Skip to main content

CWE archive

CWE-708 CVEs

Programmatic archive

20 CVEs tagged with CWE-7080 Critical, 6 High, 10 Medium, 4 Low, 0 Unrated.

CVE-2026-40196

Published Apr 17, 2026

HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned to a user after being…

CVSS 8.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-32691

Published Mar 18, 2026

A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit agent to claim ownership of a newly initialized secret. Bet…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-5467

Published Dec 10, 2025

It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash inf…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-14262

Published Dec 8, 2025

A wrong permission check in KNIME Business Hub before version 1.17.0 allowed an authenticated user to save jobs of other users as if there were saved by the job owner. The attacke…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-5069

Published Sep 26, 2025

An issue has been discovered in GitLab CE/EE affecting all versions from 17.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated u…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-52561

Published Jun 3, 2025

A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is delete…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9633

Published Nov 14, 2024

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.3 before 17.4.2, all versions starting from 17.5 before 17.5.4, all versions starting from 17.…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-29122

Published Nov 5, 2024

Under certain conditions, access to service libraries is granted to account they should not have access to.

CVSS 6.7 · Medium

CVE-2023-41881

Published Oct 11, 2023

vantage6 is privacy preserving federated learning infrastructure. When a collaboration is deleted, the linked resources (such as tasks from that collaboration) should be deleted.…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-4008

Published Aug 3, 2023

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-20044

Published Jan 20, 2023

A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. This vulnerability is due to insecure file permissions. An…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-20043

Published Jan 20, 2023

A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. This vulnerability is due to insecure file permissions. An…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-33737

Published Jul 6, 2022

The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random generated admin password

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32726

Published Jul 12, 2021

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted after a user has been deleted…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32689

Published Jul 12, 2021

Nextcloud Talk is a fully on-premises audio/video and chat communication service. In versions prior to 11.2.2, if a user was able to reuse an earlier used username, they could get…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1