CWE-279 · 25 records
Incorrect Execution-Assigned Permissions
CVEs in this class
25 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-37734No exploit | An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.open-emr · openemr · CWE-279 | Critical9.8 | — | 0.8% | Jun 26, 2024 |
37Monitor | CVE-2020-8025No exploit | outdated entries in permissions profiles for /var/lib/pcp/tmp/* may cause security issuessuse · linux enterprise high performance computing · CWE-279 | Critical9.3 | — | 0.5% | Aug 7, 2020 |
35Monitor | CVE-2023-4665No exploit | Privilage Escalation in Saphira Connectadobe · connect · CWE-279 | High8.8 | — | 1.0% | Sep 15, 2023 |
35Monitor | CVE-2025-22843No exploit | Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated usCWE-279 | High8.8 | — | 0.1% | May 13, 2025 |
34Monitor | CVE-2025-14025No exploit | Ansible-automation-platform/aap-gateway: aap-gateway: read-only personal access token (pat) bypasses write restrictionsred hat · red hat ansible automation platform 2.5 for rhel 8 · CWE-279 | High8.5 | — | 0.4% | Jan 8, 2026 |
34Monitor | CVE-2024-11220No exploit | Open Automation Software Incorrect Execution-Assigned Permissionsopenautomationsoftware · open automation software · CWE-279 | High8.5 | — | 0.2% | Dec 6, 2024 |
31Monitor | CVE-2023-4383No exploit | MicroWorld eScan Anti-Virus runasroot incorrect execution-assigned permissionsescanav · escan anti-virus · CWE-279 | High7.8 | — | 0.3% | Aug 16, 2023 |
31Monitor | CVE-2024-25621No exploit | containerd affected by a local privilege escalation via wide permissions on CRI directorylinuxfoundation · containerd · CWE-279 | High7.8 | — | 0.2% | Nov 6, 2025 |
30Monitor | CVE-2025-23263No exploit | NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause escalation of privilegnvidia · doca-host and mellanox ofed · CWE-279 | High7.6 | — | 0.2% | Jul 17, 2025 |
29Monitor | CVE-2025-30001No exploit | Apache StreamPark: Authenticated users can trigger remote command executionapache · streampark · CWE-279 | High7.3 | — | 0.6% | Oct 10, 2025 |
28Monitor | CVE-2023-3915No exploit | Incorrect Execution-Assigned Permissions in GitLabgitlab · gitlab · CWE-279 | High7.2 | — | 0.7% | Sep 1, 2023 |
28Monitor | CVE-2026-20062No exploit | A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in multiple context mode could allow an authecisco · cisco secure firewall adaptive security appliance (asa) software · CWE-279 | High7.2 | — | 0.1% | Mar 4, 2026 |
26Monitor | CVE-2023-50914No exploit | A Privilege Escalation issue in the inter-process communication procedure from GOG Galaxy (Beta) 2.0.67.2 through v2.0.71.2 allows authenticCWE-279 | Medium6.7 | — | 0.7% | Apr 30, 2024 |
26Monitor | CVE-2025-12801No exploit | Nfs-utils: rpc.mountd in the nfs-utils privilege escalationredhat · openshift container platform · CWE-279 | Medium6.5 | — | 0.5% | Mar 4, 2026 |
22Monitor | CVE-2026-4948No exploit | Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorizationfirewalld · firewalld · CWE-279 | Medium5.5 | — | 0.2% | Mar 27, 2026 |
21Monitor | CVE-2024-37025No exploit | Incorrect execution-assigned permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installer before version 23.1.1 mCWE-279 | Medium5.4 | — | 0.2% | Nov 13, 2024 |
21Monitor | CVE-2025-13663No exploit | Quartus Prime Pro Edition Installer Advisoryintel · quartus prime · CWE-279 | Medium5.4 | — | 0.1% | Dec 11, 2025 |
20Monitor | CVE-2025-20612No exploit | Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated usCWE-279 | Medium5.1 | — | 0.2% | May 13, 2025 |
20Monitor | CVE-2025-23233No exploit | Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated usCWE-279 | Medium5.1 | — | 0.2% | May 13, 2025 |
17Monitor | CVE-2017-8441No exploit | Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases.elastic · x-pack · CWE-279 | Medium4.3 | — | 0.7% | Jun 5, 2017 |
17Monitor | CVE-2026-46388No exploit | osquery: Unprivileged users can temporarily read file carve contentsosquery · osquery · CWE-279 | Medium4.4 | — | 0.1% | Jul 10, 2026 |
16Monitor | CVE-2025-26422No exploit | In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permissiongoogle · android · CWE-279 | Medium4.0 | — | 0.1% | Sep 4, 2025 |
15Monitor | CVE-2025-36228No exploit | Incorrect Execution-Assigned Permissions in IBM Aspera Faspexibm · aspera faspex · CWE-279 | Low3.8 | — | 0.2% | Dec 26, 2025 |
8Monitor | CVE-2024-39286No exploit | Incorrect execution-assigned permissions in the Linux kernel mode driver for the Intel(R) 800 Series Ethernet Driver before version 1.15.4 mCWE-279 | Low2.0 | — | 0.2% | Feb 12, 2025 |
8Monitor | GHSA-qc59-cxj2-c2w4No exploit | aws-cdk-lib's aspect order change causes different Permissions Boundary assigned to Rolenpm · aws-cdk-lib · CWE-279 | Low2.2 | — | — | Apr 15, 2025 |
- CVE-2024-3773439Monitor
An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.
CriticalCVSS 9.8No exploitEPSS 1%open-emr · openemrJun 26, 2024
- CVE-2020-802537Monitor
outdated entries in permissions profiles for /var/lib/pcp/tmp/* may cause security issues
CriticalCVSS 9.3No exploitEPSS 0%suse · linux enterprise high performance computingAug 7, 2020
- CVE-2023-466535Monitor
Privilage Escalation in Saphira Connect
HighCVSS 8.8No exploitEPSS 1%adobe · connectSep 15, 2023
- CVE-2025-2284335Monitor
Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated us
HighCVSS 8.8No exploitEPSS 0%May 13, 2025
- CVE-2025-1402534Monitor
Ansible-automation-platform/aap-gateway: aap-gateway: read-only personal access token (pat) bypasses write restrictions
HighCVSS 8.5No exploitEPSS 0%red hat · red hat ansible automation platform 2.5 for rhel 8Jan 8, 2026
- CVE-2024-1122034Monitor
Open Automation Software Incorrect Execution-Assigned Permissions
HighCVSS 8.5No exploitEPSS 0%openautomationsoftware · open automation softwareDec 6, 2024
- CVE-2023-438331Monitor
MicroWorld eScan Anti-Virus runasroot incorrect execution-assigned permissions
HighCVSS 7.8No exploitEPSS 0%escanav · escan anti-virusAug 16, 2023
- CVE-2024-2562131Monitor
containerd affected by a local privilege escalation via wide permissions on CRI directory
HighCVSS 7.8No exploitEPSS 0%linuxfoundation · containerdNov 6, 2025
- CVE-2025-2326330Monitor
NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause escalation of privileg
HighCVSS 7.6No exploitEPSS 0%nvidia · doca-host and mellanox ofedJul 17, 2025
- CVE-2025-3000129Monitor
Apache StreamPark: Authenticated users can trigger remote command execution
HighCVSS 7.3No exploitEPSS 1%apache · streamparkOct 10, 2025
- CVE-2023-391528Monitor
Incorrect Execution-Assigned Permissions in GitLab
HighCVSS 7.2No exploitEPSS 1%gitlab · gitlabSep 1, 2023
- CVE-2026-2006228Monitor
A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in multiple context mode could allow an authe
HighCVSS 7.2No exploitEPSS 0%cisco · cisco secure firewall adaptive security appliance (asa) softwareMar 4, 2026
- CVE-2023-5091426Monitor
A Privilege Escalation issue in the inter-process communication procedure from GOG Galaxy (Beta) 2.0.67.2 through v2.0.71.2 allows authentic
MediumCVSS 6.7No exploitEPSS 1%Apr 30, 2024
- CVE-2025-1280126Monitor
Nfs-utils: rpc.mountd in the nfs-utils privilege escalation
MediumCVSS 6.5No exploitEPSS 0%redhat · openshift container platformMar 4, 2026
- CVE-2026-494822Monitor
Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization
MediumCVSS 5.5No exploitEPSS 0%firewalld · firewalldMar 27, 2026
- CVE-2024-3702521Monitor
Incorrect execution-assigned permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installer before version 23.1.1 m
MediumCVSS 5.4No exploitEPSS 0%Nov 13, 2024
- CVE-2025-1366321Monitor
Quartus Prime Pro Edition Installer Advisory
MediumCVSS 5.4No exploitEPSS 0%intel · quartus primeDec 11, 2025
- CVE-2025-2061220Monitor
Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated us
MediumCVSS 5.1No exploitEPSS 0%May 13, 2025
- CVE-2025-2323320Monitor
Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated us
MediumCVSS 5.1No exploitEPSS 0%May 13, 2025
- CVE-2017-844117Monitor
Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases.
MediumCVSS 4.3No exploitEPSS 1%elastic · x-packJun 5, 2017
- CVE-2026-4638817Monitor
osquery: Unprivileged users can temporarily read file carve contents
MediumCVSS 4.4No exploitEPSS 0%osquery · osqueryJul 10, 2026
- CVE-2025-2642216Monitor
In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permission
MediumCVSS 4.0No exploitEPSS 0%google · androidSep 4, 2025
- CVE-2025-3622815Monitor
Incorrect Execution-Assigned Permissions in IBM Aspera Faspex
LowCVSS 3.8No exploitEPSS 0%ibm · aspera faspexDec 26, 2025
- CVE-2024-392868Monitor
Incorrect execution-assigned permissions in the Linux kernel mode driver for the Intel(R) 800 Series Ethernet Driver before version 1.15.4 m
LowCVSS 2.0No exploitEPSS 0%Feb 12, 2025
- GHSA-qc59-cxj2-c2w48Monitor
aws-cdk-lib's aspect order change causes different Permissions Boundary assigned to Role
LowCVSS 2.2No exploitnpm · aws-cdk-libApr 15, 2025