CWE-283 · 31 kayıt
Unverified Ownership
Bu sınıftaki CVE’ler
31 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2024-27903İstismar yok | OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitraryopenvpn · openvpn · CWE-283 | Kritik9,8 | — | %8,9 | 8 Tem 2024 |
36İzleyin | CVE-2026-26016İstismar yok | Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorizationpterodactyl · panel · CWE-283 | Kritik9,2 | — | %0,5 | 19 Şub 2026 |
33İzleyin | CVE-2026-29788İstismar yok | TSPortal: Anyone can forge self-deletion requests of any userwikitide · tsportal · CWE-283 | Yüksek8,4 | — | %0,4 | 6 Mar 2026 |
32İzleyin | CVE-2021-24501İstismar yok | Workreap theme < 2.2.2 - Missing Authorization Checks in Ajax Actionsamentotech · workreap · CWE-283 | Yüksek8,1 | — | %1,3 | 9 Ağu 2021 |
32İzleyin | CVE-2021-24500İstismar yok | Workreap theme < 2.2.2 - Multiple CSRF + IDOR Vulnerabilitiesamentotech · workreap · CWE-283 | Yüksek8,1 | — | %0,6 | 9 Ağu 2021 |
31İzleyin | CVE-2025-43882İstismar yok | Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability.dell · thinos · CWE-283 | Yüksek7,8 | — | %0,1 | 27 Ağu 2025 |
28İzleyin | CVE-2025-47940İstismar yok | TYPO3 CMS Vulnerable to Privilege Escalation to System Maintainertypo3 · typo3 · CWE-283 | Yüksek7,2 | — | %0,4 | 20 May 2025 |
28İzleyin | CVE-2026-54467İstismar yok | On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, trustedfirmware · trusted firmware-m · CWE-283 | Yüksek7,0 | — | %0,2 | 26 Ağu 2026 |
28İzleyin | CVE-2026-93853İstismar yok | Barman snapshot backup deletion trusts unverified backup catalog metadataenterprisedb · barman · CWE-283 | Yüksek7,2 | — | — | Bugün |
27İzleyin | CVE-2025-1007İstismar yok | Improper Authorization in /user/namespace/{namespace}/detailseclipse · open vsx · CWE-283 | Orta6,9 | — | %0,5 | 19 Şub 2025 |
27İzleyin | CVE-2026-44707İstismar yok | Chatwoot: Pre-Account Takeover via OAuth on Unconfirmed Accountschatwoot · chatwoot · CWE-283 | Orta6,8 | — | %0,5 | 26 May 2026 |
27İzleyin | CVE-2025-24890İstismar yok | gix-sec safe.directory protections absent for elevated administratorsgitoxidelabs · gitoxide · CWE-283 | Orta6,8 | — | %0,2 | 14 Eyl 2026 |
26İzleyin | CVE-2022-29220İstismar yok | No verification of commits origin in github-action-merge-dependabotfastify · github action merge dependabot · CWE-283 | Orta6,5 | — | %0,5 | 31 May 2022 |
26İzleyin | CVE-2026-44562İstismar yok | Open WebUI: Model Import Overwrites Any Model Without Ownership Checkopenwebui · open webui · CWE-283 | Orta6,5 | — | %0,4 | 15 May 2026 |
26İzleyin | CVE-2026-9745İstismar yok | Vulnerabilities exists in IBM Netezza Softwareibm · netezza performance server · CWE-283 | Orta6,5 | — | %0,3 | 3 Eyl 2026 |
23İzleyin | CVE-2020-8554Kavram kanıtı | Kubernetes man in the middle using LoadBalancer or ExternalIPskubernetes · kubernetes · CWE-283 | Orta5,0 | — | %9,3 | 21 Oca 2021 |
23İzleyin | CVE-2026-4269İstismar yok | Improper S3 ownership verification in Bedrock AgentCore Starter Toolkitamazon · bedrock agentcore starter toolkit · CWE-283 | Orta5,8 | — | %0,4 | 16 Mar 2026 |
22İzleyin | CVE-2025-9822İstismar yok | Secret data extraction via elfindermautic · mautic · CWE-283 | Orta5,5 | — | %0,2 | 3 Eyl 2025 |
22İzleyin | CVE-2024-1853İstismar yok | Zemana AntiLogger v2.74.204.664 - Arbitrary Process Terminationzemena · antilogger · CWE-283 | Orta5,5 | — | %0,2 | 14 Mar 2024 |
21İzleyin | CVE-2025-12815İstismar yok | An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.aws · research and engineering studio (res) · CWE-283 | Orta5,3 | — | %0,3 | 6 Kas 2025 |
20İzleyin | CVE-2026-85781İstismar yok | Unverified access point ownership in Amazon EFS CSI Driveraws · aws-efs-csi-driver · CWE-283 | Orta5,1 | — | %0,4 | 4 Eyl 2026 |
20İzleyin | CVE-2026-87912İstismar yok | Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecopsaws · aws security agent plugin · CWE-283 | Orta5,1 | — | %0,4 | 10 Eyl 2026 |
20İzleyin | CVE-2026-87913İstismar yok | Missing S3 bucket ownership verification in the AWS Security Agent MCP serveraws · aws security agent mcp server · CWE-283 | Orta5,1 | — | %0,4 | 10 Eyl 2026 |
20İzleyin | CVE-2026-40337İstismar yok | Sentry kernel has incomplete ownership check for IRQ line manipulationcamelot-os · sentry-kernel · CWE-283 | Orta5,1 | — | %0,2 | 17 Nis 2026 |
20İzleyin | CVE-2026-84386İstismar yok | A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacfortinet · forticlientwindows · CWE-283 | Orta5,1 | — | %0,1 | 8 Eyl 2026 |
- CVE-2024-2790342Planlayın
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary
KritikCVSS 9,8İstismar yokEPSS %9openvpn · openvpn8 Tem 2024
- CVE-2026-2601636İzleyin
Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization
KritikCVSS 9,2İstismar yokEPSS %0pterodactyl · panel19 Şub 2026
- CVE-2026-2978833İzleyin
TSPortal: Anyone can forge self-deletion requests of any user
YüksekCVSS 8,4İstismar yokEPSS %0wikitide · tsportal6 Mar 2026
- CVE-2021-2450132İzleyin
Workreap theme < 2.2.2 - Missing Authorization Checks in Ajax Actions
YüksekCVSS 8,1İstismar yokEPSS %1amentotech · workreap9 Ağu 2021
- CVE-2021-2450032İzleyin
Workreap theme < 2.2.2 - Multiple CSRF + IDOR Vulnerabilities
YüksekCVSS 8,1İstismar yokEPSS %1amentotech · workreap9 Ağu 2021
- CVE-2025-4388231İzleyin
Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability.
YüksekCVSS 7,8İstismar yokEPSS %0dell · thinos27 Ağu 2025
- CVE-2025-4794028İzleyin
TYPO3 CMS Vulnerable to Privilege Escalation to System Maintainer
YüksekCVSS 7,2İstismar yokEPSS %0typo3 · typo320 May 2025
- CVE-2026-5446728İzleyin
On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure,
YüksekCVSS 7,0İstismar yokEPSS %0trustedfirmware · trusted firmware-m26 Ağu 2026
- CVE-2026-9385328İzleyin
Barman snapshot backup deletion trusts unverified backup catalog metadata
YüksekCVSS 7,2İstismar yokenterprisedb · barmanBugün
- CVE-2025-100727İzleyin
Improper Authorization in /user/namespace/{namespace}/details
OrtaCVSS 6,9İstismar yokEPSS %1eclipse · open vsx19 Şub 2025
- CVE-2026-4470727İzleyin
Chatwoot: Pre-Account Takeover via OAuth on Unconfirmed Accounts
OrtaCVSS 6,8İstismar yokEPSS %0chatwoot · chatwoot26 May 2026
- CVE-2025-2489027İzleyin
gix-sec safe.directory protections absent for elevated administrators
OrtaCVSS 6,8İstismar yokEPSS %0gitoxidelabs · gitoxide14 Eyl 2026
- CVE-2022-2922026İzleyin
No verification of commits origin in github-action-merge-dependabot
OrtaCVSS 6,5İstismar yokEPSS %0fastify · github action merge dependabot31 May 2022
- CVE-2026-4456226İzleyin
Open WebUI: Model Import Overwrites Any Model Without Ownership Check
OrtaCVSS 6,5İstismar yokEPSS %0openwebui · open webui15 May 2026
- CVE-2026-974526İzleyin
Vulnerabilities exists in IBM Netezza Software
OrtaCVSS 6,5İstismar yokEPSS %0ibm · netezza performance server3 Eyl 2026
- CVE-2020-855423İzleyin
Kubernetes man in the middle using LoadBalancer or ExternalIPs
OrtaCVSS 5,0Kavram kanıtıEPSS %9kubernetes · kubernetes21 Oca 2021
- CVE-2026-426923İzleyin
Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit
OrtaCVSS 5,8İstismar yokEPSS %0amazon · bedrock agentcore starter toolkit16 Mar 2026
- CVE-2025-982222İzleyin
Secret data extraction via elfinder
OrtaCVSS 5,5İstismar yokEPSS %0mautic · mautic3 Eyl 2025
- CVE-2024-185322İzleyin
Zemana AntiLogger v2.74.204.664 - Arbitrary Process Termination
OrtaCVSS 5,5İstismar yokEPSS %0zemena · antilogger14 Mar 2024
- CVE-2025-1281521İzleyin
An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.
OrtaCVSS 5,3İstismar yokEPSS %0aws · research and engineering studio (res)6 Kas 2025
- CVE-2026-8578120İzleyin
Unverified access point ownership in Amazon EFS CSI Driver
OrtaCVSS 5,1İstismar yokEPSS %0aws · aws-efs-csi-driver4 Eyl 2026
- CVE-2026-8791220İzleyin
Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops
OrtaCVSS 5,1İstismar yokEPSS %0aws · aws security agent plugin10 Eyl 2026
- CVE-2026-8791320İzleyin
Missing S3 bucket ownership verification in the AWS Security Agent MCP server
OrtaCVSS 5,1İstismar yokEPSS %0aws · aws security agent mcp server10 Eyl 2026
- CVE-2026-4033720İzleyin
Sentry kernel has incomplete ownership check for IRQ line manipulation
OrtaCVSS 5,1İstismar yokEPSS %0camelot-os · sentry-kernel17 Nis 2026
- CVE-2026-8438620İzleyin
A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attac
OrtaCVSS 5,1İstismar yokEPSS %0fortinet · forticlientwindows8 Eyl 2026