Skip to content
Noroxi

CWE-708 · 19 records

Incorrect Ownership Assignment

CVEs in this class

19 records

  • Webauthn tokens not removed after user has been deleted

    CriticalCVSS 9.8No exploitEPSS 2%

    nextcloud · nextcloud serverJul 12, 2021

  • CVE-2023-4008
    39Monitor

    Incorrect Ownership Assignment in GitLab

    CriticalCVSS 9.8No exploitEPSS 1%

    gitlab · gitlabAug 3, 2023

  • HomeBox has Unauthorized API Access via Retained defaultGroup ID After Group Access Revocation

    HighCVSS 8.1No exploitEPSS 0%

    sysadminsmedia · homeboxApr 17, 2026

  • A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740).

    HighCVSS 7.8No exploitEPSS 0%

    parallels · parallels desktopJun 3, 2025

  • The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a rand

    HighCVSS 7.5No exploitEPSS 1%

    openvpn · openvpn access serverJul 6, 2022

  • CVE-2024-9633
    30Monitor

    Incorrect Ownership Assignment in GitLab

    HighCVSS 7.5No exploitEPSS 0%

    gitlab · gitlabNov 14, 2024

  • A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges.

    HighCVSS 7.3No exploitEPSS 0%

    cisco · cx cloud agentJan 20, 2023

  • Zoom Workplace Apps - Incorrect Ownership Assignment

    MediumCVSS 6.5No exploitEPSS 0%

    zoom · meeting software development kitFeb 25, 2025

  • IBM Global Configuration Management incorrect ownership assignment

    MediumCVSS 6.5No exploitEPSS 0%

    ibm · global configuration managementAug 20, 2024

  • CVE-2025-5069
    26Monitor

    Incorrect Ownership Assignment in GitLab

    MediumCVSS 6.5No exploitEPSS 0%

    gitlab · gitlabSep 26, 2025

  • A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges.

    MediumCVSS 6.7No exploitEPSS 0%

    cisco · cx cloud agentJan 20, 2023

  • Incorrect file ownership of privileged service's libraries in Enel X JuiceBox

    MediumCVSS 6.7No exploitEPSS 0%

    enel x · juicebox pro 3.0 22kw cellularNov 5, 2024

  • Philips MRI 1.5T and 3T Incorrect Ownership Assignment

    MediumCVSS 5.9No exploitEPSS 0%

    philips · mri 3t firmwareNov 19, 2021

  • Zoom Apps for macOS - Uncontrolled Resource Consumption

    MediumCVSS 5.5No exploitEPSS 0%

    zoom · meeting software development kitFeb 25, 2025

  • Lemmy user purging users or communities or banning users can delete images they didn't upload/exclusively use

    MediumCVSS 5.5No exploit

    crates.io · lemmy_serverApr 8, 2025

  • Timing ownership claim attack on new external back-end secrets

    MediumCVSS 5.3No exploitEPSS 0%

    canonical · jujuMar 18, 2026

  • Jobs can be saved as workflows with wrong permissions on KNIME Business Hub

    MediumCVSS 5.3No exploitEPSS 0%

    knime · business hubDec 8, 2025

  • CVE-2026-6469
    15Monitor

    PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership

    LowCVSS 3.8No exploitEPSS 0%

    postgresql · postgresqlAug 13, 2026

  • Ubuntu Apport Insecure File Permissions Vulnerability

    LowCVSS 1.9No exploitEPSS 0%

    canonical · apportDec 10, 2025

All vulnerability classes