Skip to main content

CWE archive

CWE-282 CVEs

Programmatic archive

29 CVEs tagged with CWE-2820 Critical, 11 High, 17 Medium, 1 Low, 0 Unrated.

CVE-2026-50130

Published Jul 14, 2026

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivilege…

CVSS 8.8 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-40214

Published May 7, 2026

In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NUL…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-3867

Published Apr 27, 2026

An improper ownership management vulnerability has been identified in Moxa’s Secure Router. Because of improper ownership management, a low-privileged authenticated user may acces…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-23514

Published Mar 25, 2026

Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized c…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-67642

Published Dec 10, 2025

Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the appropriate context for Vault credentials lookup, allowing attackers with Item/Configure permission…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-57732

Published Aug 20, 2025

In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-46416

Published Jun 27, 2025

The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This…

CVSS 2.9 · Low

CVE-2025-32946

Published Apr 15, 2025

This vulnerability allows any attacker to add playlists to a different user’s channel using the ActivityPub protocol. The vulnerable code sets the owner of the new playlist to be…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32945

Published Apr 15, 2025

The vulnerability allows an existing user to add playlists to a different user’s channel using the PeerTube REST API. The vulnerable code sets the owner of the new playlist to be…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27254

Published Mar 10, 2025

CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass.  The software's startup authentication can be disabled by altering a Windows…

CVSS 8.0 · High
evidence mentions
2
Buzz score
21.0

CVE-2024-47816

Published Oct 9, 2024

ImportDump is a mediawiki extension designed to automate user import requests. A user's local actor ID is stored in the database to tell who made what requests. Therefore, if a us…

CVSS 6.4 · Medium

CVE-2024-39755

Published Oct 3, 2024

A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially crafted PKG file can lead to execute priviledged operation. A…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8949

Published Sep 17, 2024

A vulnerability classified as critical has been found in SourceCodester Online Eyewear Shop 1.0. This affects an unknown part of the file /classes/Master.php of the component Cart…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45104

Published Sep 13, 2024

A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45103

Published Sep 13, 2024

A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37999

Published Jul 8, 2024

A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions). The affected application executes as a trusted account with high privileges and network acce…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3383

Published Apr 10, 2024

A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user…

CVSS 7.4 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-7226

Published Jan 11, 2024

A vulnerability was found in meetyoucrop big-whale 1.1 and classified as critical. Affected by this issue is some unknown functionality of the file /auth/user/all.api of the compo…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0989

Published Sep 29, 2023

An information disclosure issue in GitLab CE/EE affecting all versions starting from 13.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows an attacker to ex…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0386

Published Mar 22, 2023

A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a…

CVSS 7.8 · High
evidence mentions
4
Buzz score
49.1
KEV listed
Showing 1-25 of 29 CVEsPage 1 of 2