CWE-280 · 190 records
Improper Handling of Insufficient Permissions or Privileges
CVEs in this class
190 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
48Plan | CVE-2024-24116Proof of concept | An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.ruijie · rg-nbs2009g-p firmware · CWE-280 | Critical9.8 | — | 28.4% | Oct 2, 2024 |
39Monitor | CVE-2025-6573No exploit | GPU DDK - RGXFW_CTL.pui8FWScratchBuf Leak/Overwriteimagination technologies · graphics ddk · CWE-280 | Critical9.8 | — | 0.4% | Aug 8, 2025 |
39Monitor | CVE-2025-46066No exploit | An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privilegesautomai · director · CWE-280 | Critical9.9 | — | 0.3% | Jan 12, 2026 |
37Monitor | CVE-2026-41566No exploit | Apache Kvrocks: Improper permission for the APPLYBATCH commandapache software foundation · apache kvrocks · CWE-280 | Critical9.4 | — | 0.4% | Jun 25, 2026 |
36Monitor | CVE-2024-46874No exploit | Ruijie Reyee OS Improper Handling of Insufficient Permissions or Privilegesruijienetworks · reyee os · CWE-280 | Critical9.2 | — | 0.4% | Dec 6, 2024 |
35Monitor | CVE-2019-6570No exploit | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0).siemens · sinema remote connect server · CWE-280 | High8.8 | — | 1.3% | Apr 17, 2019 |
35Monitor | CVE-2022-2193No exploit | Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 authypr · hypr server · CWE-280 | High8.8 | — | 0.9% | Jul 19, 2022 |
35Monitor | CVE-2025-29826No exploit | Microsoft Dataverse Elevation of Privilege Vulnerabilitymicrosoft · dataverse · CWE-280 | High8.8 | — | 0.8% | May 13, 2025 |
35Monitor | CVE-2026-40371No exploit | Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerabilitymicrosoft · dynamics 365 · CWE-280 | High8.8 | — | 0.8% | Jun 9, 2026 |
35Monitor | CVE-2024-25108No exploit | Insufficient authorization allowing elevated access to resources in pixelfedpixelfed · pixelfed · CWE-280 | High8.8 | — | 0.7% | Feb 12, 2024 |
35Monitor | CVE-2025-27025No exploit | Improper File Access in Infinera G42infinera · g42 · CWE-280 | High8.8 | — | 0.7% | Jul 2, 2025 |
35Monitor | CVE-2024-22078No exploit | An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before.elspec-ltd · g5dfr firmware · CWE-280 | High8.8 | — | 0.6% | Mar 20, 2024 |
35Monitor | CVE-2024-6660No exploit | BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Optionreputeinfosystems · bookingpress · CWE-280 | High8.8 | — | 0.6% | Jul 17, 2024 |
35Monitor | CVE-2024-36451No exploit | Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003.webmin · webmin · CWE-280 | High8.8 | — | 0.6% | Jul 10, 2024 |
35Monitor | CVE-2025-8109No exploit | GPU DDK - GPU shader shared memory corrupted using ptrace to disrupt GPU operationimagination technologies · graphics ddk · CWE-280 | High8.8 | — | 0.4% | Aug 4, 2025 |
35Monitor | CVE-2025-22256No exploit | A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1fortinet · fortipam · CWE-280 | High8.8 | — | 0.4% | Jun 10, 2025 |
35Monitor | CVE-2026-59567No exploit | Local privilege escalationzscaler · client connector · CWE-280 | High8.8 | — | 0.1% | Aug 24, 2026 |
34Monitor | CVE-2026-18860No exploit | Velociraptor incorrect Org deletion permissions checkrapid7 · velociraptor · CWE-280 | High8.7 | — | 0.4% | Aug 11, 2026 |
34Monitor | CVE-2026-2123No exploit | Privilege escalation vulnerability in Operations Agentmicrofocus · operations agent · CWE-280 | High8.6 | — | 0.1% | Mar 31, 2026 |
33Monitor | CVE-2026-20817Proof of concept | Windows Error Reporting Service Elevation of Privilege Vulnerabilitymicrosoft · windows 10 21h2 · CWE-280 | High7.8 | — | 5.5% | Jan 13, 2026 |
33Monitor | CVE-2026-0047Proof of concept | In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due to a missing permisgoogle · android · CWE-280 | High8.4 | — | 0.1% | Mar 2, 2026 |
32Monitor | CVE-2020-29031No exploit | Insecure Direct Object Reference in GateManager WebUI can cause privilege escalationsecomea · gatemanager 8250 firmware · CWE-280 | High8.1 | — | 0.7% | Feb 15, 2021 |
32Monitor | CVE-2025-67848No exploit | Moodle: moodle: authentication bypass via lti provider allows suspended users to gain unauthorized access.moodle · moodle · CWE-280 | High8.1 | — | 0.4% | Feb 3, 2026 |
32Monitor | CVE-2024-43702No exploit | GPU DDK - MLIST/PM render state buffers writable allowing arbitrary writes to kernel memory pagesimagination technologies · graphics ddk · CWE-280 | High8.1 | — | 0.3% | Nov 29, 2024 |
32Monitor | CVE-2025-62509No exploit | FileRise improper ownership/permission validation allowed cross-tenant file operationsfilerise · filerise · CWE-280 | High8.1 | — | 0.3% | Oct 20, 2025 |
- CVE-2024-2411648Plan
An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.
CriticalCVSS 9.8Proof of conceptEPSS 28%ruijie · rg-nbs2009g-p firmwareOct 2, 2024
- CVE-2025-657339Monitor
GPU DDK - RGXFW_CTL.pui8FWScratchBuf Leak/Overwrite
CriticalCVSS 9.8No exploitEPSS 0%imagination technologies · graphics ddkAug 8, 2025
- CVE-2025-4606639Monitor
An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges
CriticalCVSS 9.9No exploitEPSS 0%automai · directorJan 12, 2026
- CVE-2026-4156637Monitor
Apache Kvrocks: Improper permission for the APPLYBATCH command
CriticalCVSS 9.4No exploitEPSS 0%apache software foundation · apache kvrocksJun 25, 2026
- CVE-2024-4687436Monitor
Ruijie Reyee OS Improper Handling of Insufficient Permissions or Privileges
CriticalCVSS 9.2No exploitEPSS 0%ruijienetworks · reyee osDec 6, 2024
- CVE-2019-657035Monitor
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0).
HighCVSS 8.8No exploitEPSS 1%siemens · sinema remote connect serverApr 17, 2019
- CVE-2022-219335Monitor
Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 aut
HighCVSS 8.8No exploitEPSS 1%hypr · hypr serverJul 19, 2022
- CVE-2025-2982635Monitor
Microsoft Dataverse Elevation of Privilege Vulnerability
HighCVSS 8.8No exploitEPSS 1%microsoft · dataverseMay 13, 2025
- CVE-2026-4037135Monitor
Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability
HighCVSS 8.8No exploitEPSS 1%microsoft · dynamics 365Jun 9, 2026
- CVE-2024-2510835Monitor
Insufficient authorization allowing elevated access to resources in pixelfed
HighCVSS 8.8No exploitEPSS 1%pixelfed · pixelfedFeb 12, 2024
- CVE-2025-2702535Monitor
Improper File Access in Infinera G42
HighCVSS 8.8No exploitEPSS 1%infinera · g42Jul 2, 2025
- CVE-2024-2207835Monitor
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before.
HighCVSS 8.8No exploitEPSS 1%elspec-ltd · g5dfr firmwareMar 20, 2024
- CVE-2024-666035Monitor
BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Option
HighCVSS 8.8No exploitEPSS 1%reputeinfosystems · bookingpressJul 17, 2024
- CVE-2024-3645135Monitor
Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003.
HighCVSS 8.8No exploitEPSS 1%webmin · webminJul 10, 2024
- CVE-2025-810935Monitor
GPU DDK - GPU shader shared memory corrupted using ptrace to disrupt GPU operation
HighCVSS 8.8No exploitEPSS 0%imagination technologies · graphics ddkAug 4, 2025
- CVE-2025-2225635Monitor
A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1
HighCVSS 8.8No exploitEPSS 0%fortinet · fortipamJun 10, 2025
- CVE-2026-5956735Monitor
Local privilege escalation
HighCVSS 8.8No exploitEPSS 0%zscaler · client connectorAug 24, 2026
- CVE-2026-1886034Monitor
Velociraptor incorrect Org deletion permissions check
HighCVSS 8.7No exploitEPSS 0%rapid7 · velociraptorAug 11, 2026
- CVE-2026-212334Monitor
Privilege escalation vulnerability in Operations Agent
HighCVSS 8.6No exploitEPSS 0%microfocus · operations agentMar 31, 2026
- CVE-2026-2081733Monitor
Windows Error Reporting Service Elevation of Privilege Vulnerability
HighCVSS 7.8Proof of conceptEPSS 6%microsoft · windows 10 21h2Jan 13, 2026
- CVE-2026-004733Monitor
In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due to a missing permis
HighCVSS 8.4Proof of conceptEPSS 0%google · androidMar 2, 2026
- CVE-2020-2903132Monitor
Insecure Direct Object Reference in GateManager WebUI can cause privilege escalation
HighCVSS 8.1No exploitEPSS 1%secomea · gatemanager 8250 firmwareFeb 15, 2021
- CVE-2025-6784832Monitor
Moodle: moodle: authentication bypass via lti provider allows suspended users to gain unauthorized access.
HighCVSS 8.1No exploitEPSS 0%moodle · moodleFeb 3, 2026
- CVE-2024-4370232Monitor
GPU DDK - MLIST/PM render state buffers writable allowing arbitrary writes to kernel memory pages
HighCVSS 8.1No exploitEPSS 0%imagination technologies · graphics ddkNov 29, 2024
- CVE-2025-6250932Monitor
FileRise improper ownership/permission validation allowed cross-tenant file operations
HighCVSS 8.1No exploitEPSS 0%filerise · fileriseOct 20, 2025