CWE-282 · 30 kayıt
Improper Ownership Management
Bu sınıftaki CVE’ler
30 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
63Bu hafta | CVE-2023-0386Silahlaştırılmış | A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linuxlinux · linux kernel · CWE-282 | Yüksek7,8 | KEV | %7,9 | 22 Mar 2023 |
36İzleyin | CVE-2024-3383İstismar yok | PAN-OS: Improper Group Membership Change Vulnerability in Cloud Identity Engine (CIE)paloaltonetworks · pan-os · CWE-282 | Kritik9,1 | — | %0,6 | 10 Nis 2024 |
35İzleyin | CVE-2026-50130İstismar yok | Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`pi-hole · pi-hole · CWE-282 | Yüksek8,8 | — | %0,3 | 14 Tem 2026 |
34İzleyin | CVE-2024-37999İstismar yok | A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions).siemens · medicalis workflow orchestrator · CWE-282 | Yüksek8,5 | — | %0,1 | 8 Tem 2024 |
32İzleyin | CVE-2025-27254İstismar yok | CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass.ge vernova · enervista ur setup · CWE-282 | Yüksek8,0 | — | %0,2 | 10 Mar 2025 |
31İzleyin | CVE-2022-29187İstismar yok | Bypass of safe.directory protections in Gitgit-scm · git · CWE-282 | Yüksek7,8 | — | %0,4 | 12 Tem 2022 |
31İzleyin | CVE-2024-39755İstismar yok | A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0.veertu · anka build cloud · CWE-282 | Yüksek7,8 | — | %0,4 | 3 Eki 2024 |
31İzleyin | CVE-2017-12189İstismar yok | It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handlinredhat · jboss enterprise application platform · CWE-282 | Yüksek7,8 | — | %0,3 | 10 Oca 2018 |
26İzleyin | CVE-2026-23514İstismar yok | Kiteworks Core before 9.2.2 is vulnerable to Improper Ownership Managementaccellion · kiteworks · CWE-282 | Orta6,5 | — | %1,0 | 25 Mar 2026 |
26İzleyin | CVE-2023-7226İstismar yok | meetyoucrop big-whale Admin Module all.api improper ownership managementmeiyou · big whale · CWE-282 | Orta6,5 | — | %0,4 | 11 Oca 2024 |
26İzleyin | CVE-2022-0026İstismar yok | Cortex XDR Agent: Unintended Program Execution Leads to Local Privilege Escalation (PE) Vulnerabilitypaloaltonetworks · cortex xdr agent · CWE-282 | Orta6,7 | — | %0,2 | 11 May 2022 |
26İzleyin | CVE-2024-45104İstismar yok | A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device thrlenovo · xclarity administrator · CWE-282 | Orta6,5 | — | %0,2 | 13 Eyl 2024 |
25İzleyin | CVE-2024-47816İstismar yok | Users can impersonate import requesters if their actor IDs coincide in ImportDumpmiraheze · importdump · CWE-282 | Orta6,4 | — | %0,3 | 9 Eki 2024 |
25İzleyin | CVE-2026-40214İstismar yok | In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer.openstack · cyborg · CWE-282 | Orta6,3 | — | %0,3 | 7 May 2026 |
25İzleyin | CVE-2025-57732İstismar yok | In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownershipjetbrains · teamcity · CWE-282 | Orta6,3 | — | %0,1 | 20 Ağu 2025 |
24İzleyin | CVE-2026-3867İstismar yok | An improper ownership management vulnerability has been identified in Moxa’s Secure Router.moxa · edr-8010 series · CWE-282 | Orta6,0 | — | %0,4 | 27 Nis 2026 |
22İzleyin | CVE-2023-0989İstismar yok | Improper Ownership Management in GitLabgitlab · gitlab · CWE-282 | Orta5,7 | — | %0,5 | 29 Eyl 2023 |
21İzleyin | CVE-2024-8949Kavram kanıtı | SourceCodester Online Eyewear Shop Cart Content Master.php improper ownership managementoretnom23 · online eyewear shop · CWE-282 | Orta5,3 | — | %0,7 | 17 Eyl 2024 |
21İzleyin | CVE-2020-10632İstismar yok | ICSA-20-140-02 Emerson OpenEnterpriseemerson · openenterprise scada server · CWE-282 | Orta5,3 | — | %0,5 | 24 Şub 2022 |
21İzleyin | CVE-2025-32946İstismar yok | PeerTube Arbitrary Playlist Creation via ActivityPub Protocolframasoft · peertube · CWE-282 | Orta5,3 | — | %0,4 | 15 Nis 2025 |
21İzleyin | CVE-2024-43176İstismar yok | IBM OpenPages information disclosureibm · openpages with watson · CWE-282 | Orta5,4 | — | %0,3 | 9 Oca 2025 |
21İzleyin | CVE-2026-86769İstismar yok | Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkoutsnipeitapp · snipe-it · CWE-282 | Orta5,3 | — | %0,3 | 9 Eyl 2026 |
21İzleyin | CVE-2024-13246İstismar yok | Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-010node access rebuild progressive project · node access rebuild progressive · CWE-282 | Orta5,3 | — | %0,3 | 9 Oca 2025 |
21İzleyin | CVE-2024-13249İstismar yok | Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-013node access rebuild progressive project · node access rebuild progressive · CWE-282 | Orta5,4 | — | %0,2 | 9 Oca 2025 |
17İzleyin | CVE-2024-45103İstismar yok | A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privilelenovo · xclarity administrator · CWE-282 | Orta4,3 | — | %0,3 | 13 Eyl 2024 |
- CVE-2023-038663Bu hafta
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %8linux · linux kernel22 Mar 2023
- CVE-2024-338336İzleyin
PAN-OS: Improper Group Membership Change Vulnerability in Cloud Identity Engine (CIE)
KritikCVSS 9,1İstismar yokEPSS %1paloaltonetworks · pan-os10 Nis 2024
- CVE-2026-5013035İzleyin
Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`
YüksekCVSS 8,8İstismar yokEPSS %0pi-hole · pi-hole14 Tem 2026
- CVE-2024-3799934İzleyin
A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions).
YüksekCVSS 8,5İstismar yokEPSS %0siemens · medicalis workflow orchestrator8 Tem 2024
- CVE-2025-2725432İzleyin
CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass.
YüksekCVSS 8,0İstismar yokEPSS %0ge vernova · enervista ur setup10 Mar 2025
- CVE-2022-2918731İzleyin
Bypass of safe.directory protections in Git
YüksekCVSS 7,8İstismar yokEPSS %0git-scm · git12 Tem 2022
- CVE-2024-3975531İzleyin
A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0.
YüksekCVSS 7,8İstismar yokEPSS %0veertu · anka build cloud3 Eki 2024
- CVE-2017-1218931İzleyin
It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handlin
YüksekCVSS 7,8İstismar yokEPSS %0redhat · jboss enterprise application platform10 Oca 2018
- CVE-2026-2351426İzleyin
Kiteworks Core before 9.2.2 is vulnerable to Improper Ownership Management
OrtaCVSS 6,5İstismar yokEPSS %1accellion · kiteworks25 Mar 2026
- CVE-2023-722626İzleyin
meetyoucrop big-whale Admin Module all.api improper ownership management
OrtaCVSS 6,5İstismar yokEPSS %0meiyou · big whale11 Oca 2024
- CVE-2022-002626İzleyin
Cortex XDR Agent: Unintended Program Execution Leads to Local Privilege Escalation (PE) Vulnerability
OrtaCVSS 6,7İstismar yokEPSS %0paloaltonetworks · cortex xdr agent11 May 2022
- CVE-2024-4510426İzleyin
A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device thr
OrtaCVSS 6,5İstismar yokEPSS %0lenovo · xclarity administrator13 Eyl 2024
- CVE-2024-4781625İzleyin
Users can impersonate import requesters if their actor IDs coincide in ImportDump
OrtaCVSS 6,4İstismar yokEPSS %0miraheze · importdump9 Eki 2024
- CVE-2026-4021425İzleyin
In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer.
OrtaCVSS 6,3İstismar yokEPSS %0openstack · cyborg7 May 2026
- CVE-2025-5773225İzleyin
In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership
OrtaCVSS 6,3İstismar yokEPSS %0jetbrains · teamcity20 Ağu 2025
- CVE-2026-386724İzleyin
An improper ownership management vulnerability has been identified in Moxa’s Secure Router.
OrtaCVSS 6,0İstismar yokEPSS %0moxa · edr-8010 series27 Nis 2026
- CVE-2023-098922İzleyin
Improper Ownership Management in GitLab
OrtaCVSS 5,7İstismar yokEPSS %1gitlab · gitlab29 Eyl 2023
- CVE-2024-894921İzleyin
SourceCodester Online Eyewear Shop Cart Content Master.php improper ownership management
OrtaCVSS 5,3Kavram kanıtıEPSS %1oretnom23 · online eyewear shop17 Eyl 2024
- CVE-2020-1063221İzleyin
ICSA-20-140-02 Emerson OpenEnterprise
OrtaCVSS 5,3İstismar yokEPSS %0emerson · openenterprise scada server24 Şub 2022
- CVE-2025-3294621İzleyin
PeerTube Arbitrary Playlist Creation via ActivityPub Protocol
OrtaCVSS 5,3İstismar yokEPSS %0framasoft · peertube15 Nis 2025
- CVE-2024-4317621İzleyin
IBM OpenPages information disclosure
OrtaCVSS 5,4İstismar yokEPSS %0ibm · openpages with watson9 Oca 2025
- CVE-2026-8676921İzleyin
Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout
OrtaCVSS 5,3İstismar yokEPSS %0snipeitapp · snipe-it9 Eyl 2026
- CVE-2024-1324621İzleyin
Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-010
OrtaCVSS 5,3İstismar yokEPSS %0node access rebuild progressive project · node access rebuild progressive9 Oca 2025
- CVE-2024-1324921İzleyin
Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-013
OrtaCVSS 5,4İstismar yokEPSS %0node access rebuild progressive project · node access rebuild progressive9 Oca 2025
- CVE-2024-4510317İzleyin
A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privile
OrtaCVSS 4,3İstismar yokEPSS %0lenovo · xclarity administrator13 Eyl 2024