CWE-250 · 353 записей
Execution with Unnecessary Privileges
CVE этого класса
354 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
74На этой неделе | CVE-2024-38813Готовый эксплойт | Privilege escalation vulnerabilityvmware · cloud foundation · CWE-250 | Критическая9,8 | KEV | 17,4 % | 17 сент. 2024 г. |
58В плане | CVE-2024-1222Эксплойта нет | Incorrect authorization controls in PaperCut NG/MF APIspapercut · papercut mf · CWE-250 | Критическая9,8 | — | 64,0 % | 13 мар. 2024 г. |
57В плане | CVE-2025-40602Готовый эксплойт | A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).sonicwall · sma6200 firmware · CWE-250 | Средняя6,6 | KEV | 2,8 % | 18 дек. 2025 г. |
53В плане | CVE-2025-12420Proof of concept | Unauthenticated Privilege Escalation in ServiceNow AI Platformservicenow · now assist ai agents · CWE-250 | Критическая9,3 | — | 53,2 % | 12 янв. 2026 г. |
40В плане | CVE-2021-41035Эксплойта нет | In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface metheclipse · openj9 · CWE-250 | Критическая9,8 | — | 1,8 % | 25 окт. 2021 г. |
40В плане | CVE-2022-1517Эксплойта нет | 3.2.1 EXECUTION WITH UNNECESSARY PRIVILEGES CWE-250illumina · local run manager · CWE-250 | Критическая9,8 | — | 1,8 % | 24 июн. 2022 г. |
40В плане | CVE-2026-4606Эксплойта нет | GeoVision ERM Improper Privilege Assignment Leads to SYSTEM-Level Privilegegeovision · gv-edge recording manager · CWE-250 | Критическая10,0 | — | 0,4 % | 22 мар. 2026 г. |
39Наблюдать | CVE-2025-34515Эксплойта нет | Ilevia EVE X1 Server 4.7.18.0.eden Root Privilege Escalationilevia · eve x1 server firmware · CWE-250 | Критическая9,3 | — | 8,0 % | 16 окт. 2025 г. |
39Наблюдать | CVE-2024-25421Эксплойта нет | An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component.igniterealtime · openfire · CWE-250 | Критическая9,8 | — | 1,7 % | 26 мар. 2024 г. |
39Наблюдать | CVE-2023-52030Эксплойта нет | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setOpModeCfg functiototolink · a3700r firmware · CWE-250 | Критическая9,8 | — | 1,5 % | 11 янв. 2024 г. |
39Наблюдать | CVE-2023-4662Эксплойта нет | RCE in Saphira Connectadobe · connect · CWE-250 | Критическая9,8 | — | 1,2 % | 15 сент. 2023 г. |
39Наблюдать | CVE-2024-27143Эксплойта нет | Pre-authenticated Remote Code Executiontoshiba tec corporation · toshiba tec e-studio multi-function peripheral (mfp) · CWE-250 | Критическая9,8 | — | 1,1 % | 13 июн. 2024 г. |
39Наблюдать | CVE-2022-2634Эксплойта нет | Digi ConnectPort X2Ddigi · connectport x2d firmware · CWE-250 | Критическая9,8 | — | 1,0 % | 10 авг. 2022 г. |
39Наблюдать | CVE-2023-1966Эксплойта нет | Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability.illumina · iscan firmware · CWE-250 | Критическая9,8 | — | 0,9 % | 28 апр. 2023 г. |
39Наблюдать | CVE-2022-44544Эксплойта нет | Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger mahara · mahara · CWE-250 | Критическая9,8 | — | 0,8 % | 6 нояб. 2022 г. |
39Наблюдать | CVE-2026-72508Эксплойта нет | Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke serviceaccounts bound to wildcard rbac (*/*/*)red hat · red hat advanced cluster management for kubernetes 2.11 · CWE-250 | Критическая9,9 | — | 0,8 % | 12 авг. 2026 г. |
39Наблюдать | CVE-2025-33224Эксплойта нет | NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges.nvidia · isaac launchable · CWE-250 | Критическая9,8 | — | 0,8 % | 23 дек. 2025 г. |
39Наблюдать | CVE-2025-32445Эксплойта нет | Users can gain privileged access to the host system and cluster with EventSource and Sensor CRargoproj · argo-events · CWE-250 | Критическая9,9 | — | 0,8 % | 15 апр. 2025 г. |
39Наблюдать | CVE-2022-32535Эксплойта нет | Web server runs as rootbosch · pra-es8p2s firmware · CWE-250 | Критическая9,8 | — | 0,8 % | 23 июн. 2022 г. |
39Наблюдать | CVE-2026-34877Эксплойта нет | An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0.arm · mbed tls · CWE-250 | Критическая9,8 | — | 0,7 % | 2 апр. 2026 г. |
39Наблюдать | CVE-2023-45592Эксплойта нет | A CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary being executed with the ailux · imx6 · CWE-250 | Критическая9,8 | — | 0,7 % | 5 мар. 2024 г. |
39Наблюдать | CVE-2025-33223Эксплойта нет | NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges.nvidia · isaac launchable · CWE-250 | Критическая9,8 | — | 0,7 % | 23 дек. 2025 г. |
39Наблюдать | CVE-2024-3330Эксплойта нет | Spotfire Remote Code Execution Vulnerabilityspotfire · spotfire analyst · CWE-250 | Критическая9,9 | — | 0,6 % | 27 июн. 2024 г. |
39Наблюдать | CVE-2025-57119Эксплойта нет | An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login phpgurukul · online library management system · CWE-250 | Критическая9,8 | — | 0,6 % | 16 сент. 2025 г. |
39Наблюдать | CVE-2025-13375Эксплойта нет | IBM Common Cryptographic Architecture Arbitrary Command Executionibm · common cryptographic architecture · CWE-250 | Критическая9,8 | — | 0,6 % | 4 февр. 2026 г. |
- CVE-2024-3881374На этой неделе
Privilege escalation vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 17 %vmware · cloud foundation17 сент. 2024 г.
- CVE-2024-122258В плане
Incorrect authorization controls in PaperCut NG/MF APIs
КритическаяCVSS 9,8Эксплойта нетEPSS 64 %papercut · papercut mf13 мар. 2024 г.
- CVE-2025-4060257В плане
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
СредняяCVSS 6,6KEVГотовый эксплойтEPSS 3 %sonicwall · sma6200 firmware18 дек. 2025 г.
- CVE-2025-1242053В плане
Unauthenticated Privilege Escalation in ServiceNow AI Platform
КритическаяCVSS 9,3Proof of conceptEPSS 53 %servicenow · now assist ai agents12 янв. 2026 г.
- CVE-2021-4103540В плане
In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface meth
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %eclipse · openj925 окт. 2021 г.
- CVE-2022-151740В плане
3.2.1 EXECUTION WITH UNNECESSARY PRIVILEGES CWE-250
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %illumina · local run manager24 июн. 2022 г.
- CVE-2026-460640В плане
GeoVision ERM Improper Privilege Assignment Leads to SYSTEM-Level Privilege
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %geovision · gv-edge recording manager22 мар. 2026 г.
- CVE-2025-3451539Наблюдать
Ilevia EVE X1 Server 4.7.18.0.eden Root Privilege Escalation
КритическаяCVSS 9,3Эксплойта нетEPSS 8 %ilevia · eve x1 server firmware16 окт. 2025 г.
- CVE-2024-2542139Наблюдать
An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %igniterealtime · openfire26 мар. 2024 г.
- CVE-2023-5203039Наблюдать
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setOpModeCfg functio
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %totolink · a3700r firmware11 янв. 2024 г.
- CVE-2023-466239Наблюдать
RCE in Saphira Connect
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %adobe · connect15 сент. 2023 г.
- CVE-2024-2714339Наблюдать
Pre-authenticated Remote Code Execution
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %toshiba tec corporation · toshiba tec e-studio multi-function peripheral (mfp)13 июн. 2024 г.
- CVE-2022-263439Наблюдать
Digi ConnectPort X2D
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %digi · connectport x2d firmware10 авг. 2022 г.
- CVE-2023-196639Наблюдать
Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %illumina · iscan firmware28 апр. 2023 г.
- CVE-2022-4454439Наблюдать
Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mahara · mahara6 нояб. 2022 г.
- CVE-2026-7250839Наблюдать
Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke serviceaccounts bound to wildcard rbac (*/*/*)
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %red hat · red hat advanced cluster management for kubernetes 2.1112 авг. 2026 г.
- CVE-2025-3322439Наблюдать
NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nvidia · isaac launchable23 дек. 2025 г.
- CVE-2025-3244539Наблюдать
Users can gain privileged access to the host system and cluster with EventSource and Sensor CR
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %argoproj · argo-events15 апр. 2025 г.
- CVE-2022-3253539Наблюдать
Web server runs as root
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bosch · pra-es8p2s firmware23 июн. 2022 г.
- CVE-2026-3487739Наблюдать
An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %arm · mbed tls2 апр. 2026 г.
- CVE-2023-4559239Наблюдать
A CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary being executed with the
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ailux · imx65 мар. 2024 г.
- CVE-2025-3322339Наблюдать
NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nvidia · isaac launchable23 дек. 2025 г.
- CVE-2024-333039Наблюдать
Spotfire Remote Code Execution Vulnerability
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %spotfire · spotfire analyst27 июн. 2024 г.
- CVE-2025-5711939Наблюдать
An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %phpgurukul · online library management system16 сент. 2025 г.
- CVE-2025-1337539Наблюдать
IBM Common Cryptographic Architecture Arbitrary Command Execution
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ibm · common cryptographic architecture4 февр. 2026 г.