CWE-283 · 31 записей
Unverified Ownership
CVE этого класса
31 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2024-27903Эксплойта нет | OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitraryopenvpn · openvpn · CWE-283 | Критическая9,8 | — | 8,9 % | 8 июл. 2024 г. |
36Наблюдать | CVE-2026-26016Эксплойта нет | Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorizationpterodactyl · panel · CWE-283 | Критическая9,2 | — | 0,5 % | 19 февр. 2026 г. |
33Наблюдать | CVE-2026-29788Эксплойта нет | TSPortal: Anyone can forge self-deletion requests of any userwikitide · tsportal · CWE-283 | Высокая8,4 | — | 0,4 % | 6 мар. 2026 г. |
32Наблюдать | CVE-2021-24501Эксплойта нет | Workreap theme < 2.2.2 - Missing Authorization Checks in Ajax Actionsamentotech · workreap · CWE-283 | Высокая8,1 | — | 1,3 % | 9 авг. 2021 г. |
32Наблюдать | CVE-2021-24500Эксплойта нет | Workreap theme < 2.2.2 - Multiple CSRF + IDOR Vulnerabilitiesamentotech · workreap · CWE-283 | Высокая8,1 | — | 0,6 % | 9 авг. 2021 г. |
31Наблюдать | CVE-2025-43882Эксплойта нет | Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability.dell · thinos · CWE-283 | Высокая7,8 | — | 0,1 % | 27 авг. 2025 г. |
28Наблюдать | CVE-2025-47940Эксплойта нет | TYPO3 CMS Vulnerable to Privilege Escalation to System Maintainertypo3 · typo3 · CWE-283 | Высокая7,2 | — | 0,4 % | 20 мая 2025 г. |
28Наблюдать | CVE-2026-54467Эксплойта нет | On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, trustedfirmware · trusted firmware-m · CWE-283 | Высокая7,0 | — | 0,2 % | 26 авг. 2026 г. |
28Наблюдать | CVE-2026-93853Эксплойта нет | Barman snapshot backup deletion trusts unverified backup catalog metadataenterprisedb · barman · CWE-283 | Высокая7,2 | — | — | Сегодня |
27Наблюдать | CVE-2025-1007Эксплойта нет | Improper Authorization in /user/namespace/{namespace}/detailseclipse · open vsx · CWE-283 | Средняя6,9 | — | 0,5 % | 19 февр. 2025 г. |
27Наблюдать | CVE-2026-44707Эксплойта нет | Chatwoot: Pre-Account Takeover via OAuth on Unconfirmed Accountschatwoot · chatwoot · CWE-283 | Средняя6,8 | — | 0,5 % | 26 мая 2026 г. |
27Наблюдать | CVE-2025-24890Эксплойта нет | gix-sec safe.directory protections absent for elevated administratorsgitoxidelabs · gitoxide · CWE-283 | Средняя6,8 | — | 0,2 % | 14 сент. 2026 г. |
26Наблюдать | CVE-2022-29220Эксплойта нет | No verification of commits origin in github-action-merge-dependabotfastify · github action merge dependabot · CWE-283 | Средняя6,5 | — | 0,5 % | 31 мая 2022 г. |
26Наблюдать | CVE-2026-44562Эксплойта нет | Open WebUI: Model Import Overwrites Any Model Without Ownership Checkopenwebui · open webui · CWE-283 | Средняя6,5 | — | 0,4 % | 15 мая 2026 г. |
26Наблюдать | CVE-2026-9745Эксплойта нет | Vulnerabilities exists in IBM Netezza Softwareibm · netezza performance server · CWE-283 | Средняя6,5 | — | 0,3 % | 3 сент. 2026 г. |
23Наблюдать | CVE-2020-8554Proof of concept | Kubernetes man in the middle using LoadBalancer or ExternalIPskubernetes · kubernetes · CWE-283 | Средняя5,0 | — | 9,3 % | 21 янв. 2021 г. |
23Наблюдать | CVE-2026-4269Эксплойта нет | Improper S3 ownership verification in Bedrock AgentCore Starter Toolkitamazon · bedrock agentcore starter toolkit · CWE-283 | Средняя5,8 | — | 0,4 % | 16 мар. 2026 г. |
22Наблюдать | CVE-2025-9822Эксплойта нет | Secret data extraction via elfindermautic · mautic · CWE-283 | Средняя5,5 | — | 0,2 % | 3 сент. 2025 г. |
22Наблюдать | CVE-2024-1853Эксплойта нет | Zemana AntiLogger v2.74.204.664 - Arbitrary Process Terminationzemena · antilogger · CWE-283 | Средняя5,5 | — | 0,2 % | 14 мар. 2024 г. |
21Наблюдать | CVE-2025-12815Эксплойта нет | An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.aws · research and engineering studio (res) · CWE-283 | Средняя5,3 | — | 0,3 % | 6 нояб. 2025 г. |
20Наблюдать | CVE-2026-85781Эксплойта нет | Unverified access point ownership in Amazon EFS CSI Driveraws · aws-efs-csi-driver · CWE-283 | Средняя5,1 | — | 0,4 % | 4 сент. 2026 г. |
20Наблюдать | CVE-2026-87912Эксплойта нет | Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecopsaws · aws security agent plugin · CWE-283 | Средняя5,1 | — | 0,4 % | 10 сент. 2026 г. |
20Наблюдать | CVE-2026-87913Эксплойта нет | Missing S3 bucket ownership verification in the AWS Security Agent MCP serveraws · aws security agent mcp server · CWE-283 | Средняя5,1 | — | 0,4 % | 10 сент. 2026 г. |
20Наблюдать | CVE-2026-40337Эксплойта нет | Sentry kernel has incomplete ownership check for IRQ line manipulationcamelot-os · sentry-kernel · CWE-283 | Средняя5,1 | — | 0,2 % | 17 апр. 2026 г. |
20Наблюдать | CVE-2026-84386Эксплойта нет | A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacfortinet · forticlientwindows · CWE-283 | Средняя5,1 | — | 0,1 % | 8 сент. 2026 г. |
- CVE-2024-2790342В плане
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %openvpn · openvpn8 июл. 2024 г.
- CVE-2026-2601636Наблюдать
Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization
КритическаяCVSS 9,2Эксплойта нетEPSS 0 %pterodactyl · panel19 февр. 2026 г.
- CVE-2026-2978833Наблюдать
TSPortal: Anyone can forge self-deletion requests of any user
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %wikitide · tsportal6 мар. 2026 г.
- CVE-2021-2450132Наблюдать
Workreap theme < 2.2.2 - Missing Authorization Checks in Ajax Actions
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %amentotech · workreap9 авг. 2021 г.
- CVE-2021-2450032Наблюдать
Workreap theme < 2.2.2 - Multiple CSRF + IDOR Vulnerabilities
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %amentotech · workreap9 авг. 2021 г.
- CVE-2025-4388231Наблюдать
Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %dell · thinos27 авг. 2025 г.
- CVE-2025-4794028Наблюдать
TYPO3 CMS Vulnerable to Privilege Escalation to System Maintainer
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %typo3 · typo320 мая 2025 г.
- CVE-2026-5446728Наблюдать
On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure,
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %trustedfirmware · trusted firmware-m26 авг. 2026 г.
- CVE-2026-9385328Наблюдать
Barman snapshot backup deletion trusts unverified backup catalog metadata
ВысокаяCVSS 7,2Эксплойта нетenterprisedb · barmanСегодня
- CVE-2025-100727Наблюдать
Improper Authorization in /user/namespace/{namespace}/details
СредняяCVSS 6,9Эксплойта нетEPSS 1 %eclipse · open vsx19 февр. 2025 г.
- CVE-2026-4470727Наблюдать
Chatwoot: Pre-Account Takeover via OAuth on Unconfirmed Accounts
СредняяCVSS 6,8Эксплойта нетEPSS 0 %chatwoot · chatwoot26 мая 2026 г.
- CVE-2025-2489027Наблюдать
gix-sec safe.directory protections absent for elevated administrators
СредняяCVSS 6,8Эксплойта нетEPSS 0 %gitoxidelabs · gitoxide14 сент. 2026 г.
- CVE-2022-2922026Наблюдать
No verification of commits origin in github-action-merge-dependabot
СредняяCVSS 6,5Эксплойта нетEPSS 0 %fastify · github action merge dependabot31 мая 2022 г.
- CVE-2026-4456226Наблюдать
Open WebUI: Model Import Overwrites Any Model Without Ownership Check
СредняяCVSS 6,5Эксплойта нетEPSS 0 %openwebui · open webui15 мая 2026 г.
- CVE-2026-974526Наблюдать
Vulnerabilities exists in IBM Netezza Software
СредняяCVSS 6,5Эксплойта нетEPSS 0 %ibm · netezza performance server3 сент. 2026 г.
- CVE-2020-855423Наблюдать
Kubernetes man in the middle using LoadBalancer or ExternalIPs
СредняяCVSS 5,0Proof of conceptEPSS 9 %kubernetes · kubernetes21 янв. 2021 г.
- CVE-2026-426923Наблюдать
Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit
СредняяCVSS 5,8Эксплойта нетEPSS 0 %amazon · bedrock agentcore starter toolkit16 мар. 2026 г.
- CVE-2025-982222Наблюдать
Secret data extraction via elfinder
СредняяCVSS 5,5Эксплойта нетEPSS 0 %mautic · mautic3 сент. 2025 г.
- CVE-2024-185322Наблюдать
Zemana AntiLogger v2.74.204.664 - Arbitrary Process Termination
СредняяCVSS 5,5Эксплойта нетEPSS 0 %zemena · antilogger14 мар. 2024 г.
- CVE-2025-1281521Наблюдать
An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.
СредняяCVSS 5,3Эксплойта нетEPSS 0 %aws · research and engineering studio (res)6 нояб. 2025 г.
- CVE-2026-8578120Наблюдать
Unverified access point ownership in Amazon EFS CSI Driver
СредняяCVSS 5,1Эксплойта нетEPSS 0 %aws · aws-efs-csi-driver4 сент. 2026 г.
- CVE-2026-8791220Наблюдать
Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops
СредняяCVSS 5,1Эксплойта нетEPSS 0 %aws · aws security agent plugin10 сент. 2026 г.
- CVE-2026-8791320Наблюдать
Missing S3 bucket ownership verification in the AWS Security Agent MCP server
СредняяCVSS 5,1Эксплойта нетEPSS 0 %aws · aws security agent mcp server10 сент. 2026 г.
- CVE-2026-4033720Наблюдать
Sentry kernel has incomplete ownership check for IRQ line manipulation
СредняяCVSS 5,1Эксплойта нетEPSS 0 %camelot-os · sentry-kernel17 апр. 2026 г.
- CVE-2026-8438620Наблюдать
A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attac
СредняяCVSS 5,1Эксплойта нетEPSS 0 %fortinet · forticlientwindows8 сент. 2026 г.