VulnSea

CWE-283

CVEs classified under CWE-283, newest first.

8 CVEsRSS

CVE-2025-24890Medium· 6.8PoC
1w ago

gitoxide is an implementation of git written in Rust

gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats repositories controlled by another user as trusted when an administrator runs a dependent program with an unfiltered e…

TwilightGitoxideLabs · gitoxideEPSS 0.15%via NVD
CVE-2026-87913Medium· 5.9
1w ago

A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state…

A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state…

SunlitAWS · AWS Security Agent MCP serverEPSS 0.25%via NVD
CVE-2026-87912Medium· 5.9
1w ago

Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops

A missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before 1.1.0 might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials a…

SunlitAWS · AWS Security Agent pluginEPSS 0.25%via CVEORG
CVE-2026-84386Medium· 5.1
2w ago

A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via <insert attack vector here>

A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via <insert attack vector here>

SunlitFortinet · FortiClientWindowsEPSS 0.10%via NVD
CVE-2026-85781High· 8.7
2w ago

Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVolume creation privileges to cause recursive deletion…

Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVolume creation privileges to cause recursive deletion…

TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.26%via NVD
CVE-2026-9745Medium· 6.5
2w ago

IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter

IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations o…

Sunlitibm · netezza_performance_serverEPSS 0.19%via NVD
CVE-2026-54467High· 7.0
3w ago

On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.

On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.

TwilightEPSS 0.15%via NVD
CVE-2026-20912Critical· 9.1
8mo ago

Gitea does not properly validate repository ownership when linking attachments to releases

Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to…

Midnightgitea · giteaEPSS 0.46%via NVD
CWE-283 vulnerabilities (CVEs) · VulnSea