İçeriğe atla
Noroxi

CWE-280 · 190 kayıt

Improper Handling of Insufficient Permissions or Privileges

Bu sınıftaki CVE’ler

190 kayıt

  • CVE-2024-24116
    48Planlayın

    An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.

    KritikCVSS 9,8Kavram kanıtıEPSS %28

    ruijie · rg-nbs2009g-p firmware2 Eki 2024

  • CVE-2025-6573
    39İzleyin

    GPU DDK - RGXFW_CTL.pui8FWScratchBuf Leak/Overwrite

    KritikCVSS 9,8İstismar yokEPSS %0

    imagination technologies · graphics ddk8 Ağu 2025

  • CVE-2025-46066
    39İzleyin

    An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges

    KritikCVSS 9,9İstismar yokEPSS %0

    automai · director12 Oca 2026

  • CVE-2026-41566
    37İzleyin

    Apache Kvrocks: Improper permission for the APPLYBATCH command

    KritikCVSS 9,4İstismar yokEPSS %0

    apache software foundation · apache kvrocks25 Haz 2026

  • CVE-2024-46874
    36İzleyin

    Ruijie Reyee OS Improper Handling of Insufficient Permissions or Privileges

    KritikCVSS 9,2İstismar yokEPSS %0

    ruijienetworks · reyee os6 Ara 2024

  • CVE-2019-6570
    35İzleyin

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0).

    YüksekCVSS 8,8İstismar yokEPSS %1

    siemens · sinema remote connect server17 Nis 2019

  • CVE-2022-2193
    35İzleyin

    Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 aut

    YüksekCVSS 8,8İstismar yokEPSS %1

    hypr · hypr server19 Tem 2022

  • CVE-2025-29826
    35İzleyin

    Microsoft Dataverse Elevation of Privilege Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %1

    microsoft · dataverse13 May 2025

  • CVE-2026-40371
    35İzleyin

    Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %1

    microsoft · dynamics 3659 Haz 2026

  • CVE-2024-25108
    35İzleyin

    Insufficient authorization allowing elevated access to resources in pixelfed

    YüksekCVSS 8,8İstismar yokEPSS %1

    pixelfed · pixelfed12 Şub 2024

  • CVE-2025-27025
    35İzleyin

    Improper File Access in Infinera G42

    YüksekCVSS 8,8İstismar yokEPSS %1

    infinera · g422 Tem 2025

  • CVE-2024-22078
    35İzleyin

    An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before.

    YüksekCVSS 8,8İstismar yokEPSS %1

    elspec-ltd · g5dfr firmware20 Mar 2024

  • CVE-2024-6660
    35İzleyin

    BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Option

    YüksekCVSS 8,8İstismar yokEPSS %1

    reputeinfosystems · bookingpress17 Tem 2024

  • CVE-2024-36451
    35İzleyin

    Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003.

    YüksekCVSS 8,8İstismar yokEPSS %1

    webmin · webmin10 Tem 2024

  • CVE-2025-8109
    35İzleyin

    GPU DDK - GPU shader shared memory corrupted using ptrace to disrupt GPU operation

    YüksekCVSS 8,8İstismar yokEPSS %0

    imagination technologies · graphics ddk4 Ağu 2025

  • CVE-2025-22256
    35İzleyin

    A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1

    YüksekCVSS 8,8İstismar yokEPSS %0

    fortinet · fortipam10 Haz 2025

  • CVE-2026-59567
    35İzleyin

    Local privilege escalation

    YüksekCVSS 8,8İstismar yokEPSS %0

    zscaler · client connector24 Ağu 2026

  • CVE-2026-18860
    34İzleyin

    Velociraptor incorrect Org deletion permissions check

    YüksekCVSS 8,7İstismar yokEPSS %0

    rapid7 · velociraptor11 Ağu 2026

  • CVE-2026-2123
    34İzleyin

    Privilege escalation vulnerability in Operations Agent

    YüksekCVSS 8,6İstismar yokEPSS %0

    microfocus · operations agent31 Mar 2026

  • CVE-2026-20817
    33İzleyin

    Windows Error Reporting Service Elevation of Privilege Vulnerability

    YüksekCVSS 7,8Kavram kanıtıEPSS %6

    microsoft · windows 10 21h213 Oca 2026

  • CVE-2026-0047
    33İzleyin

    In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due to a missing permis

    YüksekCVSS 8,4Kavram kanıtıEPSS %0

    google · android2 Mar 2026

  • CVE-2020-29031
    32İzleyin

    Insecure Direct Object Reference in GateManager WebUI can cause privilege escalation

    YüksekCVSS 8,1İstismar yokEPSS %1

    secomea · gatemanager 8250 firmware15 Şub 2021

  • CVE-2025-67848
    32İzleyin

    Moodle: moodle: authentication bypass via lti provider allows suspended users to gain unauthorized access.

    YüksekCVSS 8,1İstismar yokEPSS %0

    moodle · moodle3 Şub 2026

  • CVE-2024-43702
    32İzleyin

    GPU DDK - MLIST/PM render state buffers writable allowing arbitrary writes to kernel memory pages

    YüksekCVSS 8,1İstismar yokEPSS %0

    imagination technologies · graphics ddk29 Kas 2024

  • CVE-2025-62509
    32İzleyin

    FileRise improper ownership/permission validation allowed cross-tenant file operations

    YüksekCVSS 8,1İstismar yokEPSS %0

    filerise · filerise20 Eki 2025

Tüm zafiyet sınıfları