CWE-708 · 19 records
Incorrect Ownership Assignment
CVEs in this class
19 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2021-32726No exploit | Webauthn tokens not removed after user has been deletednextcloud · nextcloud server · CWE-708 | Critical9.8 | — | 1.8% | Jul 12, 2021 |
39Monitor | CVE-2023-4008No exploit | Incorrect Ownership Assignment in GitLabgitlab · gitlab · CWE-708 | Critical9.8 | — | 0.7% | Aug 3, 2023 |
32Monitor | CVE-2026-40196No exploit | HomeBox has Unauthorized API Access via Retained defaultGroup ID After Group Access Revocationsysadminsmedia · homebox · CWE-708 | High8.1 | — | 0.4% | Apr 17, 2026 |
31Monitor | CVE-2024-52561No exploit | A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740).parallels · parallels desktop · CWE-708 | High7.8 | — | 0.3% | Jun 3, 2025 |
30Monitor | CVE-2022-33737No exploit | The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a randopenvpn · openvpn access server · CWE-708 | High7.5 | — | 0.9% | Jul 6, 2022 |
30Monitor | CVE-2024-9633No exploit | Incorrect Ownership Assignment in GitLabgitlab · gitlab · CWE-708 | High7.5 | — | 0.5% | Nov 14, 2024 |
29Monitor | CVE-2023-20044No exploit | A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges.cisco · cx cloud agent · CWE-708 | High7.3 | — | 0.1% | Jan 20, 2023 |
26Monitor | CVE-2024-45426No exploit | Zoom Workplace Apps - Incorrect Ownership Assignmentzoom · meeting software development kit · CWE-708 | Medium6.5 | — | 0.3% | Feb 25, 2025 |
26Monitor | CVE-2024-41773No exploit | IBM Global Configuration Management incorrect ownership assignmentibm · global configuration management · CWE-708 | Medium6.5 | — | 0.3% | Aug 20, 2024 |
26Monitor | CVE-2025-5069No exploit | Incorrect Ownership Assignment in GitLabgitlab · gitlab · CWE-708 | Medium6.5 | — | 0.2% | Sep 26, 2025 |
26Monitor | CVE-2023-20043No exploit | A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges.cisco · cx cloud agent · CWE-708 | Medium6.7 | — | 0.2% | Jan 20, 2023 |
26Monitor | CVE-2023-29122No exploit | Incorrect file ownership of privileged service's libraries in Enel X JuiceBoxenel x · juicebox pro 3.0 22kw cellular · CWE-708 | Medium6.7 | — | 0.2% | Nov 5, 2024 |
23Monitor | CVE-2021-26248No exploit | Philips MRI 1.5T and 3T Incorrect Ownership Assignmentphilips · mri 3t firmware · CWE-708 | Medium5.9 | — | 0.2% | Nov 19, 2021 |
22Monitor | CVE-2024-45417No exploit | Zoom Apps for macOS - Uncontrolled Resource Consumptionzoom · meeting software development kit · CWE-708 | Medium5.5 | — | 0.2% | Feb 25, 2025 |
22Monitor | GHSA-wr2m-38xh-rpc9No exploit | Lemmy user purging users or communities or banning users can delete images they didn't upload/exclusively usecrates.io · lemmy_server · CWE-708 | Medium5.5 | — | — | Apr 8, 2025 |
21Monitor | CVE-2026-32691No exploit | Timing ownership claim attack on new external back-end secretscanonical · juju · CWE-708 | Medium5.3 | — | 0.3% | Mar 18, 2026 |
21Monitor | CVE-2025-14262No exploit | Jobs can be saved as workflows with wrong permissions on KNIME Business Hubknime · business hub · CWE-708 | Medium5.3 | — | 0.2% | Dec 8, 2025 |
15Monitor | CVE-2026-6469No exploit | PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownershippostgresql · postgresql · CWE-708 | Low3.8 | — | 0.3% | Aug 13, 2026 |
7Monitor | CVE-2025-5467No exploit | Ubuntu Apport Insecure File Permissions Vulnerabilitycanonical · apport · CWE-708 | Low1.9 | — | 0.2% | Dec 10, 2025 |
- CVE-2021-3272640Plan
Webauthn tokens not removed after user has been deleted
CriticalCVSS 9.8No exploitEPSS 2%nextcloud · nextcloud serverJul 12, 2021
- CVE-2023-400839Monitor
Incorrect Ownership Assignment in GitLab
CriticalCVSS 9.8No exploitEPSS 1%gitlab · gitlabAug 3, 2023
- CVE-2026-4019632Monitor
HomeBox has Unauthorized API Access via Retained defaultGroup ID After Group Access Revocation
HighCVSS 8.1No exploitEPSS 0%sysadminsmedia · homeboxApr 17, 2026
- CVE-2024-5256131Monitor
A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740).
HighCVSS 7.8No exploitEPSS 0%parallels · parallels desktopJun 3, 2025
- CVE-2022-3373730Monitor
The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a rand
HighCVSS 7.5No exploitEPSS 1%openvpn · openvpn access serverJul 6, 2022
- CVE-2024-963330Monitor
Incorrect Ownership Assignment in GitLab
HighCVSS 7.5No exploitEPSS 0%gitlab · gitlabNov 14, 2024
- CVE-2023-2004429Monitor
A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges.
HighCVSS 7.3No exploitEPSS 0%cisco · cx cloud agentJan 20, 2023
- CVE-2024-4542626Monitor
Zoom Workplace Apps - Incorrect Ownership Assignment
MediumCVSS 6.5No exploitEPSS 0%zoom · meeting software development kitFeb 25, 2025
- CVE-2024-4177326Monitor
IBM Global Configuration Management incorrect ownership assignment
MediumCVSS 6.5No exploitEPSS 0%ibm · global configuration managementAug 20, 2024
- CVE-2025-506926Monitor
Incorrect Ownership Assignment in GitLab
MediumCVSS 6.5No exploitEPSS 0%gitlab · gitlabSep 26, 2025
- CVE-2023-2004326Monitor
A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges.
MediumCVSS 6.7No exploitEPSS 0%cisco · cx cloud agentJan 20, 2023
- CVE-2023-2912226Monitor
Incorrect file ownership of privileged service's libraries in Enel X JuiceBox
MediumCVSS 6.7No exploitEPSS 0%enel x · juicebox pro 3.0 22kw cellularNov 5, 2024
- CVE-2021-2624823Monitor
Philips MRI 1.5T and 3T Incorrect Ownership Assignment
MediumCVSS 5.9No exploitEPSS 0%philips · mri 3t firmwareNov 19, 2021
- CVE-2024-4541722Monitor
Zoom Apps for macOS - Uncontrolled Resource Consumption
MediumCVSS 5.5No exploitEPSS 0%zoom · meeting software development kitFeb 25, 2025
- GHSA-wr2m-38xh-rpc922Monitor
Lemmy user purging users or communities or banning users can delete images they didn't upload/exclusively use
MediumCVSS 5.5No exploitcrates.io · lemmy_serverApr 8, 2025
- CVE-2026-3269121Monitor
Timing ownership claim attack on new external back-end secrets
MediumCVSS 5.3No exploitEPSS 0%canonical · jujuMar 18, 2026
- CVE-2025-1426221Monitor
Jobs can be saved as workflows with wrong permissions on KNIME Business Hub
MediumCVSS 5.3No exploitEPSS 0%knime · business hubDec 8, 2025
- CVE-2026-646915Monitor
PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership
LowCVSS 3.8No exploitEPSS 0%postgresql · postgresqlAug 13, 2026
- CVE-2025-54677Monitor
Ubuntu Apport Insecure File Permissions Vulnerability
LowCVSS 1.9No exploitEPSS 0%canonical · apportDec 10, 2025