CWE-282 · 30 записей
Improper Ownership Management
CVE этого класса
30 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
63На этой неделе | CVE-2023-0386Готовый эксплойт | A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linuxlinux · linux kernel · CWE-282 | Высокая7,8 | KEV | 7,9 % | 22 мар. 2023 г. |
36Наблюдать | CVE-2024-3383Эксплойта нет | PAN-OS: Improper Group Membership Change Vulnerability in Cloud Identity Engine (CIE)paloaltonetworks · pan-os · CWE-282 | Критическая9,1 | — | 0,6 % | 10 апр. 2024 г. |
35Наблюдать | CVE-2026-50130Эксплойта нет | Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`pi-hole · pi-hole · CWE-282 | Высокая8,8 | — | 0,3 % | 14 июл. 2026 г. |
34Наблюдать | CVE-2024-37999Эксплойта нет | A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions).siemens · medicalis workflow orchestrator · CWE-282 | Высокая8,5 | — | 0,1 % | 8 июл. 2024 г. |
32Наблюдать | CVE-2025-27254Эксплойта нет | CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass.ge vernova · enervista ur setup · CWE-282 | Высокая8,0 | — | 0,2 % | 10 мар. 2025 г. |
31Наблюдать | CVE-2022-29187Эксплойта нет | Bypass of safe.directory protections in Gitgit-scm · git · CWE-282 | Высокая7,8 | — | 0,4 % | 12 июл. 2022 г. |
31Наблюдать | CVE-2024-39755Эксплойта нет | A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0.veertu · anka build cloud · CWE-282 | Высокая7,8 | — | 0,4 % | 3 окт. 2024 г. |
31Наблюдать | CVE-2017-12189Эксплойта нет | It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handlinredhat · jboss enterprise application platform · CWE-282 | Высокая7,8 | — | 0,3 % | 10 янв. 2018 г. |
26Наблюдать | CVE-2026-23514Эксплойта нет | Kiteworks Core before 9.2.2 is vulnerable to Improper Ownership Managementaccellion · kiteworks · CWE-282 | Средняя6,5 | — | 1,0 % | 25 мар. 2026 г. |
26Наблюдать | CVE-2023-7226Эксплойта нет | meetyoucrop big-whale Admin Module all.api improper ownership managementmeiyou · big whale · CWE-282 | Средняя6,5 | — | 0,4 % | 11 янв. 2024 г. |
26Наблюдать | CVE-2022-0026Эксплойта нет | Cortex XDR Agent: Unintended Program Execution Leads to Local Privilege Escalation (PE) Vulnerabilitypaloaltonetworks · cortex xdr agent · CWE-282 | Средняя6,7 | — | 0,2 % | 11 мая 2022 г. |
26Наблюдать | CVE-2024-45104Эксплойта нет | A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device thrlenovo · xclarity administrator · CWE-282 | Средняя6,5 | — | 0,2 % | 13 сент. 2024 г. |
25Наблюдать | CVE-2024-47816Эксплойта нет | Users can impersonate import requesters if their actor IDs coincide in ImportDumpmiraheze · importdump · CWE-282 | Средняя6,4 | — | 0,3 % | 9 окт. 2024 г. |
25Наблюдать | CVE-2026-40214Эксплойта нет | In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer.openstack · cyborg · CWE-282 | Средняя6,3 | — | 0,3 % | 7 мая 2026 г. |
25Наблюдать | CVE-2025-57732Эксплойта нет | In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownershipjetbrains · teamcity · CWE-282 | Средняя6,3 | — | 0,1 % | 20 авг. 2025 г. |
24Наблюдать | CVE-2026-3867Эксплойта нет | An improper ownership management vulnerability has been identified in Moxa’s Secure Router.moxa · edr-8010 series · CWE-282 | Средняя6,0 | — | 0,4 % | 27 апр. 2026 г. |
22Наблюдать | CVE-2023-0989Эксплойта нет | Improper Ownership Management in GitLabgitlab · gitlab · CWE-282 | Средняя5,7 | — | 0,5 % | 29 сент. 2023 г. |
21Наблюдать | CVE-2024-8949Proof of concept | SourceCodester Online Eyewear Shop Cart Content Master.php improper ownership managementoretnom23 · online eyewear shop · CWE-282 | Средняя5,3 | — | 0,7 % | 17 сент. 2024 г. |
21Наблюдать | CVE-2020-10632Эксплойта нет | ICSA-20-140-02 Emerson OpenEnterpriseemerson · openenterprise scada server · CWE-282 | Средняя5,3 | — | 0,5 % | 24 февр. 2022 г. |
21Наблюдать | CVE-2025-32946Эксплойта нет | PeerTube Arbitrary Playlist Creation via ActivityPub Protocolframasoft · peertube · CWE-282 | Средняя5,3 | — | 0,4 % | 15 апр. 2025 г. |
21Наблюдать | CVE-2024-43176Эксплойта нет | IBM OpenPages information disclosureibm · openpages with watson · CWE-282 | Средняя5,4 | — | 0,3 % | 9 янв. 2025 г. |
21Наблюдать | CVE-2026-86769Эксплойта нет | Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkoutsnipeitapp · snipe-it · CWE-282 | Средняя5,3 | — | 0,3 % | 9 сент. 2026 г. |
21Наблюдать | CVE-2024-13246Эксплойта нет | Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-010node access rebuild progressive project · node access rebuild progressive · CWE-282 | Средняя5,3 | — | 0,3 % | 9 янв. 2025 г. |
21Наблюдать | CVE-2024-13249Эксплойта нет | Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-013node access rebuild progressive project · node access rebuild progressive · CWE-282 | Средняя5,4 | — | 0,2 % | 9 янв. 2025 г. |
17Наблюдать | CVE-2024-45103Эксплойта нет | A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privilelenovo · xclarity administrator · CWE-282 | Средняя4,3 | — | 0,3 % | 13 сент. 2024 г. |
- CVE-2023-038663На этой неделе
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 8 %linux · linux kernel22 мар. 2023 г.
- CVE-2024-338336Наблюдать
PAN-OS: Improper Group Membership Change Vulnerability in Cloud Identity Engine (CIE)
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %paloaltonetworks · pan-os10 апр. 2024 г.
- CVE-2026-5013035Наблюдать
Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %pi-hole · pi-hole14 июл. 2026 г.
- CVE-2024-3799934Наблюдать
A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions).
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %siemens · medicalis workflow orchestrator8 июл. 2024 г.
- CVE-2025-2725432Наблюдать
CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass.
ВысокаяCVSS 8,0Эксплойта нетEPSS 0 %ge vernova · enervista ur setup10 мар. 2025 г.
- CVE-2022-2918731Наблюдать
Bypass of safe.directory protections in Git
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %git-scm · git12 июл. 2022 г.
- CVE-2024-3975531Наблюдать
A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %veertu · anka build cloud3 окт. 2024 г.
- CVE-2017-1218931Наблюдать
It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handlin
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %redhat · jboss enterprise application platform10 янв. 2018 г.
- CVE-2026-2351426Наблюдать
Kiteworks Core before 9.2.2 is vulnerable to Improper Ownership Management
СредняяCVSS 6,5Эксплойта нетEPSS 1 %accellion · kiteworks25 мар. 2026 г.
- CVE-2023-722626Наблюдать
meetyoucrop big-whale Admin Module all.api improper ownership management
СредняяCVSS 6,5Эксплойта нетEPSS 0 %meiyou · big whale11 янв. 2024 г.
- CVE-2022-002626Наблюдать
Cortex XDR Agent: Unintended Program Execution Leads to Local Privilege Escalation (PE) Vulnerability
СредняяCVSS 6,7Эксплойта нетEPSS 0 %paloaltonetworks · cortex xdr agent11 мая 2022 г.
- CVE-2024-4510426Наблюдать
A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device thr
СредняяCVSS 6,5Эксплойта нетEPSS 0 %lenovo · xclarity administrator13 сент. 2024 г.
- CVE-2024-4781625Наблюдать
Users can impersonate import requesters if their actor IDs coincide in ImportDump
СредняяCVSS 6,4Эксплойта нетEPSS 0 %miraheze · importdump9 окт. 2024 г.
- CVE-2026-4021425Наблюдать
In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer.
СредняяCVSS 6,3Эксплойта нетEPSS 0 %openstack · cyborg7 мая 2026 г.
- CVE-2025-5773225Наблюдать
In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership
СредняяCVSS 6,3Эксплойта нетEPSS 0 %jetbrains · teamcity20 авг. 2025 г.
- CVE-2026-386724Наблюдать
An improper ownership management vulnerability has been identified in Moxa’s Secure Router.
СредняяCVSS 6,0Эксплойта нетEPSS 0 %moxa · edr-8010 series27 апр. 2026 г.
- CVE-2023-098922Наблюдать
Improper Ownership Management in GitLab
СредняяCVSS 5,7Эксплойта нетEPSS 1 %gitlab · gitlab29 сент. 2023 г.
- CVE-2024-894921Наблюдать
SourceCodester Online Eyewear Shop Cart Content Master.php improper ownership management
СредняяCVSS 5,3Proof of conceptEPSS 1 %oretnom23 · online eyewear shop17 сент. 2024 г.
- CVE-2020-1063221Наблюдать
ICSA-20-140-02 Emerson OpenEnterprise
СредняяCVSS 5,3Эксплойта нетEPSS 0 %emerson · openenterprise scada server24 февр. 2022 г.
- CVE-2025-3294621Наблюдать
PeerTube Arbitrary Playlist Creation via ActivityPub Protocol
СредняяCVSS 5,3Эксплойта нетEPSS 0 %framasoft · peertube15 апр. 2025 г.
- CVE-2024-4317621Наблюдать
IBM OpenPages information disclosure
СредняяCVSS 5,4Эксплойта нетEPSS 0 %ibm · openpages with watson9 янв. 2025 г.
- CVE-2026-8676921Наблюдать
Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout
СредняяCVSS 5,3Эксплойта нетEPSS 0 %snipeitapp · snipe-it9 сент. 2026 г.
- CVE-2024-1324621Наблюдать
Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-010
СредняяCVSS 5,3Эксплойта нетEPSS 0 %node access rebuild progressive project · node access rebuild progressive9 янв. 2025 г.
- CVE-2024-1324921Наблюдать
Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-013
СредняяCVSS 5,4Эксплойта нетEPSS 0 %node access rebuild progressive project · node access rebuild progressive9 янв. 2025 г.
- CVE-2024-4510317Наблюдать
A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privile
СредняяCVSS 4,3Эксплойта нетEPSS 0 %lenovo · xclarity administrator13 сент. 2024 г.