CWE-283 · 31 records
Unverified Ownership
CVEs in this class
31 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2024-27903No exploit | OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitraryopenvpn · openvpn · CWE-283 | Critical9.8 | — | 8.9% | Jul 8, 2024 |
36Monitor | CVE-2026-26016No exploit | Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorizationpterodactyl · panel · CWE-283 | Critical9.2 | — | 0.5% | Feb 19, 2026 |
33Monitor | CVE-2026-29788No exploit | TSPortal: Anyone can forge self-deletion requests of any userwikitide · tsportal · CWE-283 | High8.4 | — | 0.4% | Mar 6, 2026 |
32Monitor | CVE-2021-24501No exploit | Workreap theme < 2.2.2 - Missing Authorization Checks in Ajax Actionsamentotech · workreap · CWE-283 | High8.1 | — | 1.3% | Aug 9, 2021 |
32Monitor | CVE-2021-24500No exploit | Workreap theme < 2.2.2 - Multiple CSRF + IDOR Vulnerabilitiesamentotech · workreap · CWE-283 | High8.1 | — | 0.6% | Aug 9, 2021 |
31Monitor | CVE-2025-43882No exploit | Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability.dell · thinos · CWE-283 | High7.8 | — | 0.1% | Aug 27, 2025 |
28Monitor | CVE-2025-47940No exploit | TYPO3 CMS Vulnerable to Privilege Escalation to System Maintainertypo3 · typo3 · CWE-283 | High7.2 | — | 0.4% | May 20, 2025 |
28Monitor | CVE-2026-93853No exploit | Barman snapshot backup deletion trusts unverified backup catalog metadataenterprisedb · barman · CWE-283 | High7.2 | — | 0.2% | Sep 29, 2026 |
28Monitor | CVE-2026-54467No exploit | On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, trustedfirmware · trusted firmware-m · CWE-283 | High7.0 | — | 0.2% | Aug 26, 2026 |
27Monitor | CVE-2025-1007No exploit | Improper Authorization in /user/namespace/{namespace}/detailseclipse · open vsx · CWE-283 | Medium6.9 | — | 0.5% | Feb 19, 2025 |
27Monitor | CVE-2026-44707No exploit | Chatwoot: Pre-Account Takeover via OAuth on Unconfirmed Accountschatwoot · chatwoot · CWE-283 | Medium6.8 | — | 0.5% | May 26, 2026 |
27Monitor | CVE-2025-24890No exploit | gix-sec safe.directory protections absent for elevated administratorsgitoxidelabs · gitoxide · CWE-283 | Medium6.8 | — | 0.2% | Sep 14, 2026 |
26Monitor | CVE-2022-29220No exploit | No verification of commits origin in github-action-merge-dependabotfastify · github action merge dependabot · CWE-283 | Medium6.5 | — | 0.5% | May 31, 2022 |
26Monitor | CVE-2026-44562No exploit | Open WebUI: Model Import Overwrites Any Model Without Ownership Checkopenwebui · open webui · CWE-283 | Medium6.5 | — | 0.4% | May 15, 2026 |
26Monitor | CVE-2026-9745No exploit | Vulnerabilities exists in IBM Netezza Softwareibm · netezza performance server · CWE-283 | Medium6.5 | — | 0.3% | Sep 3, 2026 |
23Monitor | CVE-2020-8554Proof of concept | Kubernetes man in the middle using LoadBalancer or ExternalIPskubernetes · kubernetes · CWE-283 | Medium5.0 | — | 9.3% | Jan 21, 2021 |
23Monitor | CVE-2026-4269No exploit | Improper S3 ownership verification in Bedrock AgentCore Starter Toolkitamazon · bedrock agentcore starter toolkit · CWE-283 | Medium5.8 | — | 0.4% | Mar 16, 2026 |
22Monitor | CVE-2025-9822No exploit | Secret data extraction via elfindermautic · mautic · CWE-283 | Medium5.5 | — | 0.2% | Sep 3, 2025 |
22Monitor | CVE-2024-1853No exploit | Zemana AntiLogger v2.74.204.664 - Arbitrary Process Terminationzemena · antilogger · CWE-283 | Medium5.5 | — | 0.2% | Mar 14, 2024 |
21Monitor | CVE-2025-12815No exploit | An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.aws · research and engineering studio (res) · CWE-283 | Medium5.3 | — | 0.3% | Nov 6, 2025 |
20Monitor | CVE-2026-85781No exploit | Unverified access point ownership in Amazon EFS CSI Driveraws · aws-efs-csi-driver · CWE-283 | Medium5.1 | — | 0.4% | Sep 4, 2026 |
20Monitor | CVE-2026-87912No exploit | Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecopsaws · aws security agent plugin · CWE-283 | Medium5.1 | — | 0.4% | Sep 10, 2026 |
20Monitor | CVE-2026-87913No exploit | Missing S3 bucket ownership verification in the AWS Security Agent MCP serveraws · aws security agent mcp server · CWE-283 | Medium5.1 | — | 0.4% | Sep 10, 2026 |
20Monitor | CVE-2026-40337No exploit | Sentry kernel has incomplete ownership check for IRQ line manipulationcamelot-os · sentry-kernel · CWE-283 | Medium5.1 | — | 0.2% | Apr 17, 2026 |
20Monitor | CVE-2026-84386No exploit | A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacfortinet · forticlientwindows · CWE-283 | Medium5.1 | — | 0.1% | Sep 8, 2026 |
- CVE-2024-2790342Plan
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary
CriticalCVSS 9.8No exploitEPSS 9%openvpn · openvpnJul 8, 2024
- CVE-2026-2601636Monitor
Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization
CriticalCVSS 9.2No exploitEPSS 0%pterodactyl · panelFeb 19, 2026
- CVE-2026-2978833Monitor
TSPortal: Anyone can forge self-deletion requests of any user
HighCVSS 8.4No exploitEPSS 0%wikitide · tsportalMar 6, 2026
- CVE-2021-2450132Monitor
Workreap theme < 2.2.2 - Missing Authorization Checks in Ajax Actions
HighCVSS 8.1No exploitEPSS 1%amentotech · workreapAug 9, 2021
- CVE-2021-2450032Monitor
Workreap theme < 2.2.2 - Multiple CSRF + IDOR Vulnerabilities
HighCVSS 8.1No exploitEPSS 1%amentotech · workreapAug 9, 2021
- CVE-2025-4388231Monitor
Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability.
HighCVSS 7.8No exploitEPSS 0%dell · thinosAug 27, 2025
- CVE-2025-4794028Monitor
TYPO3 CMS Vulnerable to Privilege Escalation to System Maintainer
HighCVSS 7.2No exploitEPSS 0%typo3 · typo3May 20, 2025
- CVE-2026-9385328Monitor
Barman snapshot backup deletion trusts unverified backup catalog metadata
HighCVSS 7.2No exploitEPSS 0%enterprisedb · barmanSep 29, 2026
- CVE-2026-5446728Monitor
On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure,
HighCVSS 7.0No exploitEPSS 0%trustedfirmware · trusted firmware-mAug 26, 2026
- CVE-2025-100727Monitor
Improper Authorization in /user/namespace/{namespace}/details
MediumCVSS 6.9No exploitEPSS 1%eclipse · open vsxFeb 19, 2025
- CVE-2026-4470727Monitor
Chatwoot: Pre-Account Takeover via OAuth on Unconfirmed Accounts
MediumCVSS 6.8No exploitEPSS 0%chatwoot · chatwootMay 26, 2026
- CVE-2025-2489027Monitor
gix-sec safe.directory protections absent for elevated administrators
MediumCVSS 6.8No exploitEPSS 0%gitoxidelabs · gitoxideSep 14, 2026
- CVE-2022-2922026Monitor
No verification of commits origin in github-action-merge-dependabot
MediumCVSS 6.5No exploitEPSS 0%fastify · github action merge dependabotMay 31, 2022
- CVE-2026-4456226Monitor
Open WebUI: Model Import Overwrites Any Model Without Ownership Check
MediumCVSS 6.5No exploitEPSS 0%openwebui · open webuiMay 15, 2026
- CVE-2026-974526Monitor
Vulnerabilities exists in IBM Netezza Software
MediumCVSS 6.5No exploitEPSS 0%ibm · netezza performance serverSep 3, 2026
- CVE-2020-855423Monitor
Kubernetes man in the middle using LoadBalancer or ExternalIPs
MediumCVSS 5.0Proof of conceptEPSS 9%kubernetes · kubernetesJan 21, 2021
- CVE-2026-426923Monitor
Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit
MediumCVSS 5.8No exploitEPSS 0%amazon · bedrock agentcore starter toolkitMar 16, 2026
- CVE-2025-982222Monitor
Secret data extraction via elfinder
MediumCVSS 5.5No exploitEPSS 0%mautic · mauticSep 3, 2025
- CVE-2024-185322Monitor
Zemana AntiLogger v2.74.204.664 - Arbitrary Process Termination
MediumCVSS 5.5No exploitEPSS 0%zemena · antiloggerMar 14, 2024
- CVE-2025-1281521Monitor
An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.
MediumCVSS 5.3No exploitEPSS 0%aws · research and engineering studio (res)Nov 6, 2025
- CVE-2026-8578120Monitor
Unverified access point ownership in Amazon EFS CSI Driver
MediumCVSS 5.1No exploitEPSS 0%aws · aws-efs-csi-driverSep 4, 2026
- CVE-2026-8791220Monitor
Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops
MediumCVSS 5.1No exploitEPSS 0%aws · aws security agent pluginSep 10, 2026
- CVE-2026-8791320Monitor
Missing S3 bucket ownership verification in the AWS Security Agent MCP server
MediumCVSS 5.1No exploitEPSS 0%aws · aws security agent mcp serverSep 10, 2026
- CVE-2026-4033720Monitor
Sentry kernel has incomplete ownership check for IRQ line manipulation
MediumCVSS 5.1No exploitEPSS 0%camelot-os · sentry-kernelApr 17, 2026
- CVE-2026-8438620Monitor
A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attac
MediumCVSS 5.1No exploitEPSS 0%fortinet · forticlientwindowsSep 8, 2026