Перейти к содержимому
Noroxi

CWE-282 · 30 записей

Improper Ownership Management

CVE этого класса

30 записей

  • CVE-2023-0386
    63На этой неделе

    A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 8 %

    linux · linux kernel22 мар. 2023 г.

  • CVE-2024-3383
    36Наблюдать

    PAN-OS: Improper Group Membership Change Vulnerability in Cloud Identity Engine (CIE)

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    paloaltonetworks · pan-os10 апр. 2024 г.

  • CVE-2026-50130
    35Наблюдать

    Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    pi-hole · pi-hole14 июл. 2026 г.

  • CVE-2024-37999
    34Наблюдать

    A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions).

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    siemens · medicalis workflow orchestrator8 июл. 2024 г.

  • CVE-2025-27254
    32Наблюдать

    CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass.

    ВысокаяCVSS 8,0Эксплойта нетEPSS 0 %

    ge vernova · enervista ur setup10 мар. 2025 г.

  • CVE-2022-29187
    31Наблюдать

    Bypass of safe.directory protections in Git

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    git-scm · git12 июл. 2022 г.

  • CVE-2024-39755
    31Наблюдать

    A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    veertu · anka build cloud3 окт. 2024 г.

  • CVE-2017-12189
    31Наблюдать

    It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handlin

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    redhat · jboss enterprise application platform10 янв. 2018 г.

  • CVE-2026-23514
    26Наблюдать

    Kiteworks Core before 9.2.2 is vulnerable to Improper Ownership Management

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    accellion · kiteworks25 мар. 2026 г.

  • CVE-2023-7226
    26Наблюдать

    meetyoucrop big-whale Admin Module all.api improper ownership management

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    meiyou · big whale11 янв. 2024 г.

  • CVE-2022-0026
    26Наблюдать

    Cortex XDR Agent: Unintended Program Execution Leads to Local Privilege Escalation (PE) Vulnerability

    СредняяCVSS 6,7Эксплойта нетEPSS 0 %

    paloaltonetworks · cortex xdr agent11 мая 2022 г.

  • CVE-2024-45104
    26Наблюдать

    A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device thr

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    lenovo · xclarity administrator13 сент. 2024 г.

  • CVE-2024-47816
    25Наблюдать

    Users can impersonate import requesters if their actor IDs coincide in ImportDump

    СредняяCVSS 6,4Эксплойта нетEPSS 0 %

    miraheze · importdump9 окт. 2024 г.

  • CVE-2026-40214
    25Наблюдать

    In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer.

    СредняяCVSS 6,3Эксплойта нетEPSS 0 %

    openstack · cyborg7 мая 2026 г.

  • CVE-2025-57732
    25Наблюдать

    In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership

    СредняяCVSS 6,3Эксплойта нетEPSS 0 %

    jetbrains · teamcity20 авг. 2025 г.

  • CVE-2026-3867
    24Наблюдать

    An improper ownership management vulnerability has been identified in Moxa’s Secure Router.

    СредняяCVSS 6,0Эксплойта нетEPSS 0 %

    moxa · edr-8010 series27 апр. 2026 г.

  • CVE-2023-0989
    22Наблюдать

    Improper Ownership Management in GitLab

    СредняяCVSS 5,7Эксплойта нетEPSS 1 %

    gitlab · gitlab29 сент. 2023 г.

  • CVE-2024-8949
    21Наблюдать

    SourceCodester Online Eyewear Shop Cart Content Master.php improper ownership management

    СредняяCVSS 5,3Proof of conceptEPSS 1 %

    oretnom23 · online eyewear shop17 сент. 2024 г.

  • CVE-2020-10632
    21Наблюдать

    ICSA-20-140-02 Emerson OpenEnterprise

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    emerson · openenterprise scada server24 февр. 2022 г.

  • CVE-2025-32946
    21Наблюдать

    PeerTube Arbitrary Playlist Creation via ActivityPub Protocol

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    framasoft · peertube15 апр. 2025 г.

  • CVE-2024-43176
    21Наблюдать

    IBM OpenPages information disclosure

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    ibm · openpages with watson9 янв. 2025 г.

  • CVE-2026-86769
    21Наблюдать

    Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    snipeitapp · snipe-it9 сент. 2026 г.

  • CVE-2024-13246
    21Наблюдать

    Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-010

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    node access rebuild progressive project · node access rebuild progressive9 янв. 2025 г.

  • CVE-2024-13249
    21Наблюдать

    Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-013

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    node access rebuild progressive project · node access rebuild progressive9 янв. 2025 г.

  • CVE-2024-45103
    17Наблюдать

    A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privile

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    lenovo · xclarity administrator13 сент. 2024 г.

Все классы уязвимостей