CWE-708 · 19 записей
Incorrect Ownership Assignment
CVE этого класса
19 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2021-32726Эксплойта нет | Webauthn tokens not removed after user has been deletednextcloud · nextcloud server · CWE-708 | Критическая9,8 | — | 1,8 % | 12 июл. 2021 г. |
39Наблюдать | CVE-2023-4008Эксплойта нет | Incorrect Ownership Assignment in GitLabgitlab · gitlab · CWE-708 | Критическая9,8 | — | 0,7 % | 3 авг. 2023 г. |
32Наблюдать | CVE-2026-40196Эксплойта нет | HomeBox has Unauthorized API Access via Retained defaultGroup ID After Group Access Revocationsysadminsmedia · homebox · CWE-708 | Высокая8,1 | — | 0,4 % | 17 апр. 2026 г. |
31Наблюдать | CVE-2024-52561Эксплойта нет | A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740).parallels · parallels desktop · CWE-708 | Высокая7,8 | — | 0,3 % | 3 июн. 2025 г. |
30Наблюдать | CVE-2022-33737Эксплойта нет | The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a randopenvpn · openvpn access server · CWE-708 | Высокая7,5 | — | 0,9 % | 6 июл. 2022 г. |
30Наблюдать | CVE-2024-9633Эксплойта нет | Incorrect Ownership Assignment in GitLabgitlab · gitlab · CWE-708 | Высокая7,5 | — | 0,5 % | 14 нояб. 2024 г. |
29Наблюдать | CVE-2023-20044Эксплойта нет | A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges.cisco · cx cloud agent · CWE-708 | Высокая7,3 | — | 0,1 % | 20 янв. 2023 г. |
26Наблюдать | CVE-2024-45426Эксплойта нет | Zoom Workplace Apps - Incorrect Ownership Assignmentzoom · meeting software development kit · CWE-708 | Средняя6,5 | — | 0,3 % | 25 февр. 2025 г. |
26Наблюдать | CVE-2024-41773Эксплойта нет | IBM Global Configuration Management incorrect ownership assignmentibm · global configuration management · CWE-708 | Средняя6,5 | — | 0,3 % | 20 авг. 2024 г. |
26Наблюдать | CVE-2025-5069Эксплойта нет | Incorrect Ownership Assignment in GitLabgitlab · gitlab · CWE-708 | Средняя6,5 | — | 0,2 % | 26 сент. 2025 г. |
26Наблюдать | CVE-2023-20043Эксплойта нет | A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges.cisco · cx cloud agent · CWE-708 | Средняя6,7 | — | 0,2 % | 20 янв. 2023 г. |
26Наблюдать | CVE-2023-29122Эксплойта нет | Incorrect file ownership of privileged service's libraries in Enel X JuiceBoxenel x · juicebox pro 3.0 22kw cellular · CWE-708 | Средняя6,7 | — | 0,2 % | 5 нояб. 2024 г. |
23Наблюдать | CVE-2021-26248Эксплойта нет | Philips MRI 1.5T and 3T Incorrect Ownership Assignmentphilips · mri 3t firmware · CWE-708 | Средняя5,9 | — | 0,2 % | 19 нояб. 2021 г. |
22Наблюдать | CVE-2024-45417Эксплойта нет | Zoom Apps for macOS - Uncontrolled Resource Consumptionzoom · meeting software development kit · CWE-708 | Средняя5,5 | — | 0,2 % | 25 февр. 2025 г. |
22Наблюдать | GHSA-wr2m-38xh-rpc9Эксплойта нет | Lemmy user purging users or communities or banning users can delete images they didn't upload/exclusively usecrates.io · lemmy_server · CWE-708 | Средняя5,5 | — | — | 8 апр. 2025 г. |
21Наблюдать | CVE-2026-32691Эксплойта нет | Timing ownership claim attack on new external back-end secretscanonical · juju · CWE-708 | Средняя5,3 | — | 0,3 % | 18 мар. 2026 г. |
21Наблюдать | CVE-2025-14262Эксплойта нет | Jobs can be saved as workflows with wrong permissions on KNIME Business Hubknime · business hub · CWE-708 | Средняя5,3 | — | 0,2 % | 8 дек. 2025 г. |
15Наблюдать | CVE-2026-6469Эксплойта нет | PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownershippostgresql · postgresql · CWE-708 | Низкая3,8 | — | 0,3 % | 13 авг. 2026 г. |
7Наблюдать | CVE-2025-5467Эксплойта нет | Ubuntu Apport Insecure File Permissions Vulnerabilitycanonical · apport · CWE-708 | Низкая1,9 | — | 0,2 % | 10 дек. 2025 г. |
- CVE-2021-3272640В плане
Webauthn tokens not removed after user has been deleted
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nextcloud · nextcloud server12 июл. 2021 г.
- CVE-2023-400839Наблюдать
Incorrect Ownership Assignment in GitLab
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gitlab · gitlab3 авг. 2023 г.
- CVE-2026-4019632Наблюдать
HomeBox has Unauthorized API Access via Retained defaultGroup ID After Group Access Revocation
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %sysadminsmedia · homebox17 апр. 2026 г.
- CVE-2024-5256131Наблюдать
A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740).
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %parallels · parallels desktop3 июн. 2025 г.
- CVE-2022-3373730Наблюдать
The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a rand
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openvpn · openvpn access server6 июл. 2022 г.
- CVE-2024-963330Наблюдать
Incorrect Ownership Assignment in GitLab
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %gitlab · gitlab14 нояб. 2024 г.
- CVE-2023-2004429Наблюдать
A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges.
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %cisco · cx cloud agent20 янв. 2023 г.
- CVE-2024-4542626Наблюдать
Zoom Workplace Apps - Incorrect Ownership Assignment
СредняяCVSS 6,5Эксплойта нетEPSS 0 %zoom · meeting software development kit25 февр. 2025 г.
- CVE-2024-4177326Наблюдать
IBM Global Configuration Management incorrect ownership assignment
СредняяCVSS 6,5Эксплойта нетEPSS 0 %ibm · global configuration management20 авг. 2024 г.
- CVE-2025-506926Наблюдать
Incorrect Ownership Assignment in GitLab
СредняяCVSS 6,5Эксплойта нетEPSS 0 %gitlab · gitlab26 сент. 2025 г.
- CVE-2023-2004326Наблюдать
A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges.
СредняяCVSS 6,7Эксплойта нетEPSS 0 %cisco · cx cloud agent20 янв. 2023 г.
- CVE-2023-2912226Наблюдать
Incorrect file ownership of privileged service's libraries in Enel X JuiceBox
СредняяCVSS 6,7Эксплойта нетEPSS 0 %enel x · juicebox pro 3.0 22kw cellular5 нояб. 2024 г.
- CVE-2021-2624823Наблюдать
Philips MRI 1.5T and 3T Incorrect Ownership Assignment
СредняяCVSS 5,9Эксплойта нетEPSS 0 %philips · mri 3t firmware19 нояб. 2021 г.
- CVE-2024-4541722Наблюдать
Zoom Apps for macOS - Uncontrolled Resource Consumption
СредняяCVSS 5,5Эксплойта нетEPSS 0 %zoom · meeting software development kit25 февр. 2025 г.
- GHSA-wr2m-38xh-rpc922Наблюдать
Lemmy user purging users or communities or banning users can delete images they didn't upload/exclusively use
СредняяCVSS 5,5Эксплойта нетcrates.io · lemmy_server8 апр. 2025 г.
- CVE-2026-3269121Наблюдать
Timing ownership claim attack on new external back-end secrets
СредняяCVSS 5,3Эксплойта нетEPSS 0 %canonical · juju18 мар. 2026 г.
- CVE-2025-1426221Наблюдать
Jobs can be saved as workflows with wrong permissions on KNIME Business Hub
СредняяCVSS 5,3Эксплойта нетEPSS 0 %knime · business hub8 дек. 2025 г.
- CVE-2026-646915Наблюдать
PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership
НизкаяCVSS 3,8Эксплойта нетEPSS 0 %postgresql · postgresql13 авг. 2026 г.
- CVE-2025-54677Наблюдать
Ubuntu Apport Insecure File Permissions Vulnerability
НизкаяCVSS 1,9Эксплойта нетEPSS 0 %canonical · apport10 дек. 2025 г.