CWE-648 · 68 records
Incorrect Use of Privileged APIs
CVEs in this class
68 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
74This week | CVE-2026-76460Weaponized | Cisco Identity Services Engine Authentication Bypass Vulnerabilitycisco · identity services engine · CWE-648 | Critical10.0 | KEV | 14.0% | Sep 16, 2026 |
58Plan | CVE-2026-20122Weaponized | Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerabilitycisco · catalyst sd-wan manager · CWE-648 | Medium5.4 | KEV | 25.0% | Feb 25, 2026 |
42Plan | CVE-2019-14813No exploit | A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged artifex · ghostscript · CWE-648 | Critical9.8 | — | 11.4% | Sep 6, 2019 |
40Plan | CVE-2019-1010178No exploit | Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648.modx · fred · CWE-648 | Critical9.8 | — | 4.6% | Jul 24, 2019 |
40Plan | CVE-2022-2023No exploit | Incorrect Use of Privileged APIs in polonel/trudesktrudesk project · trudesk · CWE-648 | Critical9.8 | — | 3.2% | Jun 20, 2022 |
39Monitor | CVE-2024-11068No exploit | D-Link DSL6740C - Incorrect Use of Privileged APIsdlink · dsl6740c firmware · CWE-648 | Critical9.8 | — | 1.2% | Nov 11, 2024 |
39Monitor | CVE-2023-4972No exploit | Information Disclosure in Digital Yepasyepas · digital yepas · CWE-648 | Critical9.8 | — | 0.7% | Sep 14, 2023 |
36Monitor | CVE-2019-14869No exploit | A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its priviartifex · ghostscript · CWE-648 | High8.8 | — | 3.4% | Nov 15, 2019 |
36Monitor | CVE-2026-41386No exploit | OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codesopenclaw · openclaw · CWE-648 | Critical9.1 | — | 0.6% | Apr 28, 2026 |
36Monitor | CVE-2026-41329No exploit | OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalationopenclaw · openclaw · CWE-648 | Critical9.0 | — | 0.5% | Apr 20, 2026 |
36Monitor | CVE-2024-37018No exploit | The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken bCWE-648 | Critical9.1 | — | 0.4% | May 30, 2024 |
35Monitor | CVE-2022-20956No exploit | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker cisco · identity services engine · CWE-648 | High8.8 | — | 1.4% | Nov 4, 2022 |
35Monitor | CVE-2023-28062No exploit | Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability.dell · powerprotect data manager · CWE-648 | High8.8 | — | 0.8% | Apr 11, 2023 |
35Monitor | CVE-2025-5997No exploit | Privilege Escalation in Beamsec PhishProbeamsec · phishpro · CWE-648 | High8.8 | — | 0.4% | Jul 28, 2025 |
35Monitor | GHSA-r3v5-2grc-429hNo exploit | Duplicate Advisory: OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approvenpm · openclaw · CWE-648 | High8.8 | — | — | Apr 10, 2026 |
34Monitor | CVE-2026-35639No exploit | OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope Validationopenclaw · openclaw · CWE-648 | High8.7 | — | 0.8% | Apr 9, 2026 |
34Monitor | CVE-2025-7344No exploit | Digiwin|EAI - Privilege Escalationdigiwin · eai · CWE-648 | High8.7 | — | 0.5% | Jul 21, 2025 |
34Monitor | CVE-2026-35669No exploit | OpenClaw < 2026.3.25 - Privilege Escalation via Gateway Plugin HTTP Authentication Scopeopenclaw · openclaw · CWE-648 | High8.7 | — | 0.5% | Apr 10, 2026 |
34Monitor | CVE-2026-35663No exploit | OpenClaw < 2026.3.25 - Privilege Escalation via Backend Reconnect Scope Self-Claimopenclaw · openclaw · CWE-648 | High8.7 | — | 0.5% | Apr 10, 2026 |
34Monitor | CVE-2026-41225No exploit | iControl REST vulnerabilityf5 · big-ip access policy manager · CWE-648 | High8.6 | — | 0.5% | May 13, 2026 |
34Monitor | CVE-2026-63727No exploit | Anchore Enterprise Privilege Escalation via User Management APIanchore · anchore enterprise · CWE-648 | High8.7 | — | 0.4% | Jul 28, 2026 |
34Monitor | CVE-2022-26323No exploit | Incorrect Use of Privileged vulnerability has been discovered on OpenText™ UCMDB and Operation Bridge Manager product.opentext™ · operations bridge manager · CWE-648 | High8.7 | — | 0.3% | Apr 17, 2025 |
34Monitor | CVE-2026-35625No exploit | OpenClaw < 2026.3.25 - Privilege Escalation via Silent Local Shared-Auth Reconnectopenclaw · openclaw · CWE-648 | High8.5 | — | 0.3% | Apr 9, 2026 |
34Monitor | CVE-2024-32008No exploit | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2).siemens · spectrum power 4 · CWE-648 | High8.5 | — | 0.1% | Nov 11, 2025 |
33Monitor | CVE-2026-54424Proof of concept | An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege.unity · parsec · CWE-648 | High8.4 | — | 0.2% | Jul 3, 2026 |
- CVE-2026-7646074This week
Cisco Identity Services Engine Authentication Bypass Vulnerability
CriticalCVSS 10.0KEVWeaponizedEPSS 14%cisco · identity services engineSep 16, 2026
- CVE-2026-2012258Plan
Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability
MediumCVSS 5.4KEVWeaponizedEPSS 25%cisco · catalyst sd-wan managerFeb 25, 2026
- CVE-2019-1481342Plan
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged
CriticalCVSS 9.8No exploitEPSS 11%artifex · ghostscriptSep 6, 2019
- CVE-2019-101017840Plan
Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648.
CriticalCVSS 9.8No exploitEPSS 5%modx · fredJul 24, 2019
- CVE-2022-202340Plan
Incorrect Use of Privileged APIs in polonel/trudesk
CriticalCVSS 9.8No exploitEPSS 3%trudesk project · trudeskJun 20, 2022
- CVE-2024-1106839Monitor
D-Link DSL6740C - Incorrect Use of Privileged APIs
CriticalCVSS 9.8No exploitEPSS 1%dlink · dsl6740c firmwareNov 11, 2024
- CVE-2023-497239Monitor
Information Disclosure in Digital Yepas
CriticalCVSS 9.8No exploitEPSS 1%yepas · digital yepasSep 14, 2023
- CVE-2019-1486936Monitor
A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privi
HighCVSS 8.8No exploitEPSS 3%artifex · ghostscriptNov 15, 2019
- CVE-2026-4138636Monitor
OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes
CriticalCVSS 9.1No exploitEPSS 1%openclaw · openclawApr 28, 2026
- CVE-2026-4132936Monitor
OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalation
CriticalCVSS 9.0No exploitEPSS 1%openclaw · openclawApr 20, 2026
- CVE-2024-3701836Monitor
The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken b
CriticalCVSS 9.1No exploitEPSS 0%May 30, 2024
- CVE-2022-2095635Monitor
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker
HighCVSS 8.8No exploitEPSS 1%cisco · identity services engineNov 4, 2022
- CVE-2023-2806235Monitor
Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability.
HighCVSS 8.8No exploitEPSS 1%dell · powerprotect data managerApr 11, 2023
- CVE-2025-599735Monitor
Privilege Escalation in Beamsec PhishPro
HighCVSS 8.8No exploitEPSS 0%beamsec · phishproJul 28, 2025
- GHSA-r3v5-2grc-429h35Monitor
Duplicate Advisory: OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approve
HighCVSS 8.8No exploitnpm · openclawApr 10, 2026
- CVE-2026-3563934Monitor
OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope Validation
HighCVSS 8.7No exploitEPSS 1%openclaw · openclawApr 9, 2026
- CVE-2025-734434Monitor
Digiwin|EAI - Privilege Escalation
HighCVSS 8.7No exploitEPSS 1%digiwin · eaiJul 21, 2025
- CVE-2026-3566934Monitor
OpenClaw < 2026.3.25 - Privilege Escalation via Gateway Plugin HTTP Authentication Scope
HighCVSS 8.7No exploitEPSS 1%openclaw · openclawApr 10, 2026
- CVE-2026-3566334Monitor
OpenClaw < 2026.3.25 - Privilege Escalation via Backend Reconnect Scope Self-Claim
HighCVSS 8.7No exploitEPSS 1%openclaw · openclawApr 10, 2026
- CVE-2026-4122534Monitor
iControl REST vulnerability
HighCVSS 8.6No exploitEPSS 0%f5 · big-ip access policy managerMay 13, 2026
- CVE-2026-6372734Monitor
Anchore Enterprise Privilege Escalation via User Management API
HighCVSS 8.7No exploitEPSS 0%anchore · anchore enterpriseJul 28, 2026
- CVE-2022-2632334Monitor
Incorrect Use of Privileged vulnerability has been discovered on OpenText™ UCMDB and Operation Bridge Manager product.
HighCVSS 8.7No exploitEPSS 0%opentext™ · operations bridge managerApr 17, 2025
- CVE-2026-3562534Monitor
OpenClaw < 2026.3.25 - Privilege Escalation via Silent Local Shared-Auth Reconnect
HighCVSS 8.5No exploitEPSS 0%openclaw · openclawApr 9, 2026
- CVE-2024-3200834Monitor
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2).
HighCVSS 8.5No exploitEPSS 0%siemens · spectrum power 4Nov 11, 2025
- CVE-2026-5442433Monitor
An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege.
HighCVSS 8.4Proof of conceptEPSS 0%unity · parsecJul 3, 2026