CWE-648 · 68 kayıt
Incorrect Use of Privileged APIs
Bu sınıftaki CVE’ler
68 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
74Bu hafta | CVE-2026-76460Silahlaştırılmış | Cisco Identity Services Engine Authentication Bypass Vulnerabilitycisco · identity services engine · CWE-648 | Kritik10,0 | KEV | %14,0 | 16 Eyl 2026 |
58Planlayın | CVE-2026-20122Silahlaştırılmış | Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerabilitycisco · catalyst sd-wan manager · CWE-648 | Orta5,4 | KEV | %25,0 | 25 Şub 2026 |
42Planlayın | CVE-2019-14813İstismar yok | A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged artifex · ghostscript · CWE-648 | Kritik9,8 | — | %11,4 | 6 Eyl 2019 |
40Planlayın | CVE-2019-1010178İstismar yok | Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648.modx · fred · CWE-648 | Kritik9,8 | — | %4,6 | 24 Tem 2019 |
40Planlayın | CVE-2022-2023İstismar yok | Incorrect Use of Privileged APIs in polonel/trudesktrudesk project · trudesk · CWE-648 | Kritik9,8 | — | %3,2 | 20 Haz 2022 |
39İzleyin | CVE-2024-11068İstismar yok | D-Link DSL6740C - Incorrect Use of Privileged APIsdlink · dsl6740c firmware · CWE-648 | Kritik9,8 | — | %1,2 | 11 Kas 2024 |
39İzleyin | CVE-2023-4972İstismar yok | Information Disclosure in Digital Yepasyepas · digital yepas · CWE-648 | Kritik9,8 | — | %0,7 | 14 Eyl 2023 |
36İzleyin | CVE-2019-14869İstismar yok | A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its priviartifex · ghostscript · CWE-648 | Yüksek8,8 | — | %3,4 | 15 Kas 2019 |
36İzleyin | CVE-2026-41386İstismar yok | OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codesopenclaw · openclaw · CWE-648 | Kritik9,1 | — | %0,6 | 28 Nis 2026 |
36İzleyin | CVE-2026-41329İstismar yok | OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalationopenclaw · openclaw · CWE-648 | Kritik9,0 | — | %0,5 | 20 Nis 2026 |
36İzleyin | CVE-2024-37018İstismar yok | The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken bCWE-648 | Kritik9,1 | — | %0,4 | 30 May 2024 |
35İzleyin | CVE-2022-20956İstismar yok | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker cisco · identity services engine · CWE-648 | Yüksek8,8 | — | %1,4 | 4 Kas 2022 |
35İzleyin | CVE-2023-28062İstismar yok | Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability.dell · powerprotect data manager · CWE-648 | Yüksek8,8 | — | %0,8 | 11 Nis 2023 |
35İzleyin | CVE-2025-5997İstismar yok | Privilege Escalation in Beamsec PhishProbeamsec · phishpro · CWE-648 | Yüksek8,8 | — | %0,4 | 28 Tem 2025 |
35İzleyin | GHSA-r3v5-2grc-429hİstismar yok | Duplicate Advisory: OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approvenpm · openclaw · CWE-648 | Yüksek8,8 | — | — | 10 Nis 2026 |
34İzleyin | CVE-2026-35639İstismar yok | OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope Validationopenclaw · openclaw · CWE-648 | Yüksek8,7 | — | %0,8 | 9 Nis 2026 |
34İzleyin | CVE-2025-7344İstismar yok | Digiwin|EAI - Privilege Escalationdigiwin · eai · CWE-648 | Yüksek8,7 | — | %0,5 | 21 Tem 2025 |
34İzleyin | CVE-2026-35669İstismar yok | OpenClaw < 2026.3.25 - Privilege Escalation via Gateway Plugin HTTP Authentication Scopeopenclaw · openclaw · CWE-648 | Yüksek8,7 | — | %0,5 | 10 Nis 2026 |
34İzleyin | CVE-2026-35663İstismar yok | OpenClaw < 2026.3.25 - Privilege Escalation via Backend Reconnect Scope Self-Claimopenclaw · openclaw · CWE-648 | Yüksek8,7 | — | %0,5 | 10 Nis 2026 |
34İzleyin | CVE-2026-41225İstismar yok | iControl REST vulnerabilityf5 · big-ip access policy manager · CWE-648 | Yüksek8,6 | — | %0,5 | 13 May 2026 |
34İzleyin | CVE-2026-63727İstismar yok | Anchore Enterprise Privilege Escalation via User Management APIanchore · anchore enterprise · CWE-648 | Yüksek8,7 | — | %0,4 | 28 Tem 2026 |
34İzleyin | CVE-2022-26323İstismar yok | Incorrect Use of Privileged vulnerability has been discovered on OpenText™ UCMDB and Operation Bridge Manager product.opentext™ · operations bridge manager · CWE-648 | Yüksek8,7 | — | %0,3 | 17 Nis 2025 |
34İzleyin | CVE-2026-35625İstismar yok | OpenClaw < 2026.3.25 - Privilege Escalation via Silent Local Shared-Auth Reconnectopenclaw · openclaw · CWE-648 | Yüksek8,5 | — | %0,3 | 9 Nis 2026 |
34İzleyin | CVE-2024-32008İstismar yok | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2).siemens · spectrum power 4 · CWE-648 | Yüksek8,5 | — | %0,1 | 11 Kas 2025 |
33İzleyin | CVE-2026-54424Kavram kanıtı | An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege.unity · parsec · CWE-648 | Yüksek8,4 | — | %0,2 | 3 Tem 2026 |
- CVE-2026-7646074Bu hafta
Cisco Identity Services Engine Authentication Bypass Vulnerability
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %14cisco · identity services engine16 Eyl 2026
- CVE-2026-2012258Planlayın
Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability
OrtaCVSS 5,4KEVSilahlaştırılmışEPSS %25cisco · catalyst sd-wan manager25 Şub 2026
- CVE-2019-1481342Planlayın
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged
KritikCVSS 9,8İstismar yokEPSS %11artifex · ghostscript6 Eyl 2019
- CVE-2019-101017840Planlayın
Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648.
KritikCVSS 9,8İstismar yokEPSS %5modx · fred24 Tem 2019
- CVE-2022-202340Planlayın
Incorrect Use of Privileged APIs in polonel/trudesk
KritikCVSS 9,8İstismar yokEPSS %3trudesk project · trudesk20 Haz 2022
- CVE-2024-1106839İzleyin
D-Link DSL6740C - Incorrect Use of Privileged APIs
KritikCVSS 9,8İstismar yokEPSS %1dlink · dsl6740c firmware11 Kas 2024
- CVE-2023-497239İzleyin
Information Disclosure in Digital Yepas
KritikCVSS 9,8İstismar yokEPSS %1yepas · digital yepas14 Eyl 2023
- CVE-2019-1486936İzleyin
A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privi
YüksekCVSS 8,8İstismar yokEPSS %3artifex · ghostscript15 Kas 2019
- CVE-2026-4138636İzleyin
OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes
KritikCVSS 9,1İstismar yokEPSS %1openclaw · openclaw28 Nis 2026
- CVE-2026-4132936İzleyin
OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalation
KritikCVSS 9,0İstismar yokEPSS %1openclaw · openclaw20 Nis 2026
- CVE-2024-3701836İzleyin
The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken b
KritikCVSS 9,1İstismar yokEPSS %030 May 2024
- CVE-2022-2095635İzleyin
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker
YüksekCVSS 8,8İstismar yokEPSS %1cisco · identity services engine4 Kas 2022
- CVE-2023-2806235İzleyin
Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability.
YüksekCVSS 8,8İstismar yokEPSS %1dell · powerprotect data manager11 Nis 2023
- CVE-2025-599735İzleyin
Privilege Escalation in Beamsec PhishPro
YüksekCVSS 8,8İstismar yokEPSS %0beamsec · phishpro28 Tem 2025
- GHSA-r3v5-2grc-429h35İzleyin
Duplicate Advisory: OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approve
YüksekCVSS 8,8İstismar yoknpm · openclaw10 Nis 2026
- CVE-2026-3563934İzleyin
OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope Validation
YüksekCVSS 8,7İstismar yokEPSS %1openclaw · openclaw9 Nis 2026
- CVE-2025-734434İzleyin
Digiwin|EAI - Privilege Escalation
YüksekCVSS 8,7İstismar yokEPSS %1digiwin · eai21 Tem 2025
- CVE-2026-3566934İzleyin
OpenClaw < 2026.3.25 - Privilege Escalation via Gateway Plugin HTTP Authentication Scope
YüksekCVSS 8,7İstismar yokEPSS %1openclaw · openclaw10 Nis 2026
- CVE-2026-3566334İzleyin
OpenClaw < 2026.3.25 - Privilege Escalation via Backend Reconnect Scope Self-Claim
YüksekCVSS 8,7İstismar yokEPSS %1openclaw · openclaw10 Nis 2026
- CVE-2026-4122534İzleyin
iControl REST vulnerability
YüksekCVSS 8,6İstismar yokEPSS %0f5 · big-ip access policy manager13 May 2026
- CVE-2026-6372734İzleyin
Anchore Enterprise Privilege Escalation via User Management API
YüksekCVSS 8,7İstismar yokEPSS %0anchore · anchore enterprise28 Tem 2026
- CVE-2022-2632334İzleyin
Incorrect Use of Privileged vulnerability has been discovered on OpenText™ UCMDB and Operation Bridge Manager product.
YüksekCVSS 8,7İstismar yokEPSS %0opentext™ · operations bridge manager17 Nis 2025
- CVE-2026-3562534İzleyin
OpenClaw < 2026.3.25 - Privilege Escalation via Silent Local Shared-Auth Reconnect
YüksekCVSS 8,5İstismar yokEPSS %0openclaw · openclaw9 Nis 2026
- CVE-2024-3200834İzleyin
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2).
YüksekCVSS 8,5İstismar yokEPSS %0siemens · spectrum power 411 Kas 2025
- CVE-2026-5442433İzleyin
An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege.
YüksekCVSS 8,4Kavram kanıtıEPSS %0unity · parsec3 Tem 2026