CWE-402: Resource Leak
The product makes resources available to untrusted parties when those resources are only intended to be accessed by the product.
22 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-29925 — XWiki allows unregistered users to access private pages information through REST endpoint
- CVE-2025-48383 — Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking
- CVE-2024-29900 — @electron/packager's build process memory potentially leaked into final executable
- CVE-2025-67745 — Myhoard logs backup encryption key in plain text
- CVE-2024-47146 — Ruijie Reyee OS Resource Leak
- CVE-2025-0502 — Transmission of Private Resources into a New Sphere in Crafter Engine
- CVE-2025-49618 — In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, reg
- CVE-2025-52925 — In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka S
- CVE-2025-55014 — The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X1
- CVE-2025-66422 — Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is
- CVE-2025-32360 — In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and work on shared articl
Recently published
- CVE-2025-67745 — Myhoard logs backup encryption key in plain text
- CVE-2025-66422 — Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is
- CVE-2025-55014 — The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X1
- CVE-2025-49618 — In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, reg
- CVE-2025-52925 — In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka S
- CVE-2025-48383 — Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking
- CVE-2025-32360 — In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and work on shared articl
- CVE-2025-29925 — XWiki allows unregistered users to access private pages information through REST endpoint
- CVE-2025-0502 — Transmission of Private Resources into a New Sphere in Crafter Engine
- CVE-2024-47146 — Ruijie Reyee OS Resource Leak
- CVE-2024-29900 — @electron/packager's build process memory potentially leaked into final executable