İçeriğe atla
Noroxi

CWE-648 · 68 kayıt

Incorrect Use of Privileged APIs

Bu sınıftaki CVE’ler

68 kayıt

  • CVE-2026-76460
    74Bu hafta

    Cisco Identity Services Engine Authentication Bypass Vulnerability

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %14

    cisco · identity services engine16 Eyl 2026

  • CVE-2026-20122
    58Planlayın

    Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability

    OrtaCVSS 5,4KEVSilahlaştırılmışEPSS %25

    cisco · catalyst sd-wan manager25 Şub 2026

  • CVE-2019-14813
    42Planlayın

    A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged

    KritikCVSS 9,8İstismar yokEPSS %11

    artifex · ghostscript6 Eyl 2019

  • CVE-2019-1010178
    40Planlayın

    Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648.

    KritikCVSS 9,8İstismar yokEPSS %5

    modx · fred24 Tem 2019

  • CVE-2022-2023
    40Planlayın

    Incorrect Use of Privileged APIs in polonel/trudesk

    KritikCVSS 9,8İstismar yokEPSS %3

    trudesk project · trudesk20 Haz 2022

  • CVE-2024-11068
    39İzleyin

    D-Link DSL6740C - Incorrect Use of Privileged APIs

    KritikCVSS 9,8İstismar yokEPSS %1

    dlink · dsl6740c firmware11 Kas 2024

  • CVE-2023-4972
    39İzleyin

    Information Disclosure in Digital Yepas

    KritikCVSS 9,8İstismar yokEPSS %1

    yepas · digital yepas14 Eyl 2023

  • CVE-2019-14869
    36İzleyin

    A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privi

    YüksekCVSS 8,8İstismar yokEPSS %3

    artifex · ghostscript15 Kas 2019

  • CVE-2026-41386
    36İzleyin

    OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes

    KritikCVSS 9,1İstismar yokEPSS %1

    openclaw · openclaw28 Nis 2026

  • CVE-2026-41329
    36İzleyin

    OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalation

    KritikCVSS 9,0İstismar yokEPSS %1

    openclaw · openclaw20 Nis 2026

  • CVE-2024-37018
    36İzleyin

    The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken b

    KritikCVSS 9,1İstismar yokEPSS %0

    30 May 2024

  • CVE-2022-20956
    35İzleyin

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker

    YüksekCVSS 8,8İstismar yokEPSS %1

    cisco · identity services engine4 Kas 2022

  • CVE-2023-28062
    35İzleyin

    Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability.

    YüksekCVSS 8,8İstismar yokEPSS %1

    dell · powerprotect data manager11 Nis 2023

  • CVE-2025-5997
    35İzleyin

    Privilege Escalation in Beamsec PhishPro

    YüksekCVSS 8,8İstismar yokEPSS %0

    beamsec · phishpro28 Tem 2025

  • Duplicate Advisory: OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approve

    YüksekCVSS 8,8İstismar yok

    npm · openclaw10 Nis 2026

  • CVE-2026-35639
    34İzleyin

    OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope Validation

    YüksekCVSS 8,7İstismar yokEPSS %1

    openclaw · openclaw9 Nis 2026

  • CVE-2025-7344
    34İzleyin

    Digiwin|EAI - Privilege Escalation

    YüksekCVSS 8,7İstismar yokEPSS %1

    digiwin · eai21 Tem 2025

  • CVE-2026-35669
    34İzleyin

    OpenClaw < 2026.3.25 - Privilege Escalation via Gateway Plugin HTTP Authentication Scope

    YüksekCVSS 8,7İstismar yokEPSS %1

    openclaw · openclaw10 Nis 2026

  • CVE-2026-35663
    34İzleyin

    OpenClaw < 2026.3.25 - Privilege Escalation via Backend Reconnect Scope Self-Claim

    YüksekCVSS 8,7İstismar yokEPSS %1

    openclaw · openclaw10 Nis 2026

  • CVE-2026-41225
    34İzleyin

    iControl REST vulnerability

    YüksekCVSS 8,6İstismar yokEPSS %0

    f5 · big-ip access policy manager13 May 2026

  • CVE-2026-63727
    34İzleyin

    Anchore Enterprise Privilege Escalation via User Management API

    YüksekCVSS 8,7İstismar yokEPSS %0

    anchore · anchore enterprise28 Tem 2026

  • CVE-2022-26323
    34İzleyin

    Incorrect Use of Privileged vulnerability has been discovered on OpenText™ UCMDB and Operation Bridge Manager product.

    YüksekCVSS 8,7İstismar yokEPSS %0

    opentext™ · operations bridge manager17 Nis 2025

  • CVE-2026-35625
    34İzleyin

    OpenClaw < 2026.3.25 - Privilege Escalation via Silent Local Shared-Auth Reconnect

    YüksekCVSS 8,5İstismar yokEPSS %0

    openclaw · openclaw9 Nis 2026

  • CVE-2024-32008
    34İzleyin

    A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2).

    YüksekCVSS 8,5İstismar yokEPSS %0

    siemens · spectrum power 411 Kas 2025

  • CVE-2026-54424
    33İzleyin

    An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege.

    YüksekCVSS 8,4Kavram kanıtıEPSS %0

    unity · parsec3 Tem 2026

Tüm zafiyet sınıfları