CWE-274 · 37 записей
Improper Handling of Insufficient Privileges
CVE этого класса
37 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2025-20156Эксплойта нет | Cisco Meeting Management Client-Server Privilege Escalation Vulnerabilitycisco · meeting management · CWE-274 | Критическая9,9 | — | 1,2 % | 22 янв. 2025 г. |
39Наблюдать | CVE-2022-45101Эксплойта нет | Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS.dell · emc powerscale onefs · CWE-274 | Критическая9,8 | — | 0,8 % | 1 февр. 2023 г. |
39Наблюдать | CVE-2023-39375Эксплойта нет | SiberianCMS - CWE-274: Improper Handling of Insufficient Privilegessiberiancms · siberiancms · CWE-274 | Критическая9,8 | — | 0,8 % | 27 сент. 2023 г. |
39Наблюдать | CVE-2022-0668Эксплойта нет | JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted rjfrog · artifactory · CWE-274 | Критическая9,8 | — | 0,6 % | 8 янв. 2023 г. |
35Наблюдать | CVE-2023-35928Эксплойта нет | Nextcloud user scoped external storage can be used to gather credentials of other usersnextcloud · nextcloud server · CWE-274 | Высокая8,8 | — | 1,0 % | 23 июн. 2023 г. |
35Наблюдать | CVE-2020-7283Proof of concept | Privilege Escalation vulnerability in McAfee Total Protection (MTP)mcafee · total protection · CWE-274 | Высокая8,8 | — | 0,6 % | 3 июл. 2020 г. |
35Наблюдать | CVE-2024-21648Эксплойта нет | XWiki has no right protection on rollback actionxwiki · xwiki · CWE-274 | Высокая8,8 | — | 0,5 % | 8 янв. 2024 г. |
35Наблюдать | CVE-2024-0105Эксплойта нет | NVIDIA ConnectX Firmware contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue.nvidia · connectx4 · CWE-274 | Высокая8,9 | — | 0,3 % | 1 нояб. 2024 г. |
34Наблюдать | CVE-2024-0106Эксплойта нет | NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability where an attacker may cause an improper nvidia · bluefield 1 · CWE-274 | Высокая8,7 | — | 0,2 % | 1 нояб. 2024 г. |
33Наблюдать | CVE-2020-7267Эксплойта нет | Privilege Escalation vulnerability through symbolic links in VSELmcafee · virusscan enterprise · CWE-274 | Высокая8,4 | — | 0,3 % | 8 мая 2020 г. |
33Наблюдать | CVE-2020-7264Эксплойта нет | Privilege Escalation vulnerability through symbolic links in ENS for Windowsmcafee · endpoint security · CWE-274 | Высокая8,4 | — | 0,3 % | 8 мая 2020 г. |
33Наблюдать | CVE-2020-7265Эксплойта нет | Privilege Escalation vulnerability through symbolic links in ENSMmcafee · endpoint security · CWE-274 | Высокая8,4 | — | 0,3 % | 8 мая 2020 г. |
33Наблюдать | CVE-2020-7266Эксплойта нет | Privilege Escalation vulnerability through symbolic links in VSE for Windowsmcafee · virusscan enterprise · CWE-274 | Высокая8,4 | — | 0,3 % | 8 мая 2020 г. |
31Наблюдать | CVE-2020-24676Эксплойта нет | Insecure Windows Services in Symphony Plusabb · symphony \+ historian · CWE-274 | Высокая7,8 | — | 0,4 % | 22 дек. 2020 г. |
31Наблюдать | CVE-2017-3912Эксплойта нет | McAfee Application Control and Change Control (MACC) - password management security feature bypass (SFB) leading to an authentication bypassmcafee · application and change control · CWE-274 | Высокая7,8 | — | 0,4 % | 18 сент. 2018 г. |
31Наблюдать | CVE-2020-7289Эксплойта нет | Privilege Escalation vulnerability in MAR for Windowsmcafee · active response · CWE-274 | Высокая7,8 | — | 0,3 % | 8 мая 2020 г. |
31Наблюдать | CVE-2020-7285Эксплойта нет | Privilege Escalation vulnerability in MVISION Endpointmcafee · mvision endpoint · CWE-274 | Высокая7,8 | — | 0,3 % | 8 мая 2020 г. |
31Наблюдать | CVE-2020-7286Эксплойта нет | Privilege Escalation vulnerability in EDR for Windowsmcafee · endpoint detection and response · CWE-274 | Высокая7,8 | — | 0,3 % | 8 мая 2020 г. |
31Наблюдать | CVE-2020-7290Эксплойта нет | Privilege Escalation vulnerability in MAR for Linuxmcafee · active response · CWE-274 | Высокая7,8 | — | 0,3 % | 8 мая 2020 г. |
31Наблюдать | CVE-2020-7287Эксплойта нет | Privilege Escalation vulnerability in EDR for Linuxmcafee · endpoint detection and response · CWE-274 | Высокая7,8 | — | 0,3 % | 8 мая 2020 г. |
31Наблюдать | CVE-2020-7288Эксплойта нет | Privilege Escalation vulnerability in EDR for Macmcafee · endpoint detection and response · CWE-274 | Высокая7,8 | — | 0,3 % | 8 мая 2020 г. |
31Наблюдать | CVE-2020-7291Эксплойта нет | Privilege Escalation vulnerability MAR for Macmcafee · active response · CWE-274 | Высокая7,8 | — | 0,3 % | 8 мая 2020 г. |
29Наблюдать | CVE-2021-35534Эксплойта нет | Insufficient Security Control Vulnerabilityhitachienergy · gms600 firmware · CWE-274 | Высокая7,2 | — | 1,8 % | 18 нояб. 2021 г. |
28Наблюдать | CVE-2024-41942Эксплойта нет | JupyterHub has a privilege escalation vulnerability with the `admin:users` scopejupyter · jupyterhub · CWE-274 | Высокая7,2 | — | 0,6 % | 8 авг. 2024 г. |
27Наблюдать | CVE-2022-23511Эксплойта нет | A privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and logs from Amazon EC2amazon · cloudwatch agent · CWE-274 | Средняя6,8 | — | 0,5 % | 12 дек. 2022 г. |
- CVE-2025-2015639Наблюдать
Cisco Meeting Management Client-Server Privilege Escalation Vulnerability
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %cisco · meeting management22 янв. 2025 г.
- CVE-2022-4510139Наблюдать
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dell · emc powerscale onefs1 февр. 2023 г.
- CVE-2023-3937539Наблюдать
SiberianCMS - CWE-274: Improper Handling of Insufficient Privileges
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %siberiancms · siberiancms27 сент. 2023 г.
- CVE-2022-066839Наблюдать
JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted r
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %jfrog · artifactory8 янв. 2023 г.
- CVE-2023-3592835Наблюдать
Nextcloud user scoped external storage can be used to gather credentials of other users
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %nextcloud · nextcloud server23 июн. 2023 г.
- CVE-2020-728335Наблюдать
Privilege Escalation vulnerability in McAfee Total Protection (MTP)
ВысокаяCVSS 8,8Proof of conceptEPSS 1 %mcafee · total protection3 июл. 2020 г.
- CVE-2024-2164835Наблюдать
XWiki has no right protection on rollback action
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %xwiki · xwiki8 янв. 2024 г.
- CVE-2024-010535Наблюдать
NVIDIA ConnectX Firmware contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue.
ВысокаяCVSS 8,9Эксплойта нетEPSS 0 %nvidia · connectx41 нояб. 2024 г.
- CVE-2024-010634Наблюдать
NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability where an attacker may cause an improper
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %nvidia · bluefield 11 нояб. 2024 г.
- CVE-2020-726733Наблюдать
Privilege Escalation vulnerability through symbolic links in VSEL
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %mcafee · virusscan enterprise8 мая 2020 г.
- CVE-2020-726433Наблюдать
Privilege Escalation vulnerability through symbolic links in ENS for Windows
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %mcafee · endpoint security8 мая 2020 г.
- CVE-2020-726533Наблюдать
Privilege Escalation vulnerability through symbolic links in ENSM
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %mcafee · endpoint security8 мая 2020 г.
- CVE-2020-726633Наблюдать
Privilege Escalation vulnerability through symbolic links in VSE for Windows
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %mcafee · virusscan enterprise8 мая 2020 г.
- CVE-2020-2467631Наблюдать
Insecure Windows Services in Symphony Plus
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %abb · symphony \+ historian22 дек. 2020 г.
- CVE-2017-391231Наблюдать
McAfee Application Control and Change Control (MACC) - password management security feature bypass (SFB) leading to an authentication bypass
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %mcafee · application and change control18 сент. 2018 г.
- CVE-2020-728931Наблюдать
Privilege Escalation vulnerability in MAR for Windows
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %mcafee · active response8 мая 2020 г.
- CVE-2020-728531Наблюдать
Privilege Escalation vulnerability in MVISION Endpoint
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %mcafee · mvision endpoint8 мая 2020 г.
- CVE-2020-728631Наблюдать
Privilege Escalation vulnerability in EDR for Windows
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %mcafee · endpoint detection and response8 мая 2020 г.
- CVE-2020-729031Наблюдать
Privilege Escalation vulnerability in MAR for Linux
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %mcafee · active response8 мая 2020 г.
- CVE-2020-728731Наблюдать
Privilege Escalation vulnerability in EDR for Linux
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %mcafee · endpoint detection and response8 мая 2020 г.
- CVE-2020-728831Наблюдать
Privilege Escalation vulnerability in EDR for Mac
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %mcafee · endpoint detection and response8 мая 2020 г.
- CVE-2020-729131Наблюдать
Privilege Escalation vulnerability MAR for Mac
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %mcafee · active response8 мая 2020 г.
- CVE-2021-3553429Наблюдать
Insufficient Security Control Vulnerability
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %hitachienergy · gms600 firmware18 нояб. 2021 г.
- CVE-2024-4194228Наблюдать
JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %jupyter · jupyterhub8 авг. 2024 г.
- CVE-2022-2351127Наблюдать
A privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and logs from Amazon EC2
СредняяCVSS 6,8Эксплойта нетEPSS 1 %amazon · cloudwatch agent12 дек. 2022 г.