Перейти к содержимому
Noroxi

CWE-280 · 191 записей

Improper Handling of Insufficient Permissions or Privileges

CVE этого класса

191 записей

  • CVE-2024-24116
    48В плане

    An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.

    КритическаяCVSS 9,8Proof of conceptEPSS 28 %

    ruijie · rg-nbs2009g-p firmware2 окт. 2024 г.

  • CVE-2025-6573
    39Наблюдать

    GPU DDK - RGXFW_CTL.pui8FWScratchBuf Leak/Overwrite

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    imagination technologies · graphics ddk8 авг. 2025 г.

  • CVE-2025-46066
    39Наблюдать

    An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges

    КритическаяCVSS 9,9Эксплойта нетEPSS 0 %

    automai · director12 янв. 2026 г.

  • CVE-2026-41566
    37Наблюдать

    Apache Kvrocks: Improper permission for the APPLYBATCH command

    КритическаяCVSS 9,4Эксплойта нетEPSS 0 %

    apache software foundation · apache kvrocks25 июн. 2026 г.

  • CVE-2024-46874
    36Наблюдать

    Ruijie Reyee OS Improper Handling of Insufficient Permissions or Privileges

    КритическаяCVSS 9,2Эксплойта нетEPSS 0 %

    ruijienetworks · reyee os6 дек. 2024 г.

  • CVE-2019-6570
    35Наблюдать

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0).

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    siemens · sinema remote connect server17 апр. 2019 г.

  • CVE-2022-2193
    35Наблюдать

    Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 aut

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    hypr · hypr server19 июл. 2022 г.

  • CVE-2025-29826
    35Наблюдать

    Microsoft Dataverse Elevation of Privilege Vulnerability

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    microsoft · dataverse13 мая 2025 г.

  • CVE-2026-40371
    35Наблюдать

    Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    microsoft · dynamics 3659 июн. 2026 г.

  • CVE-2024-25108
    35Наблюдать

    Insufficient authorization allowing elevated access to resources in pixelfed

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    pixelfed · pixelfed12 февр. 2024 г.

  • CVE-2024-22078
    35Наблюдать

    An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    elspec-ltd · g5dfr firmware20 мар. 2024 г.

  • CVE-2025-27025
    35Наблюдать

    Improper File Access in Infinera G42

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    infinera · g422 июл. 2025 г.

  • CVE-2024-6660
    35Наблюдать

    BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Option

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    reputeinfosystems · bookingpress17 июл. 2024 г.

  • CVE-2024-36451
    35Наблюдать

    Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    webmin · webmin10 июл. 2024 г.

  • CVE-2025-8109
    35Наблюдать

    GPU DDK - GPU shader shared memory corrupted using ptrace to disrupt GPU operation

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    imagination technologies · graphics ddk4 авг. 2025 г.

  • CVE-2025-22256
    35Наблюдать

    A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    fortinet · fortipam10 июн. 2025 г.

  • CVE-2026-59567
    35Наблюдать

    Local privilege escalation

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    zscaler · client connector24 авг. 2026 г.

  • CVE-2026-18860
    34Наблюдать

    Velociraptor incorrect Org deletion permissions check

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    rapid7 · velociraptor11 авг. 2026 г.

  • CVE-2026-2123
    34Наблюдать

    Privilege escalation vulnerability in Operations Agent

    ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %

    microfocus · operations agent31 мар. 2026 г.

  • CVE-2026-20817
    33Наблюдать

    Windows Error Reporting Service Elevation of Privilege Vulnerability

    ВысокаяCVSS 7,8Proof of conceptEPSS 5 %

    microsoft · windows 10 21h213 янв. 2026 г.

  • CVE-2026-0047
    33Наблюдать

    In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due to a missing permis

    ВысокаяCVSS 8,4Proof of conceptEPSS 0 %

    google · android2 мар. 2026 г.

  • CVE-2026-79403
    33Наблюдать

    An issue in Kilo Code before v7.4.1 allows a local attacker to execute arbitrary code via the permission/allow-everything endpoint

    ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %

    29 сент. 2026 г.

  • CVE-2020-29031
    32Наблюдать

    Insecure Direct Object Reference in GateManager WebUI can cause privilege escalation

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    secomea · gatemanager 8250 firmware15 февр. 2021 г.

  • CVE-2025-67848
    32Наблюдать

    Moodle: moodle: authentication bypass via lti provider allows suspended users to gain unauthorized access.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    moodle · moodle3 февр. 2026 г.

  • CVE-2024-43702
    32Наблюдать

    GPU DDK - MLIST/PM render state buffers writable allowing arbitrary writes to kernel memory pages

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    imagination technologies · graphics ddk29 нояб. 2024 г.

Все классы уязвимостей