İçeriğe atla
Noroxi

CWE-279 · 25 kayıt

Incorrect Execution-Assigned Permissions

Bu sınıftaki CVE’ler

25 kayıt

  • CVE-2024-37734
    39İzleyin

    An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.

    KritikCVSS 9,8İstismar yokEPSS %1

    open-emr · openemr26 Haz 2024

  • CVE-2020-8025
    37İzleyin

    outdated entries in permissions profiles for /var/lib/pcp/tmp/* may cause security issues

    KritikCVSS 9,3İstismar yokEPSS %0

    suse · linux enterprise high performance computing7 Ağu 2020

  • CVE-2023-4665
    35İzleyin

    Privilage Escalation in Saphira Connect

    YüksekCVSS 8,8İstismar yokEPSS %1

    adobe · connect15 Eyl 2023

  • CVE-2025-22843
    35İzleyin

    Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated us

    YüksekCVSS 8,8İstismar yokEPSS %0

    13 May 2025

  • CVE-2025-14025
    34İzleyin

    Ansible-automation-platform/aap-gateway: aap-gateway: read-only personal access token (pat) bypasses write restrictions

    YüksekCVSS 8,5İstismar yokEPSS %0

    red hat · red hat ansible automation platform 2.5 for rhel 88 Oca 2026

  • CVE-2024-11220
    34İzleyin

    Open Automation Software Incorrect Execution-Assigned Permissions

    YüksekCVSS 8,5İstismar yokEPSS %0

    openautomationsoftware · open automation software6 Ara 2024

  • CVE-2023-4383
    31İzleyin

    MicroWorld eScan Anti-Virus runasroot incorrect execution-assigned permissions

    YüksekCVSS 7,8İstismar yokEPSS %0

    escanav · escan anti-virus16 Ağu 2023

  • CVE-2024-25621
    31İzleyin

    containerd affected by a local privilege escalation via wide permissions on CRI directory

    YüksekCVSS 7,8İstismar yokEPSS %0

    linuxfoundation · containerd6 Kas 2025

  • CVE-2025-23263
    30İzleyin

    NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause escalation of privileg

    YüksekCVSS 7,6İstismar yokEPSS %0

    nvidia · doca-host and mellanox ofed17 Tem 2025

  • CVE-2025-30001
    29İzleyin

    Apache StreamPark: Authenticated users can trigger remote command execution

    YüksekCVSS 7,3İstismar yokEPSS %1

    apache · streampark10 Eki 2025

  • CVE-2023-3915
    28İzleyin

    Incorrect Execution-Assigned Permissions in GitLab

    YüksekCVSS 7,2İstismar yokEPSS %1

    gitlab · gitlab1 Eyl 2023

  • CVE-2026-20062
    28İzleyin

    A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in multiple context mode could allow an authe

    YüksekCVSS 7,2İstismar yokEPSS %0

    cisco · cisco secure firewall adaptive security appliance (asa) software4 Mar 2026

  • CVE-2023-50914
    26İzleyin

    A Privilege Escalation issue in the inter-process communication procedure from GOG Galaxy (Beta) 2.0.67.2 through v2.0.71.2 allows authentic

    OrtaCVSS 6,7İstismar yokEPSS %1

    30 Nis 2024

  • CVE-2025-12801
    26İzleyin

    Nfs-utils: rpc.mountd in the nfs-utils privilege escalation

    OrtaCVSS 6,5İstismar yokEPSS %0

    redhat · openshift container platform4 Mar 2026

  • CVE-2026-4948
    22İzleyin

    Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization

    OrtaCVSS 5,5İstismar yokEPSS %0

    firewalld · firewalld27 Mar 2026

  • CVE-2024-37025
    21İzleyin

    Incorrect execution-assigned permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installer before version 23.1.1 m

    OrtaCVSS 5,4İstismar yokEPSS %0

    13 Kas 2024

  • CVE-2025-13663
    21İzleyin

    Quartus Prime Pro Edition Installer Advisory

    OrtaCVSS 5,4İstismar yokEPSS %0

    intel · quartus prime11 Ara 2025

  • CVE-2025-20612
    20İzleyin

    Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated us

    OrtaCVSS 5,1İstismar yokEPSS %0

    13 May 2025

  • CVE-2025-23233
    20İzleyin

    Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated us

    OrtaCVSS 5,1İstismar yokEPSS %0

    13 May 2025

  • CVE-2017-8441
    17İzleyin

    Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases.

    OrtaCVSS 4,3İstismar yokEPSS %1

    elastic · x-pack5 Haz 2017

  • CVE-2026-46388
    17İzleyin

    osquery: Unprivileged users can temporarily read file carve contents

    OrtaCVSS 4,4İstismar yokEPSS %0

    osquery · osquery10 Tem 2026

  • CVE-2025-26422
    16İzleyin

    In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permission

    OrtaCVSS 4,0İstismar yokEPSS %0

    google · android4 Eyl 2025

  • CVE-2025-36228
    15İzleyin

    Incorrect Execution-Assigned Permissions in IBM Aspera Faspex

    DüşükCVSS 3,8İstismar yokEPSS %0

    ibm · aspera faspex26 Ara 2025

  • Incorrect execution-assigned permissions in the Linux kernel mode driver for the Intel(R) 800 Series Ethernet Driver before version 1.15.4 m

    DüşükCVSS 2,0İstismar yokEPSS %0

    12 Şub 2025

  • aws-cdk-lib's aspect order change causes different Permissions Boundary assigned to Role

    DüşükCVSS 2,2İstismar yok

    npm · aws-cdk-lib15 Nis 2025

Tüm zafiyet sınıfları