CWE-272 · 24 записей
Least Privilege Violation
CVE этого класса
24 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2025-59106Эксплойта нет | Web Server Running with Root Privileges in dormakaba access managerdormakabagroup · dormakaba access manager 9200-k7 firmware · CWE-272 | Высокая8,8 | — | 0,8 % | 26 янв. 2026 г. |
35Наблюдать | CVE-2025-7722Эксплойта нет | Social Streams <= 1.2.1 - Authenticated (Subscriber+) Privilege Escalationsteverio · social streams · CWE-272 | Высокая8,8 | — | 0,4 % | 22 июл. 2025 г. |
34Наблюдать | CVE-2026-39459Эксплойта нет | iControl REST and tmsh vulnerabilityf5 · big-ip access policy manager · CWE-272 | Высокая8,6 | — | 0,5 % | 13 мая 2026 г. |
34Наблюдать | CVE-2025-9711Эксплойта нет | Privilege escalation in Brocade Fabric OS before 9.2.1c3, and 9.2.2 though 9.2.2bbroadcom · fabric operating system · CWE-272 | Высокая8,5 | — | 0,1 % | 3 февр. 2026 г. |
33Наблюдать | CVE-2024-35204Эксплойта нет | Veritas System Recovery before 23.3_Hotfix has incorrect permissions for the Veritas System Recovery folder, and thus low-privileged users cCWE-272 | Высокая8,4 | — | 0,2 % | 14 мая 2024 г. |
32Наблюдать | CVE-2025-47809Эксплойта нет | Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot).wibu · codemeter · CWE-272 | Высокая8,2 | — | 0,2 % | 15 мая 2025 г. |
31Наблюдать | CVE-2024-27165Эксплойта нет | Local Privilege Escalationtoshiba tec corporation · toshiba tec e-studio multi-function peripheral (mfp) · CWE-272 | Высокая7,8 | — | 0,2 % | 14 июн. 2024 г. |
31Наблюдать | CVE-2024-28824Эксплойта нет | Privilege escalation in mk_informix plugincheckmk · checkmk · CWE-272 | Высокая7,8 | — | 0,2 % | 22 мар. 2024 г. |
31Наблюдать | CVE-2023-28047Эксплойта нет | Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder creation vulnerability during installation.dell · display manager · CWE-272 | Высокая7,8 | — | 0,2 % | 20 апр. 2023 г. |
31Наблюдать | CVE-2023-32451Эксплойта нет | Dell Display Manager application, version 2.1.1.17, contains a vulnerability that low privilege user can execute malicious code during instdell · display manager · CWE-272 | Высокая7,8 | — | 0,2 % | 6 февр. 2024 г. |
31Наблюдать | CVE-2026-32655Эксплойта нет | Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain a Least Privilege Violation vulnerability.dell · alienware command center · CWE-272 | Высокая7,8 | — | 0,1 % | 27 апр. 2026 г. |
29Наблюдать | CVE-2025-49144Proof of concept | Notepad++ Privilege Escalation in Installer via Uncontrolled Executable Search Pathnotepad-plus-plus · notepad-plus-plus · CWE-272 | Высокая7,3 | — | 0,7 % | 23 июн. 2025 г. |
29Наблюдать | CVE-2026-59915Эксплойта нет | Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege Violation vulnerability.dell · alienware command center (awcc) · CWE-272 | Высокая7,3 | — | 0,1 % | 18 авг. 2026 г. |
28Наблюдать | CVE-2025-1384Эксплойта нет | Least Privilege Violation Vulnerability in the communications functions of NJ/NX-series Machine Automation Controllersomron corporation · machine automation controller nj-series · CWE-272 | Высокая7,0 | — | 0,2 % | 13 июл. 2025 г. |
28Наблюдать | CVE-2023-28046Эксплойта нет | Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder deletion vulnerability during uninstallation A local ldell · display manager · CWE-272 | Высокая7,1 | — | 0,1 % | 6 апр. 2023 г. |
26Наблюдать | CVE-2024-0798Эксплойта нет | Privilege Escalation in mintplex-labs/anything-llmmintplexlabs · anythingllm · CWE-272 | Средняя6,5 | — | 0,6 % | 26 февр. 2024 г. |
26Наблюдать | CVE-2025-62299Эксплойта нет | HCL IntelliOps Event Management is affected by multiple security vulnerabilities.hcl software · iem · CWE-272 | Средняя6,6 | — | 0,3 % | 20 авг. 2026 г. |
26Наблюдать | CVE-2025-68267Эксплойта нет | In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installajetbrains · teamcity · CWE-272 | Средняя6,5 | — | 0,2 % | 16 дек. 2025 г. |
26Наблюдать | CVE-2024-0638Эксплойта нет | Privilege escalation in mk_oracle pluginscheckmk · checkmk · CWE-272 | Средняя6,7 | — | 0,2 % | 22 мар. 2024 г. |
24Наблюдать | CVE-2026-49500Эксплойта нет | Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an Improper Link Resolution Before File Access ('Link Following')dell · alienware command center (awcc · CWE-272 | Средняя6,0 | — | 0,1 % | 18 авг. 2026 г. |
20Наблюдать | CVE-2024-28829Эксплойта нет | Privilege escalation in mk_informix plugincheckmk · checkmk · CWE-272 | Средняя5,2 | — | 0,2 % | 20 авг. 2024 г. |
17Наблюдать | CVE-2026-23634Эксплойта нет | Pepr Overly Permissive RBAC ClusterRole in Admin Modedefenseunicorns · pepr · CWE-272 | Средняя4,3 | — | 0,3 % | 16 янв. 2026 г. |
13Наблюдать | CVE-2026-79944Эксплойта нет | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Least Privilege Videll · secure connect gateway · CWE-272 | Низкая3,4 | — | 0,1 % | 9 сент. 2026 г. |
13Наблюдать | CVE-2026-79693Эксплойта нет | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Least Privilege Videll · secure connect gateway · CWE-272 | Низкая3,4 | — | 0,1 % | 9 сент. 2026 г. |
- CVE-2025-5910635Наблюдать
Web Server Running with Root Privileges in dormakaba access manager
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %dormakabagroup · dormakaba access manager 9200-k7 firmware26 янв. 2026 г.
- CVE-2025-772235Наблюдать
Social Streams <= 1.2.1 - Authenticated (Subscriber+) Privilege Escalation
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %steverio · social streams22 июл. 2025 г.
- CVE-2026-3945934Наблюдать
iControl REST and tmsh vulnerability
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %f5 · big-ip access policy manager13 мая 2026 г.
- CVE-2025-971134Наблюдать
Privilege escalation in Brocade Fabric OS before 9.2.1c3, and 9.2.2 though 9.2.2b
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %broadcom · fabric operating system3 февр. 2026 г.
- CVE-2024-3520433Наблюдать
Veritas System Recovery before 23.3_Hotfix has incorrect permissions for the Veritas System Recovery folder, and thus low-privileged users c
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %14 мая 2024 г.
- CVE-2025-4780932Наблюдать
Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot).
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %wibu · codemeter15 мая 2025 г.
- CVE-2024-2716531Наблюдать
Local Privilege Escalation
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %toshiba tec corporation · toshiba tec e-studio multi-function peripheral (mfp)14 июн. 2024 г.
- CVE-2024-2882431Наблюдать
Privilege escalation in mk_informix plugin
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %checkmk · checkmk22 мар. 2024 г.
- CVE-2023-2804731Наблюдать
Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder creation vulnerability during installation.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %dell · display manager20 апр. 2023 г.
- CVE-2023-3245131Наблюдать
Dell Display Manager application, version 2.1.1.17, contains a vulnerability that low privilege user can execute malicious code during inst
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %dell · display manager6 февр. 2024 г.
- CVE-2026-3265531Наблюдать
Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain a Least Privilege Violation vulnerability.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %dell · alienware command center27 апр. 2026 г.
- CVE-2025-4914429Наблюдать
Notepad++ Privilege Escalation in Installer via Uncontrolled Executable Search Path
ВысокаяCVSS 7,3Proof of conceptEPSS 1 %notepad-plus-plus · notepad-plus-plus23 июн. 2025 г.
- CVE-2026-5991529Наблюдать
Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege Violation vulnerability.
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %dell · alienware command center (awcc)18 авг. 2026 г.
- CVE-2025-138428Наблюдать
Least Privilege Violation Vulnerability in the communications functions of NJ/NX-series Machine Automation Controllers
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %omron corporation · machine automation controller nj-series13 июл. 2025 г.
- CVE-2023-2804628Наблюдать
Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder deletion vulnerability during uninstallation A local l
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %dell · display manager6 апр. 2023 г.
- CVE-2024-079826Наблюдать
Privilege Escalation in mintplex-labs/anything-llm
СредняяCVSS 6,5Эксплойта нетEPSS 1 %mintplexlabs · anythingllm26 февр. 2024 г.
- CVE-2025-6229926Наблюдать
HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
СредняяCVSS 6,6Эксплойта нетEPSS 0 %hcl software · iem20 авг. 2026 г.
- CVE-2025-6826726Наблюдать
In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installa
СредняяCVSS 6,5Эксплойта нетEPSS 0 %jetbrains · teamcity16 дек. 2025 г.
- CVE-2024-063826Наблюдать
Privilege escalation in mk_oracle plugins
СредняяCVSS 6,7Эксплойта нетEPSS 0 %checkmk · checkmk22 мар. 2024 г.
- CVE-2026-4950024Наблюдать
Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an Improper Link Resolution Before File Access ('Link Following')
СредняяCVSS 6,0Эксплойта нетEPSS 0 %dell · alienware command center (awcc18 авг. 2026 г.
- CVE-2024-2882920Наблюдать
Privilege escalation in mk_informix plugin
СредняяCVSS 5,2Эксплойта нетEPSS 0 %checkmk · checkmk20 авг. 2024 г.
- CVE-2026-2363417Наблюдать
Pepr Overly Permissive RBAC ClusterRole in Admin Mode
СредняяCVSS 4,3Эксплойта нетEPSS 0 %defenseunicorns · pepr16 янв. 2026 г.
- CVE-2026-7994413Наблюдать
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Least Privilege Vi
НизкаяCVSS 3,4Эксплойта нетEPSS 0 %dell · secure connect gateway9 сент. 2026 г.
- CVE-2026-7969313Наблюдать
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Least Privilege Vi
НизкаяCVSS 3,4Эксплойта нетEPSS 0 %dell · secure connect gateway9 сент. 2026 г.