Skip to content
Noroxi

CWE-280 · 190 records

Improper Handling of Insufficient Permissions or Privileges

CVEs in this class

190 records

  • An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.

    CriticalCVSS 9.8Proof of conceptEPSS 28%

    ruijie · rg-nbs2009g-p firmwareOct 2, 2024

  • CVE-2025-6573
    39Monitor

    GPU DDK - RGXFW_CTL.pui8FWScratchBuf Leak/Overwrite

    CriticalCVSS 9.8No exploitEPSS 0%

    imagination technologies · graphics ddkAug 8, 2025

  • An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges

    CriticalCVSS 9.9No exploitEPSS 0%

    automai · directorJan 12, 2026

  • Apache Kvrocks: Improper permission for the APPLYBATCH command

    CriticalCVSS 9.4No exploitEPSS 0%

    apache software foundation · apache kvrocksJun 25, 2026

  • Ruijie Reyee OS Improper Handling of Insufficient Permissions or Privileges

    CriticalCVSS 9.2No exploitEPSS 0%

    ruijienetworks · reyee osDec 6, 2024

  • CVE-2019-6570
    35Monitor

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0).

    HighCVSS 8.8No exploitEPSS 1%

    siemens · sinema remote connect serverApr 17, 2019

  • CVE-2022-2193
    35Monitor

    Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 aut

    HighCVSS 8.8No exploitEPSS 1%

    hypr · hypr serverJul 19, 2022

  • Microsoft Dataverse Elevation of Privilege Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    microsoft · dataverseMay 13, 2025

  • Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    microsoft · dynamics 365Jun 9, 2026

  • Insufficient authorization allowing elevated access to resources in pixelfed

    HighCVSS 8.8No exploitEPSS 1%

    pixelfed · pixelfedFeb 12, 2024

  • Improper File Access in Infinera G42

    HighCVSS 8.8No exploitEPSS 1%

    infinera · g42Jul 2, 2025

  • An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before.

    HighCVSS 8.8No exploitEPSS 1%

    elspec-ltd · g5dfr firmwareMar 20, 2024

  • CVE-2024-6660
    35Monitor

    BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Option

    HighCVSS 8.8No exploitEPSS 1%

    reputeinfosystems · bookingpressJul 17, 2024

  • Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003.

    HighCVSS 8.8No exploitEPSS 1%

    webmin · webminJul 10, 2024

  • CVE-2025-8109
    35Monitor

    GPU DDK - GPU shader shared memory corrupted using ptrace to disrupt GPU operation

    HighCVSS 8.8No exploitEPSS 0%

    imagination technologies · graphics ddkAug 4, 2025

  • A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1

    HighCVSS 8.8No exploitEPSS 0%

    fortinet · fortipamJun 10, 2025

  • Local privilege escalation

    HighCVSS 8.8No exploitEPSS 0%

    zscaler · client connectorAug 24, 2026

  • Velociraptor incorrect Org deletion permissions check

    HighCVSS 8.7No exploitEPSS 0%

    rapid7 · velociraptorAug 11, 2026

  • CVE-2026-2123
    34Monitor

    Privilege escalation vulnerability in Operations Agent

    HighCVSS 8.6No exploitEPSS 0%

    microfocus · operations agentMar 31, 2026

  • Windows Error Reporting Service Elevation of Privilege Vulnerability

    HighCVSS 7.8Proof of conceptEPSS 6%

    microsoft · windows 10 21h2Jan 13, 2026

  • CVE-2026-0047
    33Monitor

    In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due to a missing permis

    HighCVSS 8.4Proof of conceptEPSS 0%

    google · androidMar 2, 2026

  • Insecure Direct Object Reference in GateManager WebUI can cause privilege escalation

    HighCVSS 8.1No exploitEPSS 1%

    secomea · gatemanager 8250 firmwareFeb 15, 2021

  • Moodle: moodle: authentication bypass via lti provider allows suspended users to gain unauthorized access.

    HighCVSS 8.1No exploitEPSS 0%

    moodle · moodleFeb 3, 2026

  • GPU DDK - MLIST/PM render state buffers writable allowing arbitrary writes to kernel memory pages

    HighCVSS 8.1No exploitEPSS 0%

    imagination technologies · graphics ddkNov 29, 2024

  • FileRise improper ownership/permission validation allowed cross-tenant file operations

    HighCVSS 8.1No exploitEPSS 0%

    filerise · fileriseOct 20, 2025

All vulnerability classes