Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerabil
Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious in
Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which the
Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use afte
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allo
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process t
Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To m
@fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, r
multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is abort
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave st
Incomplete cleanup in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engin
Rocq Prover does not restore the universe graph's copy of the universe checking flag when a module that locally disabled
In the Linux kernel, the following vulnerability has been resolved: drm/xe/sync: Cleanup partially initialized sync on
Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memo
Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using d
Incomplete cleanup in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised
A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager._setup_
Tanium addressed an uncontrolled resource consumption vulnerability in Connect.
Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remo
The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TR
better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endp
Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a us
The mknod utility in uutils coreutils fails to handle security labels atomically by creating device nodes before setting
nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear envi
Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromise
File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes ano
filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cl
Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They
In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.3, DELETE /api/roles removes role
Improper cleanup of shared register resources in GPU firmware could allow an admin-privileged attacker from a Guest Virt
Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disc
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remote unauthenticated P2P peer can stall a Zebra node
A parser state isolation vulnerability in misp-stix could cause data from a previously processed STIX document to be ret
Frequently Asked Questions
What is CWE-459?
CWE-459 (CWE-459) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-459?
There are 39 CVE records associated with CWE-459 in our database. Of these, 2 are critical severity, 8 are high severity, and 12 are medium severity.
How can I protect against CWE-459 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-459 using AI-powered security agents.
Detect CWE-459 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-459 vulnerabilities across your infrastructure.
Get Started