Перейти к содержимому
Noroxi

CWE-648 · 68 записей

Incorrect Use of Privileged APIs

CVE этого класса

68 записей

  • CVE-2026-76460
    74На этой неделе

    Cisco Identity Services Engine Authentication Bypass Vulnerability

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 14 %

    cisco · identity services engine16 сент. 2026 г.

  • CVE-2026-20122
    58В плане

    Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability

    СредняяCVSS 5,4KEVГотовый эксплойтEPSS 25 %

    cisco · catalyst sd-wan manager25 февр. 2026 г.

  • CVE-2019-14813
    42В плане

    A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged

    КритическаяCVSS 9,8Эксплойта нетEPSS 11 %

    artifex · ghostscript6 сент. 2019 г.

  • CVE-2019-1010178
    40В плане

    Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648.

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    modx · fred24 июл. 2019 г.

  • CVE-2022-2023
    40В плане

    Incorrect Use of Privileged APIs in polonel/trudesk

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    trudesk project · trudesk20 июн. 2022 г.

  • CVE-2024-11068
    39Наблюдать

    D-Link DSL6740C - Incorrect Use of Privileged APIs

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    dlink · dsl6740c firmware11 нояб. 2024 г.

  • CVE-2023-4972
    39Наблюдать

    Information Disclosure in Digital Yepas

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    yepas · digital yepas14 сент. 2023 г.

  • CVE-2019-14869
    36Наблюдать

    A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privi

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    artifex · ghostscript15 нояб. 2019 г.

  • CVE-2026-41386
    36Наблюдать

    OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    openclaw · openclaw28 апр. 2026 г.

  • CVE-2026-41329
    36Наблюдать

    OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalation

    КритическаяCVSS 9,0Эксплойта нетEPSS 1 %

    openclaw · openclaw20 апр. 2026 г.

  • CVE-2024-37018
    36Наблюдать

    The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken b

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    30 мая 2024 г.

  • CVE-2022-20956
    35Наблюдать

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    cisco · identity services engine4 нояб. 2022 г.

  • CVE-2023-28062
    35Наблюдать

    Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    dell · powerprotect data manager11 апр. 2023 г.

  • CVE-2025-5997
    35Наблюдать

    Privilege Escalation in Beamsec PhishPro

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    beamsec · phishpro28 июл. 2025 г.

  • GHSA-r3v5-2grc-429h
    35Наблюдать

    Duplicate Advisory: OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approve

    ВысокаяCVSS 8,8Эксплойта нет

    npm · openclaw10 апр. 2026 г.

  • CVE-2026-35639
    34Наблюдать

    OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope Validation

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    openclaw · openclaw9 апр. 2026 г.

  • CVE-2025-7344
    34Наблюдать

    Digiwin|EAI - Privilege Escalation

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    digiwin · eai21 июл. 2025 г.

  • CVE-2026-35669
    34Наблюдать

    OpenClaw < 2026.3.25 - Privilege Escalation via Gateway Plugin HTTP Authentication Scope

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    openclaw · openclaw10 апр. 2026 г.

  • CVE-2026-35663
    34Наблюдать

    OpenClaw < 2026.3.25 - Privilege Escalation via Backend Reconnect Scope Self-Claim

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    openclaw · openclaw10 апр. 2026 г.

  • CVE-2026-41225
    34Наблюдать

    iControl REST vulnerability

    ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %

    f5 · big-ip access policy manager13 мая 2026 г.

  • CVE-2026-63727
    34Наблюдать

    Anchore Enterprise Privilege Escalation via User Management API

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    anchore · anchore enterprise28 июл. 2026 г.

  • CVE-2022-26323
    34Наблюдать

    Incorrect Use of Privileged vulnerability has been discovered on OpenText™ UCMDB and Operation Bridge Manager product.

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    opentext™ · operations bridge manager17 апр. 2025 г.

  • CVE-2026-35625
    34Наблюдать

    OpenClaw < 2026.3.25 - Privilege Escalation via Silent Local Shared-Auth Reconnect

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    openclaw · openclaw9 апр. 2026 г.

  • CVE-2024-32008
    34Наблюдать

    A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2).

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    siemens · spectrum power 411 нояб. 2025 г.

  • CVE-2026-54424
    33Наблюдать

    An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege.

    ВысокаяCVSS 8,4Proof of conceptEPSS 0 %

    unity · parsec3 июл. 2026 г.

Все классы уязвимостей