İçeriğe atla
Noroxi

CWE-282 · 30 kayıt

Improper Ownership Management

Bu sınıftaki CVE’ler

30 kayıt

  • CVE-2023-0386
    63Bu hafta

    A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %8

    linux · linux kernel22 Mar 2023

  • CVE-2024-3383
    36İzleyin

    PAN-OS: Improper Group Membership Change Vulnerability in Cloud Identity Engine (CIE)

    KritikCVSS 9,1İstismar yokEPSS %1

    paloaltonetworks · pan-os10 Nis 2024

  • CVE-2026-50130
    35İzleyin

    Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`

    YüksekCVSS 8,8İstismar yokEPSS %0

    pi-hole · pi-hole14 Tem 2026

  • CVE-2024-37999
    34İzleyin

    A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions).

    YüksekCVSS 8,5İstismar yokEPSS %0

    siemens · medicalis workflow orchestrator8 Tem 2024

  • CVE-2025-27254
    32İzleyin

    CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass.

    YüksekCVSS 8,0İstismar yokEPSS %0

    ge vernova · enervista ur setup10 Mar 2025

  • CVE-2022-29187
    31İzleyin

    Bypass of safe.directory protections in Git

    YüksekCVSS 7,8İstismar yokEPSS %0

    git-scm · git12 Tem 2022

  • CVE-2024-39755
    31İzleyin

    A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0.

    YüksekCVSS 7,8İstismar yokEPSS %0

    veertu · anka build cloud3 Eki 2024

  • CVE-2017-12189
    31İzleyin

    It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handlin

    YüksekCVSS 7,8İstismar yokEPSS %0

    redhat · jboss enterprise application platform10 Oca 2018

  • CVE-2026-23514
    26İzleyin

    Kiteworks Core before 9.2.2 is vulnerable to Improper Ownership Management

    OrtaCVSS 6,5İstismar yokEPSS %1

    accellion · kiteworks25 Mar 2026

  • CVE-2023-7226
    26İzleyin

    meetyoucrop big-whale Admin Module all.api improper ownership management

    OrtaCVSS 6,5İstismar yokEPSS %0

    meiyou · big whale11 Oca 2024

  • CVE-2022-0026
    26İzleyin

    Cortex XDR Agent: Unintended Program Execution Leads to Local Privilege Escalation (PE) Vulnerability

    OrtaCVSS 6,7İstismar yokEPSS %0

    paloaltonetworks · cortex xdr agent11 May 2022

  • CVE-2024-45104
    26İzleyin

    A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device thr

    OrtaCVSS 6,5İstismar yokEPSS %0

    lenovo · xclarity administrator13 Eyl 2024

  • CVE-2024-47816
    25İzleyin

    Users can impersonate import requesters if their actor IDs coincide in ImportDump

    OrtaCVSS 6,4İstismar yokEPSS %0

    miraheze · importdump9 Eki 2024

  • CVE-2026-40214
    25İzleyin

    In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer.

    OrtaCVSS 6,3İstismar yokEPSS %0

    openstack · cyborg7 May 2026

  • CVE-2025-57732
    25İzleyin

    In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership

    OrtaCVSS 6,3İstismar yokEPSS %0

    jetbrains · teamcity20 Ağu 2025

  • CVE-2026-3867
    24İzleyin

    An improper ownership management vulnerability has been identified in Moxa’s Secure Router.

    OrtaCVSS 6,0İstismar yokEPSS %0

    moxa · edr-8010 series27 Nis 2026

  • CVE-2023-0989
    22İzleyin

    Improper Ownership Management in GitLab

    OrtaCVSS 5,7İstismar yokEPSS %1

    gitlab · gitlab29 Eyl 2023

  • CVE-2024-8949
    21İzleyin

    SourceCodester Online Eyewear Shop Cart Content Master.php improper ownership management

    OrtaCVSS 5,3Kavram kanıtıEPSS %1

    oretnom23 · online eyewear shop17 Eyl 2024

  • CVE-2020-10632
    21İzleyin

    ICSA-20-140-02 Emerson OpenEnterprise

    OrtaCVSS 5,3İstismar yokEPSS %0

    emerson · openenterprise scada server24 Şub 2022

  • CVE-2025-32946
    21İzleyin

    PeerTube Arbitrary Playlist Creation via ActivityPub Protocol

    OrtaCVSS 5,3İstismar yokEPSS %0

    framasoft · peertube15 Nis 2025

  • CVE-2024-43176
    21İzleyin

    IBM OpenPages information disclosure

    OrtaCVSS 5,4İstismar yokEPSS %0

    ibm · openpages with watson9 Oca 2025

  • CVE-2026-86769
    21İzleyin

    Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout

    OrtaCVSS 5,3İstismar yokEPSS %0

    snipeitapp · snipe-it9 Eyl 2026

  • CVE-2024-13246
    21İzleyin

    Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-010

    OrtaCVSS 5,3İstismar yokEPSS %0

    node access rebuild progressive project · node access rebuild progressive9 Oca 2025

  • CVE-2024-13249
    21İzleyin

    Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-013

    OrtaCVSS 5,4İstismar yokEPSS %0

    node access rebuild progressive project · node access rebuild progressive9 Oca 2025

  • CVE-2024-45103
    17İzleyin

    A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privile

    OrtaCVSS 4,3İstismar yokEPSS %0

    lenovo · xclarity administrator13 Eyl 2024

Tüm zafiyet sınıfları