Перейти к содержимому
Noroxi

CWE-283 · 31 записей

Unverified Ownership

CVE этого класса

31 записей

  • CVE-2024-27903
    42В плане

    OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary

    КритическаяCVSS 9,8Эксплойта нетEPSS 9 %

    openvpn · openvpn8 июл. 2024 г.

  • CVE-2026-26016
    36Наблюдать

    Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization

    КритическаяCVSS 9,2Эксплойта нетEPSS 0 %

    pterodactyl · panel19 февр. 2026 г.

  • CVE-2026-29788
    33Наблюдать

    TSPortal: Anyone can forge self-deletion requests of any user

    ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %

    wikitide · tsportal6 мар. 2026 г.

  • CVE-2021-24501
    32Наблюдать

    Workreap theme < 2.2.2 - Missing Authorization Checks in Ajax Actions

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    amentotech · workreap9 авг. 2021 г.

  • CVE-2021-24500
    32Наблюдать

    Workreap theme < 2.2.2 - Multiple CSRF + IDOR Vulnerabilities

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    amentotech · workreap9 авг. 2021 г.

  • CVE-2025-43882
    31Наблюдать

    Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    dell · thinos27 авг. 2025 г.

  • CVE-2025-47940
    28Наблюдать

    TYPO3 CMS Vulnerable to Privilege Escalation to System Maintainer

    ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %

    typo3 · typo320 мая 2025 г.

  • CVE-2026-54467
    28Наблюдать

    On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure,

    ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %

    trustedfirmware · trusted firmware-m26 авг. 2026 г.

  • CVE-2026-93853
    28Наблюдать

    Barman snapshot backup deletion trusts unverified backup catalog metadata

    ВысокаяCVSS 7,2Эксплойта нет

    enterprisedb · barmanСегодня

  • CVE-2025-1007
    27Наблюдать

    Improper Authorization in /user/namespace/{namespace}/details

    СредняяCVSS 6,9Эксплойта нетEPSS 1 %

    eclipse · open vsx19 февр. 2025 г.

  • CVE-2026-44707
    27Наблюдать

    Chatwoot: Pre-Account Takeover via OAuth on Unconfirmed Accounts

    СредняяCVSS 6,8Эксплойта нетEPSS 0 %

    chatwoot · chatwoot26 мая 2026 г.

  • CVE-2025-24890
    27Наблюдать

    gix-sec safe.directory protections absent for elevated administrators

    СредняяCVSS 6,8Эксплойта нетEPSS 0 %

    gitoxidelabs · gitoxide14 сент. 2026 г.

  • CVE-2022-29220
    26Наблюдать

    No verification of commits origin in github-action-merge-dependabot

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    fastify · github action merge dependabot31 мая 2022 г.

  • CVE-2026-44562
    26Наблюдать

    Open WebUI: Model Import Overwrites Any Model Without Ownership Check

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    openwebui · open webui15 мая 2026 г.

  • CVE-2026-9745
    26Наблюдать

    Vulnerabilities exists in IBM Netezza Software

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    ibm · netezza performance server3 сент. 2026 г.

  • CVE-2020-8554
    23Наблюдать

    Kubernetes man in the middle using LoadBalancer or ExternalIPs

    СредняяCVSS 5,0Proof of conceptEPSS 9 %

    kubernetes · kubernetes21 янв. 2021 г.

  • CVE-2026-4269
    23Наблюдать

    Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit

    СредняяCVSS 5,8Эксплойта нетEPSS 0 %

    amazon · bedrock agentcore starter toolkit16 мар. 2026 г.

  • CVE-2025-9822
    22Наблюдать

    Secret data extraction via elfinder

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    mautic · mautic3 сент. 2025 г.

  • CVE-2024-1853
    22Наблюдать

    Zemana AntiLogger v2.74.204.664 - Arbitrary Process Termination

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    zemena · antilogger14 мар. 2024 г.

  • CVE-2025-12815
    21Наблюдать

    An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    aws · research and engineering studio (res)6 нояб. 2025 г.

  • CVE-2026-85781
    20Наблюдать

    Unverified access point ownership in Amazon EFS CSI Driver

    СредняяCVSS 5,1Эксплойта нетEPSS 0 %

    aws · aws-efs-csi-driver4 сент. 2026 г.

  • CVE-2026-87912
    20Наблюдать

    Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops

    СредняяCVSS 5,1Эксплойта нетEPSS 0 %

    aws · aws security agent plugin10 сент. 2026 г.

  • CVE-2026-87913
    20Наблюдать

    Missing S3 bucket ownership verification in the AWS Security Agent MCP server

    СредняяCVSS 5,1Эксплойта нетEPSS 0 %

    aws · aws security agent mcp server10 сент. 2026 г.

  • CVE-2026-40337
    20Наблюдать

    Sentry kernel has incomplete ownership check for IRQ line manipulation

    СредняяCVSS 5,1Эксплойта нетEPSS 0 %

    camelot-os · sentry-kernel17 апр. 2026 г.

  • CVE-2026-84386
    20Наблюдать

    A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attac

    СредняяCVSS 5,1Эксплойта нетEPSS 0 %

    fortinet · forticlientwindows8 сент. 2026 г.

Все классы уязвимостей