Перейти к содержимому
Noroxi

CWE-250 · 353 записей

Execution with Unnecessary Privileges

CVE этого класса

354 записей

  • CVE-2024-38813
    74На этой неделе

    Privilege escalation vulnerability

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 17 %

    vmware · cloud foundation17 сент. 2024 г.

  • CVE-2024-1222
    58В плане

    Incorrect authorization controls in PaperCut NG/MF APIs

    КритическаяCVSS 9,8Эксплойта нетEPSS 64 %

    papercut · papercut mf13 мар. 2024 г.

  • CVE-2025-40602
    57В плане

    A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

    СредняяCVSS 6,6KEVГотовый эксплойтEPSS 3 %

    sonicwall · sma6200 firmware18 дек. 2025 г.

  • CVE-2025-12420
    53В плане

    Unauthenticated Privilege Escalation in ServiceNow AI Platform

    КритическаяCVSS 9,3Proof of conceptEPSS 53 %

    servicenow · now assist ai agents12 янв. 2026 г.

  • CVE-2021-41035
    40В плане

    In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface meth

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    eclipse · openj925 окт. 2021 г.

  • CVE-2022-1517
    40В плане

    3.2.1 EXECUTION WITH UNNECESSARY PRIVILEGES CWE-250

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    illumina · local run manager24 июн. 2022 г.

  • CVE-2026-4606
    40В плане

    GeoVision ERM Improper Privilege Assignment Leads to SYSTEM-Level Privilege

    КритическаяCVSS 10,0Эксплойта нетEPSS 0 %

    geovision · gv-edge recording manager22 мар. 2026 г.

  • CVE-2025-34515
    39Наблюдать

    Ilevia EVE X1 Server 4.7.18.0.eden Root Privilege Escalation

    КритическаяCVSS 9,3Эксплойта нетEPSS 8 %

    ilevia · eve x1 server firmware16 окт. 2025 г.

  • CVE-2024-25421
    39Наблюдать

    An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    igniterealtime · openfire26 мар. 2024 г.

  • CVE-2023-52030
    39Наблюдать

    TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setOpModeCfg functio

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    totolink · a3700r firmware11 янв. 2024 г.

  • CVE-2023-4662
    39Наблюдать

    RCE in Saphira Connect

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    adobe · connect15 сент. 2023 г.

  • CVE-2024-27143
    39Наблюдать

    Pre-authenticated Remote Code Execution

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    toshiba tec corporation · toshiba tec e-studio multi-function peripheral (mfp)13 июн. 2024 г.

  • CVE-2022-2634
    39Наблюдать

    Digi ConnectPort X2D

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    digi · connectport x2d firmware10 авг. 2022 г.

  • CVE-2023-1966
    39Наблюдать

    Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    illumina · iscan firmware28 апр. 2023 г.

  • CVE-2022-44544
    39Наблюдать

    Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    mahara · mahara6 нояб. 2022 г.

  • CVE-2026-72508
    39Наблюдать

    Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke serviceaccounts bound to wildcard rbac (*/*/*)

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    red hat · red hat advanced cluster management for kubernetes 2.1112 авг. 2026 г.

  • CVE-2025-33224
    39Наблюдать

    NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    nvidia · isaac launchable23 дек. 2025 г.

  • CVE-2025-32445
    39Наблюдать

    Users can gain privileged access to the host system and cluster with EventSource and Sensor CR

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    argoproj · argo-events15 апр. 2025 г.

  • CVE-2022-32535
    39Наблюдать

    Web server runs as root

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    bosch · pra-es8p2s firmware23 июн. 2022 г.

  • CVE-2026-34877
    39Наблюдать

    An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    arm · mbed tls2 апр. 2026 г.

  • CVE-2023-45592
    39Наблюдать

    A CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary being executed with the

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    ailux · imx65 мар. 2024 г.

  • CVE-2025-33223
    39Наблюдать

    NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    nvidia · isaac launchable23 дек. 2025 г.

  • CVE-2024-3330
    39Наблюдать

    Spotfire Remote Code Execution Vulnerability

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    spotfire · spotfire analyst27 июн. 2024 г.

  • CVE-2025-57119
    39Наблюдать

    An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    phpgurukul · online library management system16 сент. 2025 г.

  • CVE-2025-13375
    39Наблюдать

    IBM Common Cryptographic Architecture Arbitrary Command Execution

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    ibm · common cryptographic architecture4 февр. 2026 г.

Все классы уязвимостей