CWE-280 · 190 kayıt
Improper Handling of Insufficient Permissions or Privileges
Bu sınıftaki CVE’ler
190 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
48Planlayın | CVE-2024-24116Kavram kanıtı | An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.ruijie · rg-nbs2009g-p firmware · CWE-280 | Kritik9,8 | — | %28,4 | 2 Eki 2024 |
39İzleyin | CVE-2025-6573İstismar yok | GPU DDK - RGXFW_CTL.pui8FWScratchBuf Leak/Overwriteimagination technologies · graphics ddk · CWE-280 | Kritik9,8 | — | %0,4 | 8 Ağu 2025 |
39İzleyin | CVE-2025-46066İstismar yok | An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privilegesautomai · director · CWE-280 | Kritik9,9 | — | %0,3 | 12 Oca 2026 |
37İzleyin | CVE-2026-41566İstismar yok | Apache Kvrocks: Improper permission for the APPLYBATCH commandapache software foundation · apache kvrocks · CWE-280 | Kritik9,4 | — | %0,4 | 25 Haz 2026 |
36İzleyin | CVE-2024-46874İstismar yok | Ruijie Reyee OS Improper Handling of Insufficient Permissions or Privilegesruijienetworks · reyee os · CWE-280 | Kritik9,2 | — | %0,4 | 6 Ara 2024 |
35İzleyin | CVE-2019-6570İstismar yok | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0).siemens · sinema remote connect server · CWE-280 | Yüksek8,8 | — | %1,3 | 17 Nis 2019 |
35İzleyin | CVE-2022-2193İstismar yok | Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 authypr · hypr server · CWE-280 | Yüksek8,8 | — | %0,9 | 19 Tem 2022 |
35İzleyin | CVE-2025-29826İstismar yok | Microsoft Dataverse Elevation of Privilege Vulnerabilitymicrosoft · dataverse · CWE-280 | Yüksek8,8 | — | %0,8 | 13 May 2025 |
35İzleyin | CVE-2026-40371İstismar yok | Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerabilitymicrosoft · dynamics 365 · CWE-280 | Yüksek8,8 | — | %0,8 | 9 Haz 2026 |
35İzleyin | CVE-2024-25108İstismar yok | Insufficient authorization allowing elevated access to resources in pixelfedpixelfed · pixelfed · CWE-280 | Yüksek8,8 | — | %0,7 | 12 Şub 2024 |
35İzleyin | CVE-2025-27025İstismar yok | Improper File Access in Infinera G42infinera · g42 · CWE-280 | Yüksek8,8 | — | %0,7 | 2 Tem 2025 |
35İzleyin | CVE-2024-22078İstismar yok | An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before.elspec-ltd · g5dfr firmware · CWE-280 | Yüksek8,8 | — | %0,6 | 20 Mar 2024 |
35İzleyin | CVE-2024-6660İstismar yok | BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Optionreputeinfosystems · bookingpress · CWE-280 | Yüksek8,8 | — | %0,6 | 17 Tem 2024 |
35İzleyin | CVE-2024-36451İstismar yok | Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003.webmin · webmin · CWE-280 | Yüksek8,8 | — | %0,6 | 10 Tem 2024 |
35İzleyin | CVE-2025-8109İstismar yok | GPU DDK - GPU shader shared memory corrupted using ptrace to disrupt GPU operationimagination technologies · graphics ddk · CWE-280 | Yüksek8,8 | — | %0,4 | 4 Ağu 2025 |
35İzleyin | CVE-2025-22256İstismar yok | A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1fortinet · fortipam · CWE-280 | Yüksek8,8 | — | %0,4 | 10 Haz 2025 |
35İzleyin | CVE-2026-59567İstismar yok | Local privilege escalationzscaler · client connector · CWE-280 | Yüksek8,8 | — | %0,1 | 24 Ağu 2026 |
34İzleyin | CVE-2026-18860İstismar yok | Velociraptor incorrect Org deletion permissions checkrapid7 · velociraptor · CWE-280 | Yüksek8,7 | — | %0,4 | 11 Ağu 2026 |
34İzleyin | CVE-2026-2123İstismar yok | Privilege escalation vulnerability in Operations Agentmicrofocus · operations agent · CWE-280 | Yüksek8,6 | — | %0,1 | 31 Mar 2026 |
33İzleyin | CVE-2026-20817Kavram kanıtı | Windows Error Reporting Service Elevation of Privilege Vulnerabilitymicrosoft · windows 10 21h2 · CWE-280 | Yüksek7,8 | — | %5,5 | 13 Oca 2026 |
33İzleyin | CVE-2026-0047Kavram kanıtı | In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due to a missing permisgoogle · android · CWE-280 | Yüksek8,4 | — | %0,1 | 2 Mar 2026 |
32İzleyin | CVE-2020-29031İstismar yok | Insecure Direct Object Reference in GateManager WebUI can cause privilege escalationsecomea · gatemanager 8250 firmware · CWE-280 | Yüksek8,1 | — | %0,7 | 15 Şub 2021 |
32İzleyin | CVE-2025-67848İstismar yok | Moodle: moodle: authentication bypass via lti provider allows suspended users to gain unauthorized access.moodle · moodle · CWE-280 | Yüksek8,1 | — | %0,4 | 3 Şub 2026 |
32İzleyin | CVE-2024-43702İstismar yok | GPU DDK - MLIST/PM render state buffers writable allowing arbitrary writes to kernel memory pagesimagination technologies · graphics ddk · CWE-280 | Yüksek8,1 | — | %0,3 | 29 Kas 2024 |
32İzleyin | CVE-2025-62509İstismar yok | FileRise improper ownership/permission validation allowed cross-tenant file operationsfilerise · filerise · CWE-280 | Yüksek8,1 | — | %0,3 | 20 Eki 2025 |
- CVE-2024-2411648Planlayın
An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.
KritikCVSS 9,8Kavram kanıtıEPSS %28ruijie · rg-nbs2009g-p firmware2 Eki 2024
- CVE-2025-657339İzleyin
GPU DDK - RGXFW_CTL.pui8FWScratchBuf Leak/Overwrite
KritikCVSS 9,8İstismar yokEPSS %0imagination technologies · graphics ddk8 Ağu 2025
- CVE-2025-4606639İzleyin
An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges
KritikCVSS 9,9İstismar yokEPSS %0automai · director12 Oca 2026
- CVE-2026-4156637İzleyin
Apache Kvrocks: Improper permission for the APPLYBATCH command
KritikCVSS 9,4İstismar yokEPSS %0apache software foundation · apache kvrocks25 Haz 2026
- CVE-2024-4687436İzleyin
Ruijie Reyee OS Improper Handling of Insufficient Permissions or Privileges
KritikCVSS 9,2İstismar yokEPSS %0ruijienetworks · reyee os6 Ara 2024
- CVE-2019-657035İzleyin
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0).
YüksekCVSS 8,8İstismar yokEPSS %1siemens · sinema remote connect server17 Nis 2019
- CVE-2022-219335İzleyin
Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 aut
YüksekCVSS 8,8İstismar yokEPSS %1hypr · hypr server19 Tem 2022
- CVE-2025-2982635İzleyin
Microsoft Dataverse Elevation of Privilege Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1microsoft · dataverse13 May 2025
- CVE-2026-4037135İzleyin
Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1microsoft · dynamics 3659 Haz 2026
- CVE-2024-2510835İzleyin
Insufficient authorization allowing elevated access to resources in pixelfed
YüksekCVSS 8,8İstismar yokEPSS %1pixelfed · pixelfed12 Şub 2024
- CVE-2025-2702535İzleyin
Improper File Access in Infinera G42
YüksekCVSS 8,8İstismar yokEPSS %1infinera · g422 Tem 2025
- CVE-2024-2207835İzleyin
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before.
YüksekCVSS 8,8İstismar yokEPSS %1elspec-ltd · g5dfr firmware20 Mar 2024
- CVE-2024-666035İzleyin
BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Option
YüksekCVSS 8,8İstismar yokEPSS %1reputeinfosystems · bookingpress17 Tem 2024
- CVE-2024-3645135İzleyin
Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003.
YüksekCVSS 8,8İstismar yokEPSS %1webmin · webmin10 Tem 2024
- CVE-2025-810935İzleyin
GPU DDK - GPU shader shared memory corrupted using ptrace to disrupt GPU operation
YüksekCVSS 8,8İstismar yokEPSS %0imagination technologies · graphics ddk4 Ağu 2025
- CVE-2025-2225635İzleyin
A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1
YüksekCVSS 8,8İstismar yokEPSS %0fortinet · fortipam10 Haz 2025
- CVE-2026-5956735İzleyin
Local privilege escalation
YüksekCVSS 8,8İstismar yokEPSS %0zscaler · client connector24 Ağu 2026
- CVE-2026-1886034İzleyin
Velociraptor incorrect Org deletion permissions check
YüksekCVSS 8,7İstismar yokEPSS %0rapid7 · velociraptor11 Ağu 2026
- CVE-2026-212334İzleyin
Privilege escalation vulnerability in Operations Agent
YüksekCVSS 8,6İstismar yokEPSS %0microfocus · operations agent31 Mar 2026
- CVE-2026-2081733İzleyin
Windows Error Reporting Service Elevation of Privilege Vulnerability
YüksekCVSS 7,8Kavram kanıtıEPSS %6microsoft · windows 10 21h213 Oca 2026
- CVE-2026-004733İzleyin
In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due to a missing permis
YüksekCVSS 8,4Kavram kanıtıEPSS %0google · android2 Mar 2026
- CVE-2020-2903132İzleyin
Insecure Direct Object Reference in GateManager WebUI can cause privilege escalation
YüksekCVSS 8,1İstismar yokEPSS %1secomea · gatemanager 8250 firmware15 Şub 2021
- CVE-2025-6784832İzleyin
Moodle: moodle: authentication bypass via lti provider allows suspended users to gain unauthorized access.
YüksekCVSS 8,1İstismar yokEPSS %0moodle · moodle3 Şub 2026
- CVE-2024-4370232İzleyin
GPU DDK - MLIST/PM render state buffers writable allowing arbitrary writes to kernel memory pages
YüksekCVSS 8,1İstismar yokEPSS %0imagination technologies · graphics ddk29 Kas 2024
- CVE-2025-6250932İzleyin
FileRise improper ownership/permission validation allowed cross-tenant file operations
YüksekCVSS 8,1İstismar yokEPSS %0filerise · filerise20 Eki 2025