İçeriğe atla
Noroxi

CWE-283 · 31 kayıt

Unverified Ownership

Bu sınıftaki CVE’ler

31 kayıt

  • CVE-2024-27903
    42Planlayın

    OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary

    KritikCVSS 9,8İstismar yokEPSS %9

    openvpn · openvpn8 Tem 2024

  • CVE-2026-26016
    36İzleyin

    Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization

    KritikCVSS 9,2İstismar yokEPSS %0

    pterodactyl · panel19 Şub 2026

  • CVE-2026-29788
    33İzleyin

    TSPortal: Anyone can forge self-deletion requests of any user

    YüksekCVSS 8,4İstismar yokEPSS %0

    wikitide · tsportal6 Mar 2026

  • CVE-2021-24501
    32İzleyin

    Workreap theme < 2.2.2 - Missing Authorization Checks in Ajax Actions

    YüksekCVSS 8,1İstismar yokEPSS %1

    amentotech · workreap9 Ağu 2021

  • CVE-2021-24500
    32İzleyin

    Workreap theme < 2.2.2 - Multiple CSRF + IDOR Vulnerabilities

    YüksekCVSS 8,1İstismar yokEPSS %1

    amentotech · workreap9 Ağu 2021

  • CVE-2025-43882
    31İzleyin

    Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability.

    YüksekCVSS 7,8İstismar yokEPSS %0

    dell · thinos27 Ağu 2025

  • CVE-2025-47940
    28İzleyin

    TYPO3 CMS Vulnerable to Privilege Escalation to System Maintainer

    YüksekCVSS 7,2İstismar yokEPSS %0

    typo3 · typo320 May 2025

  • CVE-2026-54467
    28İzleyin

    On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure,

    YüksekCVSS 7,0İstismar yokEPSS %0

    trustedfirmware · trusted firmware-m26 Ağu 2026

  • CVE-2026-93853
    28İzleyin

    Barman snapshot backup deletion trusts unverified backup catalog metadata

    YüksekCVSS 7,2İstismar yok

    enterprisedb · barmanBugün

  • CVE-2025-1007
    27İzleyin

    Improper Authorization in /user/namespace/{namespace}/details

    OrtaCVSS 6,9İstismar yokEPSS %1

    eclipse · open vsx19 Şub 2025

  • CVE-2026-44707
    27İzleyin

    Chatwoot: Pre-Account Takeover via OAuth on Unconfirmed Accounts

    OrtaCVSS 6,8İstismar yokEPSS %0

    chatwoot · chatwoot26 May 2026

  • CVE-2025-24890
    27İzleyin

    gix-sec safe.directory protections absent for elevated administrators

    OrtaCVSS 6,8İstismar yokEPSS %0

    gitoxidelabs · gitoxide14 Eyl 2026

  • CVE-2022-29220
    26İzleyin

    No verification of commits origin in github-action-merge-dependabot

    OrtaCVSS 6,5İstismar yokEPSS %0

    fastify · github action merge dependabot31 May 2022

  • CVE-2026-44562
    26İzleyin

    Open WebUI: Model Import Overwrites Any Model Without Ownership Check

    OrtaCVSS 6,5İstismar yokEPSS %0

    openwebui · open webui15 May 2026

  • CVE-2026-9745
    26İzleyin

    Vulnerabilities exists in IBM Netezza Software

    OrtaCVSS 6,5İstismar yokEPSS %0

    ibm · netezza performance server3 Eyl 2026

  • CVE-2020-8554
    23İzleyin

    Kubernetes man in the middle using LoadBalancer or ExternalIPs

    OrtaCVSS 5,0Kavram kanıtıEPSS %9

    kubernetes · kubernetes21 Oca 2021

  • CVE-2026-4269
    23İzleyin

    Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit

    OrtaCVSS 5,8İstismar yokEPSS %0

    amazon · bedrock agentcore starter toolkit16 Mar 2026

  • CVE-2025-9822
    22İzleyin

    Secret data extraction via elfinder

    OrtaCVSS 5,5İstismar yokEPSS %0

    mautic · mautic3 Eyl 2025

  • CVE-2024-1853
    22İzleyin

    Zemana AntiLogger v2.74.204.664 - Arbitrary Process Termination

    OrtaCVSS 5,5İstismar yokEPSS %0

    zemena · antilogger14 Mar 2024

  • CVE-2025-12815
    21İzleyin

    An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.

    OrtaCVSS 5,3İstismar yokEPSS %0

    aws · research and engineering studio (res)6 Kas 2025

  • CVE-2026-85781
    20İzleyin

    Unverified access point ownership in Amazon EFS CSI Driver

    OrtaCVSS 5,1İstismar yokEPSS %0

    aws · aws-efs-csi-driver4 Eyl 2026

  • CVE-2026-87912
    20İzleyin

    Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops

    OrtaCVSS 5,1İstismar yokEPSS %0

    aws · aws security agent plugin10 Eyl 2026

  • CVE-2026-87913
    20İzleyin

    Missing S3 bucket ownership verification in the AWS Security Agent MCP server

    OrtaCVSS 5,1İstismar yokEPSS %0

    aws · aws security agent mcp server10 Eyl 2026

  • CVE-2026-40337
    20İzleyin

    Sentry kernel has incomplete ownership check for IRQ line manipulation

    OrtaCVSS 5,1İstismar yokEPSS %0

    camelot-os · sentry-kernel17 Nis 2026

  • CVE-2026-84386
    20İzleyin

    A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attac

    OrtaCVSS 5,1İstismar yokEPSS %0

    fortinet · forticlientwindows8 Eyl 2026

Tüm zafiyet sınıfları