VYPR

CWE-672

Operation on a Resource after Expiration or Release

ClassDraft

Description

The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.

Hierarchy (View 1000)

CVEs mapped to this weakness (98)

page 3 of 5
  • CVE-2025-21117MedFeb 5, 2025
    risk 0.43cvss 6.6epss 0.00

    Dell Avamar, version 19.4 or later, contains an access token reuse vulnerability in the AUI. A low privileged local attacker could potentially exploit this vulnerability, leading to fully impersonating the user.

  • CVE-2022-2447MedSep 1, 2022
    risk 0.43cvss 6.6epss 0.01

    A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than…

  • CVE-2026-85044MedSep 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-19538HigAug 26, 2026
    risk 0.42cvss 7.5epss 0.00

    The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.

  • CVE-2025-10060MedSep 5, 2025
    risk 0.42cvss 6.5epss 0.00

    MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, potentially causing an invariant failure and server crash during commit. This issue may be triggered by improper WriteUnitOfWork state management. This issue affects…

  • CVE-2024-27308HigMar 6, 2024
    risk 0.42cvss 7.5epss 0.01

    Mio is a Metal I/O library for Rust. When using named pipes on Windows, mio will under some circumstances return invalid tokens that correspond to named pipes that have already been deregistered from the mio registry. The impact of this vulnerability depends on how mio is used.…

  • CVE-2020-36212HigJan 26, 2021
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in the abi_stable crate before 0.9.1 for Rust. DrainFilter lacks soundness because of a double drop.

  • CVE-2026-2379MedJun 5, 2026
    risk 0.38cvss 5.9epss 0.00

    On affected platforms with hardware IPSec support running Arista EOS with certain IPsec features enabled, EOS may exhibit unexpected behavior in specific cases. Physical interface flaps and certain agent restarts can cause IPsec tunnel re-establishment with existing Security…

  • CVE-2023-1902MedJul 10, 2023
    risk 0.38cvss 5.9epss 0.01

    The bluetooth HCI host layer logic not clearing a global reference to a state pointer after handling connection events may allow a malicious HCI Controller to cause the use of a dangling reference in the host layer, leading to a crash (DoS) or potential RCE on the Host layer.

  • CVE-2023-1901MedJul 10, 2023
    risk 0.38cvss 5.9epss 0.01

    The bluetooth HCI host layer logic not clearing a global reference to a semaphore after synchronously sending HCI commands may allow a malicious HCI Controller to cause the use of a dangling reference in the host layer, leading to a crash (DoS) or potential RCE on the Host…

  • CVE-2020-11027MedApr 30, 2020
    risk 0.37cvss 6.1epss 0.14

    In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful execution. This has been patched in version 5.4.1, along with…

  • CVE-2026-44725MedAug 20, 2026
    risk 0.36cvss 6.6epss 0.00

    EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to versions 5.8.11, 5.9.3, 5.10.4, 6.0.3, 6.1.2, and 6.2.1, the plugin-install REST API and dashboard upload accepted stale grants created with emqx ctl plugins allow because there was…

  • CVE-2024-56674MedDec 27, 2024
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: virtio_net: correct netdev_tx_reset_queue() invocation point When virtnet_close is followed by virtnet_open, some TX completions can possibly remain unconsumed, until they are finally processed during the…

  • CVE-2024-49953MedOct 21, 2024
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix crash caused by calling __xfrm_state_delete() twice The km.state is not checked in driver's delayed work. When xfrm_state_check_expire() is called, the state can be reset to XFRM_STATE_EXPIRED,…

  • CVE-2021-47294MedMay 21, 2024
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: netrom: Decrease sock refcount when sock timers expire Commit 63346650c1a9 ("netrom: switch to sock timer API") switched to use sock timer API. It replaces mod_timer() by sk_reset_timer(), and del_timer() by…

  • CVE-2024-4693MedMay 14, 2024
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the QEMU Virtio PCI Bindings (hw/virtio/virtio-pci.c). An improper release and use of the irqfd for vector 0 during the boot process leads to a guest triggerable crash via vhost_net_stop(). This flaw allows a malicious guest to crash the QEMU process on the…

  • CVE-2026-53637MedSep 8, 2026
    risk 0.35cvss 6.5epss 0.00

    Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement vulnerability in the cart `FormComponent`. When an order is completed while its cart page remains open,…

  • CVE-2026-52733MedAug 18, 2026
    risk 0.35cvss 6.5epss 0.00

    ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave stale Sapling and Orchard note-commitment subtree roots in Zebra state. In zebra-state/src/service/non_finalized_state/chain.rs, Chain::pop_tip removed a…

  • CVE-2023-42446MedSep 18, 2023
    risk 0.35cvss 6.5epss 0.01

    Pow is a authentication and user management solution for Phoenix and Plug-based apps. Starting in version 1.0.14 and prior to version 1.0.34, use of `Pow.Store.Backend.MnesiaCache` is susceptible to session hijacking as expired keys are not being invalidated correctly on…

  • CVE-2019-20022MedDec 27, 2019
    risk 0.35cvss 6.5epss 0.01

    An invalid memory address dereference was discovered in load_pnm in frompnm.c in libsixel before 1.8.3.