CWE-250

Medium likelihood

Execution with Unnecessary Privileges

Parent: CWE-269 - Improper Privilege Management

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

303 vulnerabilities with CWE-250
CVE-2023-27010 HIGH
Wondershare Dr.Fone <12.9.6 - Privilege Escalation
CVSS 7.8
CVE-2022-38695 HIGH
BootRom - Privilege Escalation
CVSS 7.8
CVE-2022-38694 HIGH
BootRom - Privilege Escalation
CVSS 7.8
CVE-2022-38691 HIGH
BootROM - Privilege Escalation
CVSS 7.8
CVE-2022-34384 HIGH
Dell Alienware Update < 4.5.0 - Privilege Escalation
CVSS 7.8
CVE-2022-41290 HIGH
IBM AIX <7.4 - Privilege Escalation
CVSS 8.4
CVE-2022-43553 HIGH
EdgeRouters <2.0.9-hotfix.4 - RCE
CVSS 8.8
CVE-2022-3088 HIGH
UC-8100A-ME-T <v3.5 - Path Traversal
CVSS 7.8
CVE-2022-41950 MEDIUM
Super Xray - Privilege Escalation
CVSS 6.4
CVE-2022-44544 CRITICAL
Mahara <21.04.7-22.10.0 - RCE
CVSS 9.8
CVE-2022-39286 HIGH
Jupyter Core <4.11.2 - Code Injection
CVSS 8.8
CVE-2022-22239 HIGH
Juniper Networks Junos OS Evolved - Privilege Escalation
CVSS 8.2
CVE-2022-40182 HIGH
Desigo PXM30-1 <V02.20.126.11-41 - Info Disclosure
CVSS 8.8
CVE-2022-2634 CRITICAL
Web Application - Code Injection
CVSS 10.0
CVE-2022-1744 MEDIUM
Dominion Voting Systems ImageCast X - Privilege Escalation
CVSS 6.8
CVE-2022-1517 CRITICAL
LRM - RCE
CVSS 10.0
CVE-2022-32535 MEDIUM
Bosch Ethernet switch PRA-ES8P2S <1.01.05 - Privilege Escalation
CVSS 4.8
CVE-2022-1808 HIGH
polonel/trudesk <1.2.3 - Privilege Escalation
CVSS 8.8
CVE-2022-30695 HIGH
Acronis Snap Deploy <3640 - Privilege Escalation
CVSS 7.8
CVE-2022-0071 HIGH
Hotdog <1.0.2 - Privilege Escalation
CVSS 8.8
CVE-2022-0070 HIGH
Apache Log4j - Privilege Escalation
CVSS 8.8
CVE-2022-20676 MEDIUM
Cisco IOS XE - Privilege Escalation
CVSS 5.1
CVE-2022-27578 HIGH
Sick Overall Equipment Effectiveness - Privilege Escalation
CVSS 7.8
CVE-2022-24113 HIGH
Acronis - Privilege Escalation
CVSS 7.8
CVE-2022-21699 HIGH
IPython - Code Injection
CVSS 8.2
Details
Vulnerabilities 303
Exploit Likelihood Medium