Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-459

MITRE ↗

CWE-459

2
CRITICAL
8
HIGH
12
MEDIUM
10
LOW
36 CVEs
9.8
CVE-2026-28268

Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerabil

9.6
CVE-2026-34263

Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious in

8.0
CVE-2025-66467

Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which the

7.8
CVE-2026-7639

Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use afte

7.5
CVE-2026-3304

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allo

7.5
CVE-2026-33232

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent

7.5
CVE-2026-11576

The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process t

7.5
CVE-2026-42492

Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To m

7.5
CVE-2026-19474

@fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, r

7.5
CVE-2026-77037

multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is abort

6.5
CVE-2026-52733

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave st

6.5
CVE-2026-78947

Incomplete cleanup in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engin

6.3
CVE-2026-72714

Rocq Prover does not restore the universe graph's copy of the universe checking flag when a module that locally disabled

5.5
CVE-2026-43395

In the Linux kernel, the following vulnerability has been resolved: drm/xe/sync: Cleanup partially initialized sync on

5.5
CVE-2026-68809

Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

5.3
CVE-2026-21438

webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memo

5.3
CVE-2026-5038

Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using d

5.3
CVE-2026-79265

Incomplete cleanup in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised

4.8
CVE-2026-19019

A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager._setup_

4.3
CVE-2025-15331

Tanium addressed an uncontrolled resource consumption vulnerability in Connect.

4.3
CVE-2026-53867

Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remo

4.2
CVE-2026-19730

The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TR

3.8
CVE-2026-67334

better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endp

3.5
CVE-2026-9693

Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a us

3.4
CVE-2026-35361

The mknod utility in uutils coreutils fails to handle security labels atomically by creating device nodes before setting

3.3
CVE-2026-6830

nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear envi

3.1
CVE-2026-78903

Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromise

3.1
CVE-2026-82236

File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes ano

3.1
CVE-2026-82237

filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cl

2.4
CVE-2026-63545

Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They

2.3
CVE-2026-28196

In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk

2.0
CVE-2026-67442

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.3, DELETE /api/roles removes role

CVE-2026-0427

Improper cleanup of shared register resources in GPU firmware could allow an admin-privileged attacker from a Guest Virt

CVE-2026-20712

Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disc

CVE-2026-52736

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remote unauthenticated P2P peer can stall a Zebra node

CVE-2026-77761

A parser state isolation vulnerability in misp-stix could cause data from a previously processed STIX document to be ret

Frequently Asked Questions

What is CWE-459?

CWE-459 (CWE-459) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-459?

There are 39 CVE records associated with CWE-459 in our database. Of these, 2 are critical severity, 8 are high severity, and 12 are medium severity.

How can I protect against CWE-459 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-459 using AI-powered security agents.

Detect CWE-459 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-459 vulnerabilities across your infrastructure.

Get Started