CWE-274 · 37 records
Improper Handling of Insufficient Privileges
CVEs in this class
37 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2025-20156No exploit | Cisco Meeting Management Client-Server Privilege Escalation Vulnerabilitycisco · meeting management · CWE-274 | Critical9.9 | — | 1.2% | Jan 22, 2025 |
39Monitor | CVE-2022-45101No exploit | Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS.dell · emc powerscale onefs · CWE-274 | Critical9.8 | — | 0.8% | Feb 1, 2023 |
39Monitor | CVE-2023-39375No exploit | SiberianCMS - CWE-274: Improper Handling of Insufficient Privilegessiberiancms · siberiancms · CWE-274 | Critical9.8 | — | 0.8% | Sep 27, 2023 |
39Monitor | CVE-2022-0668No exploit | JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted rjfrog · artifactory · CWE-274 | Critical9.8 | — | 0.6% | Jan 8, 2023 |
35Monitor | CVE-2023-35928No exploit | Nextcloud user scoped external storage can be used to gather credentials of other usersnextcloud · nextcloud server · CWE-274 | High8.8 | — | 1.0% | Jun 23, 2023 |
35Monitor | CVE-2020-7283Proof of concept | Privilege Escalation vulnerability in McAfee Total Protection (MTP)mcafee · total protection · CWE-274 | High8.8 | — | 0.6% | Jul 3, 2020 |
35Monitor | CVE-2024-21648No exploit | XWiki has no right protection on rollback actionxwiki · xwiki · CWE-274 | High8.8 | — | 0.5% | Jan 8, 2024 |
35Monitor | CVE-2024-0105No exploit | NVIDIA ConnectX Firmware contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue.nvidia · connectx4 · CWE-274 | High8.9 | — | 0.3% | Nov 1, 2024 |
34Monitor | CVE-2024-0106No exploit | NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability where an attacker may cause an improper nvidia · bluefield 1 · CWE-274 | High8.7 | — | 0.2% | Nov 1, 2024 |
33Monitor | CVE-2020-7267No exploit | Privilege Escalation vulnerability through symbolic links in VSELmcafee · virusscan enterprise · CWE-274 | High8.4 | — | 0.3% | May 8, 2020 |
33Monitor | CVE-2020-7264No exploit | Privilege Escalation vulnerability through symbolic links in ENS for Windowsmcafee · endpoint security · CWE-274 | High8.4 | — | 0.3% | May 8, 2020 |
33Monitor | CVE-2020-7265No exploit | Privilege Escalation vulnerability through symbolic links in ENSMmcafee · endpoint security · CWE-274 | High8.4 | — | 0.3% | May 8, 2020 |
33Monitor | CVE-2020-7266No exploit | Privilege Escalation vulnerability through symbolic links in VSE for Windowsmcafee · virusscan enterprise · CWE-274 | High8.4 | — | 0.3% | May 8, 2020 |
31Monitor | CVE-2020-24676No exploit | Insecure Windows Services in Symphony Plusabb · symphony \+ historian · CWE-274 | High7.8 | — | 0.4% | Dec 22, 2020 |
31Monitor | CVE-2017-3912No exploit | McAfee Application Control and Change Control (MACC) - password management security feature bypass (SFB) leading to an authentication bypassmcafee · application and change control · CWE-274 | High7.8 | — | 0.4% | Sep 18, 2018 |
31Monitor | CVE-2020-7289No exploit | Privilege Escalation vulnerability in MAR for Windowsmcafee · active response · CWE-274 | High7.8 | — | 0.3% | May 8, 2020 |
31Monitor | CVE-2020-7290No exploit | Privilege Escalation vulnerability in MAR for Linuxmcafee · active response · CWE-274 | High7.8 | — | 0.3% | May 8, 2020 |
31Monitor | CVE-2020-7286No exploit | Privilege Escalation vulnerability in EDR for Windowsmcafee · endpoint detection and response · CWE-274 | High7.8 | — | 0.3% | May 8, 2020 |
31Monitor | CVE-2020-7287No exploit | Privilege Escalation vulnerability in EDR for Linuxmcafee · endpoint detection and response · CWE-274 | High7.8 | — | 0.3% | May 8, 2020 |
31Monitor | CVE-2020-7285No exploit | Privilege Escalation vulnerability in MVISION Endpointmcafee · mvision endpoint · CWE-274 | High7.8 | — | 0.3% | May 8, 2020 |
31Monitor | CVE-2020-7288No exploit | Privilege Escalation vulnerability in EDR for Macmcafee · endpoint detection and response · CWE-274 | High7.8 | — | 0.3% | May 8, 2020 |
31Monitor | CVE-2020-7291No exploit | Privilege Escalation vulnerability MAR for Macmcafee · active response · CWE-274 | High7.8 | — | 0.3% | May 8, 2020 |
29Monitor | CVE-2021-35534No exploit | Insufficient Security Control Vulnerabilityhitachienergy · gms600 firmware · CWE-274 | High7.2 | — | 1.8% | Nov 18, 2021 |
28Monitor | CVE-2024-41942No exploit | JupyterHub has a privilege escalation vulnerability with the `admin:users` scopejupyter · jupyterhub · CWE-274 | High7.2 | — | 0.6% | Aug 8, 2024 |
27Monitor | CVE-2022-23511No exploit | A privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and logs from Amazon EC2amazon · cloudwatch agent · CWE-274 | Medium6.8 | — | 0.5% | Dec 12, 2022 |
- CVE-2025-2015639Monitor
Cisco Meeting Management Client-Server Privilege Escalation Vulnerability
CriticalCVSS 9.9No exploitEPSS 1%cisco · meeting managementJan 22, 2025
- CVE-2022-4510139Monitor
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS.
CriticalCVSS 9.8No exploitEPSS 1%dell · emc powerscale onefsFeb 1, 2023
- CVE-2023-3937539Monitor
SiberianCMS - CWE-274: Improper Handling of Insufficient Privileges
CriticalCVSS 9.8No exploitEPSS 1%siberiancms · siberiancmsSep 27, 2023
- CVE-2022-066839Monitor
JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted r
CriticalCVSS 9.8No exploitEPSS 1%jfrog · artifactoryJan 8, 2023
- CVE-2023-3592835Monitor
Nextcloud user scoped external storage can be used to gather credentials of other users
HighCVSS 8.8No exploitEPSS 1%nextcloud · nextcloud serverJun 23, 2023
- CVE-2020-728335Monitor
Privilege Escalation vulnerability in McAfee Total Protection (MTP)
HighCVSS 8.8Proof of conceptEPSS 1%mcafee · total protectionJul 3, 2020
- CVE-2024-2164835Monitor
XWiki has no right protection on rollback action
HighCVSS 8.8No exploitEPSS 1%xwiki · xwikiJan 8, 2024
- CVE-2024-010535Monitor
NVIDIA ConnectX Firmware contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue.
HighCVSS 8.9No exploitEPSS 0%nvidia · connectx4Nov 1, 2024
- CVE-2024-010634Monitor
NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability where an attacker may cause an improper
HighCVSS 8.7No exploitEPSS 0%nvidia · bluefield 1Nov 1, 2024
- CVE-2020-726733Monitor
Privilege Escalation vulnerability through symbolic links in VSEL
HighCVSS 8.4No exploitEPSS 0%mcafee · virusscan enterpriseMay 8, 2020
- CVE-2020-726433Monitor
Privilege Escalation vulnerability through symbolic links in ENS for Windows
HighCVSS 8.4No exploitEPSS 0%mcafee · endpoint securityMay 8, 2020
- CVE-2020-726533Monitor
Privilege Escalation vulnerability through symbolic links in ENSM
HighCVSS 8.4No exploitEPSS 0%mcafee · endpoint securityMay 8, 2020
- CVE-2020-726633Monitor
Privilege Escalation vulnerability through symbolic links in VSE for Windows
HighCVSS 8.4No exploitEPSS 0%mcafee · virusscan enterpriseMay 8, 2020
- CVE-2020-2467631Monitor
Insecure Windows Services in Symphony Plus
HighCVSS 7.8No exploitEPSS 0%abb · symphony \+ historianDec 22, 2020
- CVE-2017-391231Monitor
McAfee Application Control and Change Control (MACC) - password management security feature bypass (SFB) leading to an authentication bypass
HighCVSS 7.8No exploitEPSS 0%mcafee · application and change controlSep 18, 2018
- CVE-2020-728931Monitor
Privilege Escalation vulnerability in MAR for Windows
HighCVSS 7.8No exploitEPSS 0%mcafee · active responseMay 8, 2020
- CVE-2020-729031Monitor
Privilege Escalation vulnerability in MAR for Linux
HighCVSS 7.8No exploitEPSS 0%mcafee · active responseMay 8, 2020
- CVE-2020-728631Monitor
Privilege Escalation vulnerability in EDR for Windows
HighCVSS 7.8No exploitEPSS 0%mcafee · endpoint detection and responseMay 8, 2020
- CVE-2020-728731Monitor
Privilege Escalation vulnerability in EDR for Linux
HighCVSS 7.8No exploitEPSS 0%mcafee · endpoint detection and responseMay 8, 2020
- CVE-2020-728531Monitor
Privilege Escalation vulnerability in MVISION Endpoint
HighCVSS 7.8No exploitEPSS 0%mcafee · mvision endpointMay 8, 2020
- CVE-2020-728831Monitor
Privilege Escalation vulnerability in EDR for Mac
HighCVSS 7.8No exploitEPSS 0%mcafee · endpoint detection and responseMay 8, 2020
- CVE-2020-729131Monitor
Privilege Escalation vulnerability MAR for Mac
HighCVSS 7.8No exploitEPSS 0%mcafee · active responseMay 8, 2020
- CVE-2021-3553429Monitor
Insufficient Security Control Vulnerability
HighCVSS 7.2No exploitEPSS 2%hitachienergy · gms600 firmwareNov 18, 2021
- CVE-2024-4194228Monitor
JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
HighCVSS 7.2No exploitEPSS 1%jupyter · jupyterhubAug 8, 2024
- CVE-2022-2351127Monitor
A privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and logs from Amazon EC2
MediumCVSS 6.8No exploitEPSS 1%amazon · cloudwatch agentDec 12, 2022