Skip to content
Noroxi

CWE-648 · 68 records

Incorrect Use of Privileged APIs

CVEs in this class

68 records

  • CVE-2026-76460
    74This week

    Cisco Identity Services Engine Authentication Bypass Vulnerability

    CriticalCVSS 10.0KEVWeaponizedEPSS 14%

    cisco · identity services engineSep 16, 2026

  • Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability

    MediumCVSS 5.4KEVWeaponizedEPSS 25%

    cisco · catalyst sd-wan managerFeb 25, 2026

  • A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged

    CriticalCVSS 9.8No exploitEPSS 11%

    artifex · ghostscriptSep 6, 2019

  • Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648.

    CriticalCVSS 9.8No exploitEPSS 5%

    modx · fredJul 24, 2019

  • Incorrect Use of Privileged APIs in polonel/trudesk

    CriticalCVSS 9.8No exploitEPSS 3%

    trudesk project · trudeskJun 20, 2022

  • D-Link DSL6740C - Incorrect Use of Privileged APIs

    CriticalCVSS 9.8No exploitEPSS 1%

    dlink · dsl6740c firmwareNov 11, 2024

  • CVE-2023-4972
    39Monitor

    Information Disclosure in Digital Yepas

    CriticalCVSS 9.8No exploitEPSS 1%

    yepas · digital yepasSep 14, 2023

  • A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privi

    HighCVSS 8.8No exploitEPSS 3%

    artifex · ghostscriptNov 15, 2019

  • OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes

    CriticalCVSS 9.1No exploitEPSS 1%

    openclaw · openclawApr 28, 2026

  • OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalation

    CriticalCVSS 9.0No exploitEPSS 1%

    openclaw · openclawApr 20, 2026

  • The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken b

    CriticalCVSS 9.1No exploitEPSS 0%

    May 30, 2024

  • A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker

    HighCVSS 8.8No exploitEPSS 1%

    cisco · identity services engineNov 4, 2022

  • Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability.

    HighCVSS 8.8No exploitEPSS 1%

    dell · powerprotect data managerApr 11, 2023

  • CVE-2025-5997
    35Monitor

    Privilege Escalation in Beamsec PhishPro

    HighCVSS 8.8No exploitEPSS 0%

    beamsec · phishproJul 28, 2025

  • Duplicate Advisory: OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approve

    HighCVSS 8.8No exploit

    npm · openclawApr 10, 2026

  • OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope Validation

    HighCVSS 8.7No exploitEPSS 1%

    openclaw · openclawApr 9, 2026

  • CVE-2025-7344
    34Monitor

    Digiwin|EAI - Privilege Escalation

    HighCVSS 8.7No exploitEPSS 1%

    digiwin · eaiJul 21, 2025

  • OpenClaw < 2026.3.25 - Privilege Escalation via Gateway Plugin HTTP Authentication Scope

    HighCVSS 8.7No exploitEPSS 1%

    openclaw · openclawApr 10, 2026

  • OpenClaw < 2026.3.25 - Privilege Escalation via Backend Reconnect Scope Self-Claim

    HighCVSS 8.7No exploitEPSS 1%

    openclaw · openclawApr 10, 2026

  • iControl REST vulnerability

    HighCVSS 8.6No exploitEPSS 0%

    f5 · big-ip access policy managerMay 13, 2026

  • Anchore Enterprise Privilege Escalation via User Management API

    HighCVSS 8.7No exploitEPSS 0%

    anchore · anchore enterpriseJul 28, 2026

  • Incorrect Use of Privileged vulnerability has been discovered on OpenText™ UCMDB and Operation Bridge Manager product.

    HighCVSS 8.7No exploitEPSS 0%

    opentext™ · operations bridge managerApr 17, 2025

  • OpenClaw < 2026.3.25 - Privilege Escalation via Silent Local Shared-Auth Reconnect

    HighCVSS 8.5No exploitEPSS 0%

    openclaw · openclawApr 9, 2026

  • A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2).

    HighCVSS 8.5No exploitEPSS 0%

    siemens · spectrum power 4Nov 11, 2025

  • An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege.

    HighCVSS 8.4Proof of conceptEPSS 0%

    unity · parsecJul 3, 2026

All vulnerability classes