CWE-268 · 22 записей
Privilege Chaining
CVE этого класса
22 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2024-4877Эксплойта нет | OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI copenvpn · openvpn · CWE-268 | Высокая8,8 | — | 0,4 % | 3 апр. 2025 г. |
35Наблюдать | CVE-2023-0759Эксплойта нет | Privilege Chaining in cockpit-hq/cockpitagentejo · cockpit · CWE-268 | Высокая8,8 | — | 0,3 % | 9 февр. 2023 г. |
35Наблюдать | CVE-2023-0971Эксплойта нет | Command Authentication Bypass in Z/IP Gatewaysilabs · z\/ip gateway sdk · CWE-268 | Высокая8,8 | — | 0,3 % | 21 июн. 2023 г. |
34Наблюдать | CVE-2026-32325Эксплойта нет | Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier.fsas technologies inc. · serverview agents for windows · CWE-268 | Высокая8,5 | — | 0,1 % | 1 июн. 2026 г. |
34Наблюдать | CVE-2025-7973Эксплойта нет | Rockwell Automation FactoryTalk® ViewPoint Privilege Escalation Vulnerabilityrockwell automation · factorytalk® viewpoint · CWE-268 | Высокая8,5 | — | 0,1 % | 14 авг. 2025 г. |
34Наблюдать | CVE-2025-64701Эксплойта нет | QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability, which may allow a user who can log in to aqualitysoft corporation · qnd premium/advance/standard · CWE-268 | Высокая8,5 | — | 0,1 % | 11 дек. 2025 г. |
32Наблюдать | CVE-2024-1299Эксплойта нет | Privilege Chaining in GitLabgitlab · gitlab · CWE-268 | Высокая8,1 | — | 0,7 % | 6 мар. 2024 г. |
31Наблюдать | CVE-2025-49741Proof of concept | Microsoft Edge (Chromium-based) Information Disclosure Vulnerabilitymicrosoft · edge chromium · CWE-268 | Высокая7,5 | — | 3,9 % | 1 июл. 2025 г. |
31Наблюдать | CVE-2019-3844Proof of concept | It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, whichsystemd project · systemd · CWE-268 | Высокая7,8 | — | 0,9 % | 26 апр. 2019 г. |
31Наблюдать | CVE-2023-5839Эксплойта нет | Privilege Chaining in hestiacp/hestiacphestiacp · control panel · CWE-268 | Высокая7,8 | — | 0,3 % | 28 окт. 2023 г. |
31Наблюдать | CVE-2026-3888Proof of concept | Local Privilege Escalation in snapdcanonical · ubuntu linux · CWE-268 | Высокая7,8 | — | 0,2 % | 17 мар. 2026 г. |
31Наблюдать | CVE-2024-47045Эксплойта нет | Privilege chaining issue exists in the installer of e-Tax software(common program).national tax agency · the installer of e-tax software(common program) · CWE-268 | Высокая7,8 | — | 0,1 % | 26 сент. 2024 г. |
30Наблюдать | CVE-2025-36124Эксплойта нет | IBM WebSphere Application Server Liberty bypass securityibm · websphere application server · CWE-268 | Высокая7,5 | — | 0,4 % | 12 авг. 2025 г. |
28Наблюдать | CVE-2025-0889Эксплойта нет | Privilege Management for Windows – Elevation of Privilegebeyondtrust · privilege management for windows · CWE-268 | Высокая7,2 | — | 0,2 % | 26 февр. 2025 г. |
28Наблюдать | CVE-2025-2297Эксплойта нет | Privilege Management for Windows - Elevation of Privilegebeyondtrust · privilege management for windows · CWE-268 | Высокая7,2 | — | 0,1 % | 28 июл. 2025 г. |
26Наблюдать | CVE-2024-1250Эксплойта нет | Privilege Chaining in GitLabgitlab · gitlab · CWE-268 | Средняя6,5 | — | 0,5 % | 12 февр. 2024 г. |
26Наблюдать | CVE-2023-2250Эксплойта нет | A flaw was found in the Open Cluster Management (OCM) when a user have access to the worker nodes which has the cluster-manager-registrationlinuxfoundation · open cluster management · CWE-268 | Средняя6,7 | — | 0,2 % | 24 апр. 2023 г. |
26Наблюдать | GHSA-xpff-c35g-j3crЭксплойта нет | silverstripe/framework Privilege Escalation Risk in Member Edit formPackagist · silverstripe/framework · CWE-268 | Средняя6,5 | — | — | 27 мая 2024 г. |
24Наблюдать | CVE-2025-32955Эксплойта нет | Harden-Runner Evasion of 'disable-sudo' policystep-security · harden-runner · CWE-268 | Средняя6,0 | — | 0,2 % | 21 апр. 2025 г. |
20Наблюдать | CVE-2025-20112Эксплойта нет | Cisco Unified Communications Products Privilege Escalation Vulnerabilitycisco · cisco emergency responder · CWE-268 | Средняя5,1 | — | 0,1 % | 21 мая 2025 г. |
19Наблюдать | CVE-2023-20194Эксплойта нет | A vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operatincisco · identity services engine · CWE-268 | Средняя4,9 | — | 0,7 % | 7 сент. 2023 г. |
19Наблюдать | CVE-2022-1003Эксплойта нет | Sysadmin can override existing configs & bypass restrictions like EnableUploadsmattermost · mattermost · CWE-268 | Средняя4,9 | — | 0,5 % | 18 мар. 2022 г. |
- CVE-2024-487735Наблюдать
OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI c
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %openvpn · openvpn3 апр. 2025 г.
- CVE-2023-075935Наблюдать
Privilege Chaining in cockpit-hq/cockpit
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %agentejo · cockpit9 февр. 2023 г.
- CVE-2023-097135Наблюдать
Command Authentication Bypass in Z/IP Gateway
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %silabs · z\/ip gateway sdk21 июн. 2023 г.
- CVE-2026-3232534Наблюдать
Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier.
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %fsas technologies inc. · serverview agents for windows1 июн. 2026 г.
- CVE-2025-797334Наблюдать
Rockwell Automation FactoryTalk® ViewPoint Privilege Escalation Vulnerability
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %rockwell automation · factorytalk® viewpoint14 авг. 2025 г.
- CVE-2025-6470134Наблюдать
QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability, which may allow a user who can log in to a
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %qualitysoft corporation · qnd premium/advance/standard11 дек. 2025 г.
- CVE-2024-129932Наблюдать
Privilege Chaining in GitLab
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %gitlab · gitlab6 мар. 2024 г.
- CVE-2025-4974131Наблюдать
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %microsoft · edge chromium1 июл. 2025 г.
- CVE-2019-384431Наблюдать
It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %systemd project · systemd26 апр. 2019 г.
- CVE-2023-583931Наблюдать
Privilege Chaining in hestiacp/hestiacp
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %hestiacp · control panel28 окт. 2023 г.
- CVE-2026-388831Наблюдать
Local Privilege Escalation in snapd
ВысокаяCVSS 7,8Proof of conceptEPSS 0 %canonical · ubuntu linux17 мар. 2026 г.
- CVE-2024-4704531Наблюдать
Privilege chaining issue exists in the installer of e-Tax software(common program).
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %national tax agency · the installer of e-tax software(common program)26 сент. 2024 г.
- CVE-2025-3612430Наблюдать
IBM WebSphere Application Server Liberty bypass security
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %ibm · websphere application server12 авг. 2025 г.
- CVE-2025-088928Наблюдать
Privilege Management for Windows – Elevation of Privilege
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %beyondtrust · privilege management for windows26 февр. 2025 г.
- CVE-2025-229728Наблюдать
Privilege Management for Windows - Elevation of Privilege
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %beyondtrust · privilege management for windows28 июл. 2025 г.
- CVE-2024-125026Наблюдать
Privilege Chaining in GitLab
СредняяCVSS 6,5Эксплойта нетEPSS 1 %gitlab · gitlab12 февр. 2024 г.
- CVE-2023-225026Наблюдать
A flaw was found in the Open Cluster Management (OCM) when a user have access to the worker nodes which has the cluster-manager-registration
СредняяCVSS 6,7Эксплойта нетEPSS 0 %linuxfoundation · open cluster management24 апр. 2023 г.
- GHSA-xpff-c35g-j3cr26Наблюдать
silverstripe/framework Privilege Escalation Risk in Member Edit form
СредняяCVSS 6,5Эксплойта нетPackagist · silverstripe/framework27 мая 2024 г.
- CVE-2025-3295524Наблюдать
Harden-Runner Evasion of 'disable-sudo' policy
СредняяCVSS 6,0Эксплойта нетEPSS 0 %step-security · harden-runner21 апр. 2025 г.
- CVE-2025-2011220Наблюдать
Cisco Unified Communications Products Privilege Escalation Vulnerability
СредняяCVSS 5,1Эксплойта нетEPSS 0 %cisco · cisco emergency responder21 мая 2025 г.
- CVE-2023-2019419Наблюдать
A vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operatin
СредняяCVSS 4,9Эксплойта нетEPSS 1 %cisco · identity services engine7 сент. 2023 г.
- CVE-2022-100319Наблюдать
Sysadmin can override existing configs & bypass restrictions like EnableUploads
СредняяCVSS 4,9Эксплойта нетEPSS 1 %mattermost · mattermost18 мар. 2022 г.