CWE-279 · 25 kayıt
Incorrect Execution-Assigned Permissions
Bu sınıftaki CVE’ler
25 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2024-37734İstismar yok | An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.open-emr · openemr · CWE-279 | Kritik9,8 | — | %0,8 | 26 Haz 2024 |
37İzleyin | CVE-2020-8025İstismar yok | outdated entries in permissions profiles for /var/lib/pcp/tmp/* may cause security issuessuse · linux enterprise high performance computing · CWE-279 | Kritik9,3 | — | %0,5 | 7 Ağu 2020 |
35İzleyin | CVE-2023-4665İstismar yok | Privilage Escalation in Saphira Connectadobe · connect · CWE-279 | Yüksek8,8 | — | %1,0 | 15 Eyl 2023 |
35İzleyin | CVE-2025-22843İstismar yok | Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated usCWE-279 | Yüksek8,8 | — | %0,1 | 13 May 2025 |
34İzleyin | CVE-2025-14025İstismar yok | Ansible-automation-platform/aap-gateway: aap-gateway: read-only personal access token (pat) bypasses write restrictionsred hat · red hat ansible automation platform 2.5 for rhel 8 · CWE-279 | Yüksek8,5 | — | %0,4 | 8 Oca 2026 |
34İzleyin | CVE-2024-11220İstismar yok | Open Automation Software Incorrect Execution-Assigned Permissionsopenautomationsoftware · open automation software · CWE-279 | Yüksek8,5 | — | %0,2 | 6 Ara 2024 |
31İzleyin | CVE-2023-4383İstismar yok | MicroWorld eScan Anti-Virus runasroot incorrect execution-assigned permissionsescanav · escan anti-virus · CWE-279 | Yüksek7,8 | — | %0,3 | 16 Ağu 2023 |
31İzleyin | CVE-2024-25621İstismar yok | containerd affected by a local privilege escalation via wide permissions on CRI directorylinuxfoundation · containerd · CWE-279 | Yüksek7,8 | — | %0,2 | 6 Kas 2025 |
30İzleyin | CVE-2025-23263İstismar yok | NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause escalation of privilegnvidia · doca-host and mellanox ofed · CWE-279 | Yüksek7,6 | — | %0,2 | 17 Tem 2025 |
29İzleyin | CVE-2025-30001İstismar yok | Apache StreamPark: Authenticated users can trigger remote command executionapache · streampark · CWE-279 | Yüksek7,3 | — | %0,6 | 10 Eki 2025 |
28İzleyin | CVE-2023-3915İstismar yok | Incorrect Execution-Assigned Permissions in GitLabgitlab · gitlab · CWE-279 | Yüksek7,2 | — | %0,7 | 1 Eyl 2023 |
28İzleyin | CVE-2026-20062İstismar yok | A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in multiple context mode could allow an authecisco · cisco secure firewall adaptive security appliance (asa) software · CWE-279 | Yüksek7,2 | — | %0,1 | 4 Mar 2026 |
26İzleyin | CVE-2023-50914İstismar yok | A Privilege Escalation issue in the inter-process communication procedure from GOG Galaxy (Beta) 2.0.67.2 through v2.0.71.2 allows authenticCWE-279 | Orta6,7 | — | %0,7 | 30 Nis 2024 |
26İzleyin | CVE-2025-12801İstismar yok | Nfs-utils: rpc.mountd in the nfs-utils privilege escalationredhat · openshift container platform · CWE-279 | Orta6,5 | — | %0,5 | 4 Mar 2026 |
22İzleyin | CVE-2026-4948İstismar yok | Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorizationfirewalld · firewalld · CWE-279 | Orta5,5 | — | %0,2 | 27 Mar 2026 |
21İzleyin | CVE-2024-37025İstismar yok | Incorrect execution-assigned permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installer before version 23.1.1 mCWE-279 | Orta5,4 | — | %0,2 | 13 Kas 2024 |
21İzleyin | CVE-2025-13663İstismar yok | Quartus Prime Pro Edition Installer Advisoryintel · quartus prime · CWE-279 | Orta5,4 | — | %0,1 | 11 Ara 2025 |
20İzleyin | CVE-2025-20612İstismar yok | Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated usCWE-279 | Orta5,1 | — | %0,2 | 13 May 2025 |
20İzleyin | CVE-2025-23233İstismar yok | Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated usCWE-279 | Orta5,1 | — | %0,2 | 13 May 2025 |
17İzleyin | CVE-2017-8441İstismar yok | Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases.elastic · x-pack · CWE-279 | Orta4,3 | — | %0,7 | 5 Haz 2017 |
17İzleyin | CVE-2026-46388İstismar yok | osquery: Unprivileged users can temporarily read file carve contentsosquery · osquery · CWE-279 | Orta4,4 | — | %0,1 | 10 Tem 2026 |
16İzleyin | CVE-2025-26422İstismar yok | In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permissiongoogle · android · CWE-279 | Orta4,0 | — | %0,1 | 4 Eyl 2025 |
15İzleyin | CVE-2025-36228İstismar yok | Incorrect Execution-Assigned Permissions in IBM Aspera Faspexibm · aspera faspex · CWE-279 | Düşük3,8 | — | %0,2 | 26 Ara 2025 |
8İzleyin | CVE-2024-39286İstismar yok | Incorrect execution-assigned permissions in the Linux kernel mode driver for the Intel(R) 800 Series Ethernet Driver before version 1.15.4 mCWE-279 | Düşük2,0 | — | %0,2 | 12 Şub 2025 |
8İzleyin | GHSA-qc59-cxj2-c2w4İstismar yok | aws-cdk-lib's aspect order change causes different Permissions Boundary assigned to Rolenpm · aws-cdk-lib · CWE-279 | Düşük2,2 | — | — | 15 Nis 2025 |
- CVE-2024-3773439İzleyin
An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.
KritikCVSS 9,8İstismar yokEPSS %1open-emr · openemr26 Haz 2024
- CVE-2020-802537İzleyin
outdated entries in permissions profiles for /var/lib/pcp/tmp/* may cause security issues
KritikCVSS 9,3İstismar yokEPSS %0suse · linux enterprise high performance computing7 Ağu 2020
- CVE-2023-466535İzleyin
Privilage Escalation in Saphira Connect
YüksekCVSS 8,8İstismar yokEPSS %1adobe · connect15 Eyl 2023
- CVE-2025-2284335İzleyin
Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated us
YüksekCVSS 8,8İstismar yokEPSS %013 May 2025
- CVE-2025-1402534İzleyin
Ansible-automation-platform/aap-gateway: aap-gateway: read-only personal access token (pat) bypasses write restrictions
YüksekCVSS 8,5İstismar yokEPSS %0red hat · red hat ansible automation platform 2.5 for rhel 88 Oca 2026
- CVE-2024-1122034İzleyin
Open Automation Software Incorrect Execution-Assigned Permissions
YüksekCVSS 8,5İstismar yokEPSS %0openautomationsoftware · open automation software6 Ara 2024
- CVE-2023-438331İzleyin
MicroWorld eScan Anti-Virus runasroot incorrect execution-assigned permissions
YüksekCVSS 7,8İstismar yokEPSS %0escanav · escan anti-virus16 Ağu 2023
- CVE-2024-2562131İzleyin
containerd affected by a local privilege escalation via wide permissions on CRI directory
YüksekCVSS 7,8İstismar yokEPSS %0linuxfoundation · containerd6 Kas 2025
- CVE-2025-2326330İzleyin
NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause escalation of privileg
YüksekCVSS 7,6İstismar yokEPSS %0nvidia · doca-host and mellanox ofed17 Tem 2025
- CVE-2025-3000129İzleyin
Apache StreamPark: Authenticated users can trigger remote command execution
YüksekCVSS 7,3İstismar yokEPSS %1apache · streampark10 Eki 2025
- CVE-2023-391528İzleyin
Incorrect Execution-Assigned Permissions in GitLab
YüksekCVSS 7,2İstismar yokEPSS %1gitlab · gitlab1 Eyl 2023
- CVE-2026-2006228İzleyin
A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in multiple context mode could allow an authe
YüksekCVSS 7,2İstismar yokEPSS %0cisco · cisco secure firewall adaptive security appliance (asa) software4 Mar 2026
- CVE-2023-5091426İzleyin
A Privilege Escalation issue in the inter-process communication procedure from GOG Galaxy (Beta) 2.0.67.2 through v2.0.71.2 allows authentic
OrtaCVSS 6,7İstismar yokEPSS %130 Nis 2024
- CVE-2025-1280126İzleyin
Nfs-utils: rpc.mountd in the nfs-utils privilege escalation
OrtaCVSS 6,5İstismar yokEPSS %0redhat · openshift container platform4 Mar 2026
- CVE-2026-494822İzleyin
Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization
OrtaCVSS 5,5İstismar yokEPSS %0firewalld · firewalld27 Mar 2026
- CVE-2024-3702521İzleyin
Incorrect execution-assigned permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installer before version 23.1.1 m
OrtaCVSS 5,4İstismar yokEPSS %013 Kas 2024
- CVE-2025-1366321İzleyin
Quartus Prime Pro Edition Installer Advisory
OrtaCVSS 5,4İstismar yokEPSS %0intel · quartus prime11 Ara 2025
- CVE-2025-2061220İzleyin
Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated us
OrtaCVSS 5,1İstismar yokEPSS %013 May 2025
- CVE-2025-2323320İzleyin
Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated us
OrtaCVSS 5,1İstismar yokEPSS %013 May 2025
- CVE-2017-844117İzleyin
Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases.
OrtaCVSS 4,3İstismar yokEPSS %1elastic · x-pack5 Haz 2017
- CVE-2026-4638817İzleyin
osquery: Unprivileged users can temporarily read file carve contents
OrtaCVSS 4,4İstismar yokEPSS %0osquery · osquery10 Tem 2026
- CVE-2025-2642216İzleyin
In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permission
OrtaCVSS 4,0İstismar yokEPSS %0google · android4 Eyl 2025
- CVE-2025-3622815İzleyin
Incorrect Execution-Assigned Permissions in IBM Aspera Faspex
DüşükCVSS 3,8İstismar yokEPSS %0ibm · aspera faspex26 Ara 2025
- CVE-2024-392868İzleyin
Incorrect execution-assigned permissions in the Linux kernel mode driver for the Intel(R) 800 Series Ethernet Driver before version 1.15.4 m
DüşükCVSS 2,0İstismar yokEPSS %012 Şub 2025
- GHSA-qc59-cxj2-c2w48İzleyin
aws-cdk-lib's aspect order change causes different Permissions Boundary assigned to Role
DüşükCVSS 2,2İstismar yoknpm · aws-cdk-lib15 Nis 2025