CWE-267 · 65 записей
Privilege Defined With Unsafe Actions
CVE этого класса
65 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
64На этой неделе | CVE-2025-41244Готовый эксплойт | VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)vmware · aria operations · CWE-267 | Высокая7,8 | KEV | 8,4 % | 29 сент. 2025 г. |
39Наблюдать | CVE-2026-29646Эксплойта нет | In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to the supervisor interrCWE-267 | Критическая9,8 | — | 0,7 % | 20 апр. 2026 г. |
36Наблюдать | CVE-2024-42365Готовый эксплойт | Asterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplanasterisk · asterisk · CWE-267 | Высокая8,8 | — | 4,7 % | 8 авг. 2024 г. |
36Наблюдать | CVE-2020-29396Эксплойта нет | A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows odoo · odoo · CWE-267 | Высокая8,8 | — | 3,2 % | 22 дек. 2020 г. |
36Наблюдать | CVE-2021-44547Эксплойта нет | A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading todoo · odoo · CWE-267 | Критическая9,1 | — | 0,7 % | 25 апр. 2023 г. |
36Наблюдать | CVE-2026-10090Эксплойта нет | Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-adred hat · red hat advanced cluster management for kubernetes 2.11 · CWE-267 | Критическая9,0 | — | 0,6 % | 5 авг. 2026 г. |
35Наблюдать | CVE-2021-32739Эксплойта нет | Results of queries for ApiListener objects include the ticket salt which allows in turn to steal (more privileged) identitiesicinga · icinga · CWE-267 | Высокая8,8 | — | 1,1 % | 15 июл. 2021 г. |
35Наблюдать | CVE-2025-53900Эксплойта нет | Kiteworks MFT has a Privilege Defined With Unsafe Actionsaccellion · kiteworks managed file transfer · CWE-267 | Высокая8,8 | — | 1,1 % | 28 нояб. 2025 г. |
35Наблюдать | CVE-2024-55968Proof of concept | An issue was discovered in DTEX DEC-M (DTEX Forwarder) 6.1.1.CWE-267 | Высокая8,8 | — | 1,0 % | 28 янв. 2025 г. |
35Наблюдать | CVE-2025-23015Эксплойта нет | Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actionsapache · cassandra · CWE-267 | Высокая8,8 | — | 1,0 % | 4 февр. 2025 г. |
35Наблюдать | CVE-2023-2983Эксплойта нет | Privilege Defined With Unsafe Actions in pimcore/pimcorepimcore · pimcore · CWE-267 | Высокая8,8 | — | 0,9 % | 30 мая 2023 г. |
35Наблюдать | CVE-2026-18951Эксплойта нет | Odh-training-operator-rhel9: [trainer v2 security] trn-02: rhoai overlay aggregates trainjobs crud into standard edit clusterrolered hat · red hat openshift ai 3.3 · CWE-267 | Высокая8,8 | — | 0,9 % | 10 авг. 2026 г. |
35Наблюдать | CVE-2023-32457Эксплойта нет | Dell PowerScale OneFS, versions 8.2.2.x-9.5.0.x, contains an improper privilege management vulnerability.dell · powerscale onefs · CWE-267 | Высокая8,8 | — | 0,6 % | 29 авг. 2023 г. |
35Наблюдать | CVE-2023-41966Эксплойта нет | Sielco Radio Link and Analog FM Transmitters Privilege Defined With Unsafe Actionssielco · analog fm transmitter exc5000gx firmware · CWE-267 | Высокая8,8 | — | 0,6 % | 26 окт. 2023 г. |
35Наблюдать | CVE-2025-26467Эксплойта нет | Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only)apache · cassandra · CWE-267 | Высокая8,8 | — | 0,5 % | 25 авг. 2025 г. |
35Наблюдать | CVE-2025-14349Эксплойта нет | Business Logic Error in Universal Software's FlexCity/Kioskuni-yaz · flexcity · CWE-267 | Высокая8,8 | — | 0,4 % | 13 февр. 2026 г. |
35Наблюдать | CVE-2025-7691Эксплойта нет | Privilege Defined With Unsafe Actions in GitLabgitlab · gitlab · CWE-267 | Высокая8,8 | — | 0,4 % | 26 сент. 2025 г. |
35Наблюдать | CVE-2026-27314Эксплойта нет | Apache Cassandra: Privilege escalation via ADD IDENTITY authorization bypassapache · cassandra · CWE-267 | Высокая8,8 | — | 0,3 % | 7 апр. 2026 г. |
35Наблюдать | CVE-2025-36255Эксплойта нет | DS8900F and DS8A00 Privilege Escalationibm · ds8900f firmware · CWE-267 | Высокая8,8 | — | 0,2 % | 19 авг. 2026 г. |
35Наблюдать | CVE-2026-0945Эксплойта нет | Role Delegation - Moderately critical - Access bypass - SA-CONTRIB-2026-002role delegation project · role delegation · CWE-267 | Высокая8,8 | — | 0,2 % | 4 февр. 2026 г. |
34Наблюдать | CVE-2021-23166Эксплойта нет | A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and wodoo · odoo · CWE-267 | Высокая8,7 | — | 0,6 % | 25 апр. 2023 г. |
34Наблюдать | CVE-2021-23186Эксплойта нет | A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access andodoo · odoo · CWE-267 | Высокая8,7 | — | 0,6 % | 25 апр. 2023 г. |
34Наблюдать | CVE-2023-43746Эксплойта нет | BIG-IP Appliance mode external monitor vulnerabilityf5 · big-ip access policy manager · CWE-267 | Высокая8,7 | — | 0,4 % | 10 окт. 2023 г. |
34Наблюдать | CVE-2026-23526Эксплойта нет | CVAT vulnerable to privilege escalation of users with staff statuscvat · computer vision annotation tool · CWE-267 | Высокая8,5 | — | 0,3 % | 21 янв. 2026 г. |
34Наблюдать | CVE-2026-42406Эксплойта нет | BIG-IP and BIG-IQ privilege escalation vulnerabilityf5 · big-ip access policy manager · CWE-267 | Высокая8,5 | — | 0,3 % | 13 мая 2026 г. |
- CVE-2025-4124464На этой неделе
VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 8 %vmware · aria operations29 сент. 2025 г.
- CVE-2026-2964639Наблюдать
In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to the supervisor interr
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %20 апр. 2026 г.
- CVE-2024-4236536Наблюдать
Asterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplan
ВысокаяCVSS 8,8Готовый эксплойтEPSS 5 %asterisk · asterisk8 авг. 2024 г.
- CVE-2020-2939636Наблюдать
A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %odoo · odoo22 дек. 2020 г.
- CVE-2021-4454736Наблюдать
A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading t
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %odoo · odoo25 апр. 2023 г.
- CVE-2026-1009036Наблюдать
Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-ad
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %red hat · red hat advanced cluster management for kubernetes 2.115 авг. 2026 г.
- CVE-2021-3273935Наблюдать
Results of queries for ApiListener objects include the ticket salt which allows in turn to steal (more privileged) identities
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %icinga · icinga15 июл. 2021 г.
- CVE-2025-5390035Наблюдать
Kiteworks MFT has a Privilege Defined With Unsafe Actions
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %accellion · kiteworks managed file transfer28 нояб. 2025 г.
- CVE-2024-5596835Наблюдать
An issue was discovered in DTEX DEC-M (DTEX Forwarder) 6.1.1.
ВысокаяCVSS 8,8Proof of conceptEPSS 1 %28 янв. 2025 г.
- CVE-2025-2301535Наблюдать
Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %apache · cassandra4 февр. 2025 г.
- CVE-2023-298335Наблюдать
Privilege Defined With Unsafe Actions in pimcore/pimcore
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %pimcore · pimcore30 мая 2023 г.
- CVE-2026-1895135Наблюдать
Odh-training-operator-rhel9: [trainer v2 security] trn-02: rhoai overlay aggregates trainjobs crud into standard edit clusterrole
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %red hat · red hat openshift ai 3.310 авг. 2026 г.
- CVE-2023-3245735Наблюдать
Dell PowerScale OneFS, versions 8.2.2.x-9.5.0.x, contains an improper privilege management vulnerability.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %dell · powerscale onefs29 авг. 2023 г.
- CVE-2023-4196635Наблюдать
Sielco Radio Link and Analog FM Transmitters Privilege Defined With Unsafe Actions
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sielco · analog fm transmitter exc5000gx firmware26 окт. 2023 г.
- CVE-2025-2646735Наблюдать
Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only)
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %apache · cassandra25 авг. 2025 г.
- CVE-2025-1434935Наблюдать
Business Logic Error in Universal Software's FlexCity/Kiosk
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %uni-yaz · flexcity13 февр. 2026 г.
- CVE-2025-769135Наблюдать
Privilege Defined With Unsafe Actions in GitLab
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %gitlab · gitlab26 сент. 2025 г.
- CVE-2026-2731435Наблюдать
Apache Cassandra: Privilege escalation via ADD IDENTITY authorization bypass
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %apache · cassandra7 апр. 2026 г.
- CVE-2025-3625535Наблюдать
DS8900F and DS8A00 Privilege Escalation
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %ibm · ds8900f firmware19 авг. 2026 г.
- CVE-2026-094535Наблюдать
Role Delegation - Moderately critical - Access bypass - SA-CONTRIB-2026-002
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %role delegation project · role delegation4 февр. 2026 г.
- CVE-2021-2316634Наблюдать
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and w
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %odoo · odoo25 апр. 2023 г.
- CVE-2021-2318634Наблюдать
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access and
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %odoo · odoo25 апр. 2023 г.
- CVE-2023-4374634Наблюдать
BIG-IP Appliance mode external monitor vulnerability
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %f5 · big-ip access policy manager10 окт. 2023 г.
- CVE-2026-2352634Наблюдать
CVAT vulnerable to privilege escalation of users with staff status
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %cvat · computer vision annotation tool21 янв. 2026 г.
- CVE-2026-4240634Наблюдать
BIG-IP and BIG-IQ privilege escalation vulnerability
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %f5 · big-ip access policy manager13 мая 2026 г.