CWE-280 · 191 записей
Improper Handling of Insufficient Permissions or Privileges
CVE этого класса
191 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
48В плане | CVE-2024-24116Proof of concept | An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.ruijie · rg-nbs2009g-p firmware · CWE-280 | Критическая9,8 | — | 28,4 % | 2 окт. 2024 г. |
39Наблюдать | CVE-2025-6573Эксплойта нет | GPU DDK - RGXFW_CTL.pui8FWScratchBuf Leak/Overwriteimagination technologies · graphics ddk · CWE-280 | Критическая9,8 | — | 0,4 % | 8 авг. 2025 г. |
39Наблюдать | CVE-2025-46066Эксплойта нет | An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privilegesautomai · director · CWE-280 | Критическая9,9 | — | 0,3 % | 12 янв. 2026 г. |
37Наблюдать | CVE-2026-41566Эксплойта нет | Apache Kvrocks: Improper permission for the APPLYBATCH commandapache software foundation · apache kvrocks · CWE-280 | Критическая9,4 | — | 0,4 % | 25 июн. 2026 г. |
36Наблюдать | CVE-2024-46874Эксплойта нет | Ruijie Reyee OS Improper Handling of Insufficient Permissions or Privilegesruijienetworks · reyee os · CWE-280 | Критическая9,2 | — | 0,4 % | 6 дек. 2024 г. |
35Наблюдать | CVE-2019-6570Эксплойта нет | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0).siemens · sinema remote connect server · CWE-280 | Высокая8,8 | — | 1,3 % | 17 апр. 2019 г. |
35Наблюдать | CVE-2022-2193Эксплойта нет | Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 authypr · hypr server · CWE-280 | Высокая8,8 | — | 1,0 % | 19 июл. 2022 г. |
35Наблюдать | CVE-2025-29826Эксплойта нет | Microsoft Dataverse Elevation of Privilege Vulnerabilitymicrosoft · dataverse · CWE-280 | Высокая8,8 | — | 0,9 % | 13 мая 2025 г. |
35Наблюдать | CVE-2026-40371Эксплойта нет | Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerabilitymicrosoft · dynamics 365 · CWE-280 | Высокая8,8 | — | 0,8 % | 9 июн. 2026 г. |
35Наблюдать | CVE-2024-25108Эксплойта нет | Insufficient authorization allowing elevated access to resources in pixelfedpixelfed · pixelfed · CWE-280 | Высокая8,8 | — | 0,7 % | 12 февр. 2024 г. |
35Наблюдать | CVE-2024-22078Эксплойта нет | An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before.elspec-ltd · g5dfr firmware · CWE-280 | Высокая8,8 | — | 0,6 % | 20 мар. 2024 г. |
35Наблюдать | CVE-2025-27025Эксплойта нет | Improper File Access in Infinera G42infinera · g42 · CWE-280 | Высокая8,8 | — | 0,6 % | 2 июл. 2025 г. |
35Наблюдать | CVE-2024-6660Эксплойта нет | BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Optionreputeinfosystems · bookingpress · CWE-280 | Высокая8,8 | — | 0,6 % | 17 июл. 2024 г. |
35Наблюдать | CVE-2024-36451Эксплойта нет | Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003.webmin · webmin · CWE-280 | Высокая8,8 | — | 0,6 % | 10 июл. 2024 г. |
35Наблюдать | CVE-2025-8109Эксплойта нет | GPU DDK - GPU shader shared memory corrupted using ptrace to disrupt GPU operationimagination technologies · graphics ddk · CWE-280 | Высокая8,8 | — | 0,4 % | 4 авг. 2025 г. |
35Наблюдать | CVE-2025-22256Эксплойта нет | A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1fortinet · fortipam · CWE-280 | Высокая8,8 | — | 0,4 % | 10 июн. 2025 г. |
35Наблюдать | CVE-2026-59567Эксплойта нет | Local privilege escalationzscaler · client connector · CWE-280 | Высокая8,8 | — | 0,1 % | 24 авг. 2026 г. |
34Наблюдать | CVE-2026-18860Эксплойта нет | Velociraptor incorrect Org deletion permissions checkrapid7 · velociraptor · CWE-280 | Высокая8,7 | — | 0,4 % | 11 авг. 2026 г. |
34Наблюдать | CVE-2026-2123Эксплойта нет | Privilege escalation vulnerability in Operations Agentmicrofocus · operations agent · CWE-280 | Высокая8,6 | — | 0,1 % | 31 мар. 2026 г. |
33Наблюдать | CVE-2026-20817Proof of concept | Windows Error Reporting Service Elevation of Privilege Vulnerabilitymicrosoft · windows 10 21h2 · CWE-280 | Высокая7,8 | — | 5,4 % | 13 янв. 2026 г. |
33Наблюдать | CVE-2026-0047Proof of concept | In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due to a missing permisgoogle · android · CWE-280 | Высокая8,4 | — | 0,1 % | 2 мар. 2026 г. |
33Наблюдать | CVE-2026-79403Эксплойта нет | An issue in Kilo Code before v7.4.1 allows a local attacker to execute arbitrary code via the permission/allow-everything endpointCWE-280 | Высокая8,4 | — | 0,1 % | 29 сент. 2026 г. |
32Наблюдать | CVE-2020-29031Эксплойта нет | Insecure Direct Object Reference in GateManager WebUI can cause privilege escalationsecomea · gatemanager 8250 firmware · CWE-280 | Высокая8,1 | — | 0,7 % | 15 февр. 2021 г. |
32Наблюдать | CVE-2025-67848Эксплойта нет | Moodle: moodle: authentication bypass via lti provider allows suspended users to gain unauthorized access.moodle · moodle · CWE-280 | Высокая8,1 | — | 0,4 % | 3 февр. 2026 г. |
32Наблюдать | CVE-2024-43702Эксплойта нет | GPU DDK - MLIST/PM render state buffers writable allowing arbitrary writes to kernel memory pagesimagination technologies · graphics ddk · CWE-280 | Высокая8,1 | — | 0,3 % | 29 нояб. 2024 г. |
- CVE-2024-2411648В плане
An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.
КритическаяCVSS 9,8Proof of conceptEPSS 28 %ruijie · rg-nbs2009g-p firmware2 окт. 2024 г.
- CVE-2025-657339Наблюдать
GPU DDK - RGXFW_CTL.pui8FWScratchBuf Leak/Overwrite
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %imagination technologies · graphics ddk8 авг. 2025 г.
- CVE-2025-4606639Наблюдать
An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges
КритическаяCVSS 9,9Эксплойта нетEPSS 0 %automai · director12 янв. 2026 г.
- CVE-2026-4156637Наблюдать
Apache Kvrocks: Improper permission for the APPLYBATCH command
КритическаяCVSS 9,4Эксплойта нетEPSS 0 %apache software foundation · apache kvrocks25 июн. 2026 г.
- CVE-2024-4687436Наблюдать
Ruijie Reyee OS Improper Handling of Insufficient Permissions or Privileges
КритическаяCVSS 9,2Эксплойта нетEPSS 0 %ruijienetworks · reyee os6 дек. 2024 г.
- CVE-2019-657035Наблюдать
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0).
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %siemens · sinema remote connect server17 апр. 2019 г.
- CVE-2022-219335Наблюдать
Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 aut
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %hypr · hypr server19 июл. 2022 г.
- CVE-2025-2982635Наблюдать
Microsoft Dataverse Elevation of Privilege Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %microsoft · dataverse13 мая 2025 г.
- CVE-2026-4037135Наблюдать
Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %microsoft · dynamics 3659 июн. 2026 г.
- CVE-2024-2510835Наблюдать
Insufficient authorization allowing elevated access to resources in pixelfed
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %pixelfed · pixelfed12 февр. 2024 г.
- CVE-2024-2207835Наблюдать
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %elspec-ltd · g5dfr firmware20 мар. 2024 г.
- CVE-2025-2702535Наблюдать
Improper File Access in Infinera G42
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %infinera · g422 июл. 2025 г.
- CVE-2024-666035Наблюдать
BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Option
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %reputeinfosystems · bookingpress17 июл. 2024 г.
- CVE-2024-3645135Наблюдать
Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %webmin · webmin10 июл. 2024 г.
- CVE-2025-810935Наблюдать
GPU DDK - GPU shader shared memory corrupted using ptrace to disrupt GPU operation
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %imagination technologies · graphics ddk4 авг. 2025 г.
- CVE-2025-2225635Наблюдать
A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %fortinet · fortipam10 июн. 2025 г.
- CVE-2026-5956735Наблюдать
Local privilege escalation
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %zscaler · client connector24 авг. 2026 г.
- CVE-2026-1886034Наблюдать
Velociraptor incorrect Org deletion permissions check
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %rapid7 · velociraptor11 авг. 2026 г.
- CVE-2026-212334Наблюдать
Privilege escalation vulnerability in Operations Agent
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %microfocus · operations agent31 мар. 2026 г.
- CVE-2026-2081733Наблюдать
Windows Error Reporting Service Elevation of Privilege Vulnerability
ВысокаяCVSS 7,8Proof of conceptEPSS 5 %microsoft · windows 10 21h213 янв. 2026 г.
- CVE-2026-004733Наблюдать
In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due to a missing permis
ВысокаяCVSS 8,4Proof of conceptEPSS 0 %google · android2 мар. 2026 г.
- CVE-2026-7940333Наблюдать
An issue in Kilo Code before v7.4.1 allows a local attacker to execute arbitrary code via the permission/allow-everything endpoint
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %29 сент. 2026 г.
- CVE-2020-2903132Наблюдать
Insecure Direct Object Reference in GateManager WebUI can cause privilege escalation
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %secomea · gatemanager 8250 firmware15 февр. 2021 г.
- CVE-2025-6784832Наблюдать
Moodle: moodle: authentication bypass via lti provider allows suspended users to gain unauthorized access.
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %moodle · moodle3 февр. 2026 г.
- CVE-2024-4370232Наблюдать
GPU DDK - MLIST/PM render state buffers writable allowing arbitrary writes to kernel memory pages
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %imagination technologies · graphics ddk29 нояб. 2024 г.