CWE-648 · 68 записей
Incorrect Use of Privileged APIs
CVE этого класса
68 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
74На этой неделе | CVE-2026-76460Готовый эксплойт | Cisco Identity Services Engine Authentication Bypass Vulnerabilitycisco · identity services engine · CWE-648 | Критическая10,0 | KEV | 14,0 % | 16 сент. 2026 г. |
58В плане | CVE-2026-20122Готовый эксплойт | Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerabilitycisco · catalyst sd-wan manager · CWE-648 | Средняя5,4 | KEV | 25,0 % | 25 февр. 2026 г. |
42В плане | CVE-2019-14813Эксплойта нет | A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged artifex · ghostscript · CWE-648 | Критическая9,8 | — | 11,4 % | 6 сент. 2019 г. |
40В плане | CVE-2019-1010178Эксплойта нет | Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648.modx · fred · CWE-648 | Критическая9,8 | — | 4,6 % | 24 июл. 2019 г. |
40В плане | CVE-2022-2023Эксплойта нет | Incorrect Use of Privileged APIs in polonel/trudesktrudesk project · trudesk · CWE-648 | Критическая9,8 | — | 3,2 % | 20 июн. 2022 г. |
39Наблюдать | CVE-2024-11068Эксплойта нет | D-Link DSL6740C - Incorrect Use of Privileged APIsdlink · dsl6740c firmware · CWE-648 | Критическая9,8 | — | 1,2 % | 11 нояб. 2024 г. |
39Наблюдать | CVE-2023-4972Эксплойта нет | Information Disclosure in Digital Yepasyepas · digital yepas · CWE-648 | Критическая9,8 | — | 0,7 % | 14 сент. 2023 г. |
36Наблюдать | CVE-2019-14869Эксплойта нет | A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its priviartifex · ghostscript · CWE-648 | Высокая8,8 | — | 3,4 % | 15 нояб. 2019 г. |
36Наблюдать | CVE-2026-41386Эксплойта нет | OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codesopenclaw · openclaw · CWE-648 | Критическая9,1 | — | 0,6 % | 28 апр. 2026 г. |
36Наблюдать | CVE-2026-41329Эксплойта нет | OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalationopenclaw · openclaw · CWE-648 | Критическая9,0 | — | 0,5 % | 20 апр. 2026 г. |
36Наблюдать | CVE-2024-37018Эксплойта нет | The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken bCWE-648 | Критическая9,1 | — | 0,4 % | 30 мая 2024 г. |
35Наблюдать | CVE-2022-20956Эксплойта нет | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker cisco · identity services engine · CWE-648 | Высокая8,8 | — | 1,4 % | 4 нояб. 2022 г. |
35Наблюдать | CVE-2023-28062Эксплойта нет | Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability.dell · powerprotect data manager · CWE-648 | Высокая8,8 | — | 0,8 % | 11 апр. 2023 г. |
35Наблюдать | CVE-2025-5997Эксплойта нет | Privilege Escalation in Beamsec PhishProbeamsec · phishpro · CWE-648 | Высокая8,8 | — | 0,4 % | 28 июл. 2025 г. |
35Наблюдать | GHSA-r3v5-2grc-429hЭксплойта нет | Duplicate Advisory: OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approvenpm · openclaw · CWE-648 | Высокая8,8 | — | — | 10 апр. 2026 г. |
34Наблюдать | CVE-2026-35639Эксплойта нет | OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope Validationopenclaw · openclaw · CWE-648 | Высокая8,7 | — | 0,8 % | 9 апр. 2026 г. |
34Наблюдать | CVE-2025-7344Эксплойта нет | Digiwin|EAI - Privilege Escalationdigiwin · eai · CWE-648 | Высокая8,7 | — | 0,5 % | 21 июл. 2025 г. |
34Наблюдать | CVE-2026-35669Эксплойта нет | OpenClaw < 2026.3.25 - Privilege Escalation via Gateway Plugin HTTP Authentication Scopeopenclaw · openclaw · CWE-648 | Высокая8,7 | — | 0,5 % | 10 апр. 2026 г. |
34Наблюдать | CVE-2026-35663Эксплойта нет | OpenClaw < 2026.3.25 - Privilege Escalation via Backend Reconnect Scope Self-Claimopenclaw · openclaw · CWE-648 | Высокая8,7 | — | 0,5 % | 10 апр. 2026 г. |
34Наблюдать | CVE-2026-41225Эксплойта нет | iControl REST vulnerabilityf5 · big-ip access policy manager · CWE-648 | Высокая8,6 | — | 0,5 % | 13 мая 2026 г. |
34Наблюдать | CVE-2026-63727Эксплойта нет | Anchore Enterprise Privilege Escalation via User Management APIanchore · anchore enterprise · CWE-648 | Высокая8,7 | — | 0,4 % | 28 июл. 2026 г. |
34Наблюдать | CVE-2022-26323Эксплойта нет | Incorrect Use of Privileged vulnerability has been discovered on OpenText™ UCMDB and Operation Bridge Manager product.opentext™ · operations bridge manager · CWE-648 | Высокая8,7 | — | 0,3 % | 17 апр. 2025 г. |
34Наблюдать | CVE-2026-35625Эксплойта нет | OpenClaw < 2026.3.25 - Privilege Escalation via Silent Local Shared-Auth Reconnectopenclaw · openclaw · CWE-648 | Высокая8,5 | — | 0,3 % | 9 апр. 2026 г. |
34Наблюдать | CVE-2024-32008Эксплойта нет | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2).siemens · spectrum power 4 · CWE-648 | Высокая8,5 | — | 0,1 % | 11 нояб. 2025 г. |
33Наблюдать | CVE-2026-54424Proof of concept | An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege.unity · parsec · CWE-648 | Высокая8,4 | — | 0,2 % | 3 июл. 2026 г. |
- CVE-2026-7646074На этой неделе
Cisco Identity Services Engine Authentication Bypass Vulnerability
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 14 %cisco · identity services engine16 сент. 2026 г.
- CVE-2026-2012258В плане
Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability
СредняяCVSS 5,4KEVГотовый эксплойтEPSS 25 %cisco · catalyst sd-wan manager25 февр. 2026 г.
- CVE-2019-1481342В плане
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged
КритическаяCVSS 9,8Эксплойта нетEPSS 11 %artifex · ghostscript6 сент. 2019 г.
- CVE-2019-101017840В плане
Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %modx · fred24 июл. 2019 г.
- CVE-2022-202340В плане
Incorrect Use of Privileged APIs in polonel/trudesk
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %trudesk project · trudesk20 июн. 2022 г.
- CVE-2024-1106839Наблюдать
D-Link DSL6740C - Incorrect Use of Privileged APIs
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dlink · dsl6740c firmware11 нояб. 2024 г.
- CVE-2023-497239Наблюдать
Information Disclosure in Digital Yepas
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %yepas · digital yepas14 сент. 2023 г.
- CVE-2019-1486936Наблюдать
A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privi
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %artifex · ghostscript15 нояб. 2019 г.
- CVE-2026-4138636Наблюдать
OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %openclaw · openclaw28 апр. 2026 г.
- CVE-2026-4132936Наблюдать
OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalation
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %openclaw · openclaw20 апр. 2026 г.
- CVE-2024-3701836Наблюдать
The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken b
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %30 мая 2024 г.
- CVE-2022-2095635Наблюдать
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %cisco · identity services engine4 нояб. 2022 г.
- CVE-2023-2806235Наблюдать
Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %dell · powerprotect data manager11 апр. 2023 г.
- CVE-2025-599735Наблюдать
Privilege Escalation in Beamsec PhishPro
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %beamsec · phishpro28 июл. 2025 г.
- GHSA-r3v5-2grc-429h35Наблюдать
Duplicate Advisory: OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approve
ВысокаяCVSS 8,8Эксплойта нетnpm · openclaw10 апр. 2026 г.
- CVE-2026-3563934Наблюдать
OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope Validation
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %openclaw · openclaw9 апр. 2026 г.
- CVE-2025-734434Наблюдать
Digiwin|EAI - Privilege Escalation
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %digiwin · eai21 июл. 2025 г.
- CVE-2026-3566934Наблюдать
OpenClaw < 2026.3.25 - Privilege Escalation via Gateway Plugin HTTP Authentication Scope
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %openclaw · openclaw10 апр. 2026 г.
- CVE-2026-3566334Наблюдать
OpenClaw < 2026.3.25 - Privilege Escalation via Backend Reconnect Scope Self-Claim
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %openclaw · openclaw10 апр. 2026 г.
- CVE-2026-4122534Наблюдать
iControl REST vulnerability
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %f5 · big-ip access policy manager13 мая 2026 г.
- CVE-2026-6372734Наблюдать
Anchore Enterprise Privilege Escalation via User Management API
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %anchore · anchore enterprise28 июл. 2026 г.
- CVE-2022-2632334Наблюдать
Incorrect Use of Privileged vulnerability has been discovered on OpenText™ UCMDB and Operation Bridge Manager product.
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %opentext™ · operations bridge manager17 апр. 2025 г.
- CVE-2026-3562534Наблюдать
OpenClaw < 2026.3.25 - Privilege Escalation via Silent Local Shared-Auth Reconnect
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %openclaw · openclaw9 апр. 2026 г.
- CVE-2024-3200834Наблюдать
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2).
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %siemens · spectrum power 411 нояб. 2025 г.
- CVE-2026-5442433Наблюдать
An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege.
ВысокаяCVSS 8,4Proof of conceptEPSS 0 %unity · parsec3 июл. 2026 г.