Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-672

MITRE ↗

CWE-672

2
CRITICAL
7
HIGH
10
MEDIUM
4
LOW
25 CVEs
9.8
CVE-2026-33278

NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables de

9.1
CVE-2013-10075

Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::

8.1
CVE-2026-43585

OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain vali

7.8
CVE-2026-23111

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in

7.8
CVE-2026-30978

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is

7.7
CVE-2026-50575

BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted devi

7.5
CVE-2026-68481

In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospec

7.1
CVE-2025-69415

In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly a

7.1
CVE-2026-56314

Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, allowing d

6.6
CVE-2026-44725

EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to versions 5.8.11, 5.9.3,

6.5
CVE-2026-52733

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave st

6.1
CVE-2026-58291

Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker t

6.0
CVE-2026-45005

OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to re

5.9
CVE-2026-31875

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a

5.9
CVE-2026-2379

On affected platforms with hardware IPSec support running Arista EOS with certain IPsec features enabled, EOS may exhibi

5.3
CVE-2026-32244

Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1

5.3
CVE-2026-33463

Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can lead to unauthorized information disclos

4.3
CVE-2026-1629

Mattermost versions 10.11.x <= 10.11.10 Fail to invalidate cached permalink preview data when a user loses channel acces

4.3
CVE-2026-79010

Operation on a resource after expiration or release in Network in Google Chrome prior to 152.0.7977.65 allowed a remote

3.7
CVE-2026-42791

Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows forged OCSP responses

3.7
CVE-2026-42955

In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost do

3.5
CVE-2026-47087

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A

3.1
CVE-2026-4053

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fiel

CVE-2026-1237

Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious us

CVE-2026-19538

The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed c

Frequently Asked Questions

What is CWE-672?

CWE-672 (CWE-672) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-672?

There are 25 CVE records associated with CWE-672 in our database. Of these, 2 are critical severity, 7 are high severity, and 10 are medium severity.

How can I protect against CWE-672 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-672 using AI-powered security agents.

Detect CWE-672 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-672 vulnerabilities across your infrastructure.

Get Started