Перейти к содержимому
Noroxi

CWE-267 · 65 записей

Privilege Defined With Unsafe Actions

CVE этого класса

65 записей

  • CVE-2025-41244
    64На этой неделе

    VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 8 %

    vmware · aria operations29 сент. 2025 г.

  • CVE-2026-29646
    39Наблюдать

    In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to the supervisor interr

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    20 апр. 2026 г.

  • CVE-2024-42365
    36Наблюдать

    Asterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplan

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 5 %

    asterisk · asterisk8 авг. 2024 г.

  • CVE-2020-29396
    36Наблюдать

    A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    odoo · odoo22 дек. 2020 г.

  • CVE-2021-44547
    36Наблюдать

    A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading t

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    odoo · odoo25 апр. 2023 г.

  • CVE-2026-10090
    36Наблюдать

    Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-ad

    КритическаяCVSS 9,0Эксплойта нетEPSS 1 %

    red hat · red hat advanced cluster management for kubernetes 2.115 авг. 2026 г.

  • CVE-2021-32739
    35Наблюдать

    Results of queries for ApiListener objects include the ticket salt which allows in turn to steal (more privileged) identities

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    icinga · icinga15 июл. 2021 г.

  • CVE-2025-53900
    35Наблюдать

    Kiteworks MFT has a Privilege Defined With Unsafe Actions

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    accellion · kiteworks managed file transfer28 нояб. 2025 г.

  • CVE-2024-55968
    35Наблюдать

    An issue was discovered in DTEX DEC-M (DTEX Forwarder) 6.1.1.

    ВысокаяCVSS 8,8Proof of conceptEPSS 1 %

    28 янв. 2025 г.

  • CVE-2025-23015
    35Наблюдать

    Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    apache · cassandra4 февр. 2025 г.

  • CVE-2023-2983
    35Наблюдать

    Privilege Defined With Unsafe Actions in pimcore/pimcore

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    pimcore · pimcore30 мая 2023 г.

  • CVE-2026-18951
    35Наблюдать

    Odh-training-operator-rhel9: [trainer v2 security] trn-02: rhoai overlay aggregates trainjobs crud into standard edit clusterrole

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    red hat · red hat openshift ai 3.310 авг. 2026 г.

  • CVE-2023-32457
    35Наблюдать

    Dell PowerScale OneFS, versions 8.2.2.x-9.5.0.x, contains an improper privilege management vulnerability.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    dell · powerscale onefs29 авг. 2023 г.

  • CVE-2023-41966
    35Наблюдать

    Sielco Radio Link and Analog FM Transmitters Privilege Defined With Unsafe Actions

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sielco · analog fm transmitter exc5000gx firmware26 окт. 2023 г.

  • CVE-2025-26467
    35Наблюдать

    Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only)

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    apache · cassandra25 авг. 2025 г.

  • CVE-2025-14349
    35Наблюдать

    Business Logic Error in Universal Software's FlexCity/Kiosk

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    uni-yaz · flexcity13 февр. 2026 г.

  • CVE-2025-7691
    35Наблюдать

    Privilege Defined With Unsafe Actions in GitLab

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    gitlab · gitlab26 сент. 2025 г.

  • CVE-2026-27314
    35Наблюдать

    Apache Cassandra: Privilege escalation via ADD IDENTITY authorization bypass

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    apache · cassandra7 апр. 2026 г.

  • CVE-2025-36255
    35Наблюдать

    DS8900F and DS8A00 Privilege Escalation

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    ibm · ds8900f firmware19 авг. 2026 г.

  • CVE-2026-0945
    35Наблюдать

    Role Delegation - Moderately critical - Access bypass - SA-CONTRIB-2026-002

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    role delegation project · role delegation4 февр. 2026 г.

  • CVE-2021-23166
    34Наблюдать

    A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and w

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    odoo · odoo25 апр. 2023 г.

  • CVE-2021-23186
    34Наблюдать

    A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access and

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    odoo · odoo25 апр. 2023 г.

  • CVE-2023-43746
    34Наблюдать

    BIG-IP Appliance mode external monitor vulnerability

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    f5 · big-ip access policy manager10 окт. 2023 г.

  • CVE-2026-23526
    34Наблюдать

    CVAT vulnerable to privilege escalation of users with staff status

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    cvat · computer vision annotation tool21 янв. 2026 г.

  • CVE-2026-42406
    34Наблюдать

    BIG-IP and BIG-IQ privilege escalation vulnerability

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    f5 · big-ip access policy manager13 мая 2026 г.

Все классы уязвимостей