Skip to content
Noroxi

CWE-283 · 31 records

Unverified Ownership

CVEs in this class

31 records

  • OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary

    CriticalCVSS 9.8No exploitEPSS 9%

    openvpn · openvpnJul 8, 2024

  • Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization

    CriticalCVSS 9.2No exploitEPSS 0%

    pterodactyl · panelFeb 19, 2026

  • TSPortal: Anyone can forge self-deletion requests of any user

    HighCVSS 8.4No exploitEPSS 0%

    wikitide · tsportalMar 6, 2026

  • Workreap theme < 2.2.2 - Missing Authorization Checks in Ajax Actions

    HighCVSS 8.1No exploitEPSS 1%

    amentotech · workreapAug 9, 2021

  • Workreap theme < 2.2.2 - Multiple CSRF + IDOR Vulnerabilities

    HighCVSS 8.1No exploitEPSS 1%

    amentotech · workreapAug 9, 2021

  • Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability.

    HighCVSS 7.8No exploitEPSS 0%

    dell · thinosAug 27, 2025

  • TYPO3 CMS Vulnerable to Privilege Escalation to System Maintainer

    HighCVSS 7.2No exploitEPSS 0%

    typo3 · typo3May 20, 2025

  • Barman snapshot backup deletion trusts unverified backup catalog metadata

    HighCVSS 7.2No exploitEPSS 0%

    enterprisedb · barmanSep 29, 2026

  • On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure,

    HighCVSS 7.0No exploitEPSS 0%

    trustedfirmware · trusted firmware-mAug 26, 2026

  • CVE-2025-1007
    27Monitor

    Improper Authorization in /user/namespace/{namespace}/details

    MediumCVSS 6.9No exploitEPSS 1%

    eclipse · open vsxFeb 19, 2025

  • Chatwoot: Pre-Account Takeover via OAuth on Unconfirmed Accounts

    MediumCVSS 6.8No exploitEPSS 0%

    chatwoot · chatwootMay 26, 2026

  • gix-sec safe.directory protections absent for elevated administrators

    MediumCVSS 6.8No exploitEPSS 0%

    gitoxidelabs · gitoxideSep 14, 2026

  • No verification of commits origin in github-action-merge-dependabot

    MediumCVSS 6.5No exploitEPSS 0%

    fastify · github action merge dependabotMay 31, 2022

  • Open WebUI: Model Import Overwrites Any Model Without Ownership Check

    MediumCVSS 6.5No exploitEPSS 0%

    openwebui · open webuiMay 15, 2026

  • CVE-2026-9745
    26Monitor

    Vulnerabilities exists in IBM Netezza Software

    MediumCVSS 6.5No exploitEPSS 0%

    ibm · netezza performance serverSep 3, 2026

  • CVE-2020-8554
    23Monitor

    Kubernetes man in the middle using LoadBalancer or ExternalIPs

    MediumCVSS 5.0Proof of conceptEPSS 9%

    kubernetes · kubernetesJan 21, 2021

  • CVE-2026-4269
    23Monitor

    Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit

    MediumCVSS 5.8No exploitEPSS 0%

    amazon · bedrock agentcore starter toolkitMar 16, 2026

  • CVE-2025-9822
    22Monitor

    Secret data extraction via elfinder

    MediumCVSS 5.5No exploitEPSS 0%

    mautic · mauticSep 3, 2025

  • CVE-2024-1853
    22Monitor

    Zemana AntiLogger v2.74.204.664 - Arbitrary Process Termination

    MediumCVSS 5.5No exploitEPSS 0%

    zemena · antiloggerMar 14, 2024

  • An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.

    MediumCVSS 5.3No exploitEPSS 0%

    aws · research and engineering studio (res)Nov 6, 2025

  • Unverified access point ownership in Amazon EFS CSI Driver

    MediumCVSS 5.1No exploitEPSS 0%

    aws · aws-efs-csi-driverSep 4, 2026

  • Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops

    MediumCVSS 5.1No exploitEPSS 0%

    aws · aws security agent pluginSep 10, 2026

  • Missing S3 bucket ownership verification in the AWS Security Agent MCP server

    MediumCVSS 5.1No exploitEPSS 0%

    aws · aws security agent mcp serverSep 10, 2026

  • Sentry kernel has incomplete ownership check for IRQ line manipulation

    MediumCVSS 5.1No exploitEPSS 0%

    camelot-os · sentry-kernelApr 17, 2026

  • A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attac

    MediumCVSS 5.1No exploitEPSS 0%

    fortinet · forticlientwindowsSep 8, 2026

All vulnerability classes