CWE-250
Medium likelihoodExecution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
341 vulnerabilities with CWE-250
CVE-2024-25421
CRITICAL
Ignite Realtime Openfire <4.9.0 - Privilege Escalation
CVSS 9.8
CVE-2024-22017
HIGH
Node.js >=18.18.0 - Privilege Escalation
CVSS 7.3
CVE-2024-1222
HIGH
PaperCut NG/MF - Privilege Escalation
CVSS 8.6
CVE-2024-23743
LOW
notion/notion < 3.1.0 - Unauthenticated Remote Code Execution via RunAsNode and enableNodeClilnspectArguments
CVSS 3.3
CVE-2023-37412
MEDIUM
IBM Aspera Faspex <5.0.10 - Privilege Escalation
CVSS 4.4
CVE-2023-30998
HIGH
IBM Security Access Manager Docker <10.0.8 - Privilege Escalation
CVSS 7.8
CVE-2023-30997
HIGH
IBM Security Access Manager Docker <10.0.8 - Privilege Escalation
CVSS 7.8
CVE-2023-38042
HIGH
Ivanti Secure Access Client < 22.7 - Local Privilege Escalation
CVSS 7.8
CVE-2023-42954
MEDIUM
FileMaker Server <20.3.1 - Privilege Escalation
CVSS 4.9
CVE-2023-50015
HIGH
Grandstream GXP14XX <1.0.8.9/GXP16XX <1.0.7.13 - Privilege Escalation
CVSS 8.8
CVE-2023-45592
MEDIUM
AiLux imx6 <imx6_1.0.7-2 - Privilege Escalation
CVSS 6.8
CVE-2023-46360
HIGH
Hardy Barth cPH2 eCharge Ladestation <1.87.0 - Privilege Escalation
CVSS 8.8
CVE-2023-52030
CRITICAL
TOTOlink A3700R v9.1.2u.5822_B20200513 - Remote Code Execution via setOpModeCfg Function
CVSS 9.8
CVE-2023-30617
MEDIUM
Kruise <1.3.1-1.5.2 - Privilege Escalation
CVSS 6.5
CVE-2023-33873
HIGH
Privilege Escalation - Privilege Escalation
CVSS 7.8
CVE-2023-6006
HIGH
PaperCut MF and NG < 23.0.1 - Privilege Escalation via Unsecured Executable Load in pc-pdl-to-image
CVSS 7.8
CVE-2023-43018
MEDIUM
IBM CICS TX Standard <11.1, Advanced <10.1.11.1 - Privilege Escalation
CVSS 5.9
CVE-2023-27313
HIGH
SnapCenter <4.9 - Privilege Escalation
CVSS 8.3
CVE-2023-27312
MEDIUM
SnapCenter Plugin for VMware vSphere <4.9 - Privilege Escalation
CVSS 5.4
CVE-2023-1943
HIGH
kOps <GCE/GCP Provider - Privilege Escalation
CVSS 8.0
CVE-2023-5207
HIGH
GitLab CE/EE <16.2.8-16.4.1 - Authenticated RCE
CVSS 8.2
CVE-2023-4003
HIGH
One Identity Password Manager <5.9.7.1 - Privilege Escalation
CVSS 7.6
CVE-2023-4662
CRITICAL
Adobe Connect < 9.0 - Remote Code Inclusion via Unnecessary Privileges
CVSS 9.8
CVE-2023-4814
HIGH
Trellix Windows DLP - Privilege Escalation
CVSS 7.1
CVE-2023-31175
HIGH
SEL-5037 SEL Grid Configurator <4.5.0.20 - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities
341
Exploit Likelihood
Medium