove exploded messages initiated by a user if the receiving user places the chat session in the background while the sending user explodes the messages.… | ||
| CVE-2026-78600 | Low | 0.23 | 3.5 | 0.00 | Sep 2, 2026 | Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a low-privileged tenant to… | ||
| CVE-2022-2307 | Low | 0.23 | 3.5 | 0.01 | Aug 5, 2022 | A lack of cascading deletes in GitLab CE/EE affecting all versions starting from 13.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious Group Owner to retain a usable Group Access Token even after the… | ||
| CVE-2024-21977 | Low | 0.21 | 3.2 | 0.00 | Sep 5, 2025 | Incomplete cleanup after loading a CPU microcode patch may allow a privileged attacker to degrade the entropy of the RDRAND instruction, potentially resulting in loss of integrity for SEV-SNP guests. | ||
| CVE-2023-29184 | Low | 0.21 | 3.2 | 0.00 | Jun 10, 2025 | An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 allows a VDOM privileged attacker to add SSH key files on the system silently via crafted CLI requests. | ||
| CVE-2024-1048 | Low | 0.21 | 3.3 | 0.00 | Feb 6, 2024 | A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the… | ||
| CVE-2022-43477 | Low | 0.21 | 3.3 | 0.00 | Nov 14, 2023 | Incomplete cleanup for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access. | ||
| CVE-2022-28764 | Low | 0.21 | 3.3 | 0.00 | Nov 14, 2022 | The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure… | ||
| CVE-2019-8730 | Low | 0.21 | 3.3 | 0.00 | Dec 18, 2019 | The contents of locked notes sometimes appeared in search results. This issue was addressed with improved data cleanup. This issue is fixed in macOS Catalina 10.15. A local user may be able to view a user’s locked notes. | ||
| CVE-2026-91730 | Low | 0.20 | 3.1 | 0.00 | Sep 15, 2026 | Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2026-78903 | Low | 0.20 | 3.1 | 0.00 | Aug 25, 2026 | Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2026-67334 | Low | 0.18 | 3.8 | 0.00 | Aug 1, 2026 | better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeSessionInDatabase is false. Attackers can reuse deleted user session tokens to maintain authentication for… | ||
| CVE-2023-2400 | Low | 0.18 | 2.7 | 0.00 | Jun 20, 2023 | Improper deletion of resource in the user management feature in Devolutions Server 2023.1.8 and earlier allows an administrator to view users vaults of deleted users via database access. | ||
| CVE-2026-75945 | Low | 0.17 | 2.6 | 0.00 | Sep 14, 2026 | A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued. | ||
| CVE-2026-75944 | Low | 0.17 | 2.6 | 0.00 | Sep 14, 2026 | A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access control enforcement. User interaction (an… | ||
| CVE-2026-75943 | Low | 0.17 | 2.6 | 0.00 | Sep 14, 2026 | A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcement. | ||
| CVE-2026-9693 | Low | 0.16 | 3.5 | 0.00 | Aug 17, 2026 | Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view private channel thread root post… | ||
| CVE-2021-46766 | Low | 0.16 | 2.5 | 0.00 | Nov 14, 2023 | Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality. | ||
| CVE-2019-8732 | Low | 0.16 | 2.4 | 0.00 | Oct 27, 2020 | The issue was addressed with improved data deletion. This issue is fixed in iOS 13. Deleted calls remained visible on the device. |
- risk 0.24cvss 3.7epss 0.00
Incomplete cleanup when performing redactions in Conduit, allowing an attacker to check whether certain strings were present in the PDU before redaction
- risk 0.24cvss 3.7epss 0.01
The Keybase Client for Android before version 5.8.0 and the Keybase Client for iOS before version 5.8.0 fails to properly remove exploded messages initiated by a user if the receiving user places the chat session in the background while the sending user explodes the messages.…
- risk 0.23cvss 3.5epss 0.00
Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a low-privileged tenant to…
- risk 0.23cvss 3.5epss 0.01
A lack of cascading deletes in GitLab CE/EE affecting all versions starting from 13.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious Group Owner to retain a usable Group Access Token even after the…
- risk 0.21cvss 3.2epss 0.00
Incomplete cleanup after loading a CPU microcode patch may allow a privileged attacker to degrade the entropy of the RDRAND instruction, potentially resulting in loss of integrity for SEV-SNP guests.
- risk 0.21cvss 3.2epss 0.00
An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 allows a VDOM privileged attacker to add SSH key files on the system silently via crafted CLI requests.
- risk 0.21cvss 3.3epss 0.00
A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the…
- risk 0.21cvss 3.3epss 0.00
Incomplete cleanup for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access.
- risk 0.21cvss 3.3epss 0.00
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure…
- risk 0.21cvss 3.3epss 0.00
The contents of locked notes sometimes appeared in search results. This issue was addressed with improved data cleanup. This issue is fixed in macOS Catalina 10.15. A local user may be able to view a user’s locked notes.
- risk 0.20cvss 3.1epss 0.00
Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.20cvss 3.1epss 0.00
Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.18cvss 3.8epss 0.00
better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeSessionInDatabase is false. Attackers can reuse deleted user session tokens to maintain authentication for…
- risk 0.18cvss 2.7epss 0.00
Improper deletion of resource in the user management feature in Devolutions Server 2023.1.8 and earlier allows an administrator to view users vaults of deleted users via database access.
- risk 0.17cvss 2.6epss 0.00
A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.
- risk 0.17cvss 2.6epss 0.00
A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access control enforcement. User interaction (an…
- risk 0.17cvss 2.6epss 0.00
A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcement.
- risk 0.16cvss 3.5epss 0.00
Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view private channel thread root post…
- risk 0.16cvss 2.5epss 0.00
Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality.
- risk 0.16cvss 2.4epss 0.00
The issue was addressed with improved data deletion. This issue is fixed in iOS 13. Deleted calls remained visible on the device.