CWE-250

Medium likelihood

Execution with Unnecessary Privileges

Parent: CWE-269 - Improper Privilege Management

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

341 vulnerabilities with CWE-250
CVE-2024-25421 CRITICAL
Ignite Realtime Openfire <4.9.0 - Privilege Escalation
CVSS 9.8
CVE-2024-22017 HIGH
Node.js >=18.18.0 - Privilege Escalation
CVSS 7.3
CVE-2024-1222 HIGH
PaperCut NG/MF - Privilege Escalation
CVSS 8.6
CVE-2024-23743 LOW
notion/notion < 3.1.0 - Unauthenticated Remote Code Execution via RunAsNode and enableNodeClilnspectArguments
CVSS 3.3
CVE-2023-37412 MEDIUM
IBM Aspera Faspex <5.0.10 - Privilege Escalation
CVSS 4.4
CVE-2023-30998 HIGH
IBM Security Access Manager Docker <10.0.8 - Privilege Escalation
CVSS 7.8
CVE-2023-30997 HIGH
IBM Security Access Manager Docker <10.0.8 - Privilege Escalation
CVSS 7.8
CVE-2023-38042 HIGH
Ivanti Secure Access Client < 22.7 - Local Privilege Escalation
CVSS 7.8
CVE-2023-42954 MEDIUM
FileMaker Server <20.3.1 - Privilege Escalation
CVSS 4.9
CVE-2023-50015 HIGH
Grandstream GXP14XX <1.0.8.9/GXP16XX <1.0.7.13 - Privilege Escalation
CVSS 8.8
CVE-2023-45592 MEDIUM
AiLux imx6 <imx6_1.0.7-2 - Privilege Escalation
CVSS 6.8
CVE-2023-46360 HIGH
Hardy Barth cPH2 eCharge Ladestation <1.87.0 - Privilege Escalation
CVSS 8.8
CVE-2023-52030 CRITICAL
TOTOlink A3700R v9.1.2u.5822_B20200513 - Remote Code Execution via setOpModeCfg Function
CVSS 9.8
CVE-2023-30617 MEDIUM
Kruise <1.3.1-1.5.2 - Privilege Escalation
CVSS 6.5
CVE-2023-33873 HIGH
Privilege Escalation - Privilege Escalation
CVSS 7.8
CVE-2023-6006 HIGH
PaperCut MF and NG < 23.0.1 - Privilege Escalation via Unsecured Executable Load in pc-pdl-to-image
CVSS 7.8
CVE-2023-43018 MEDIUM
IBM CICS TX Standard <11.1, Advanced <10.1.11.1 - Privilege Escalation
CVSS 5.9
CVE-2023-27313 HIGH
SnapCenter <4.9 - Privilege Escalation
CVSS 8.3
CVE-2023-27312 MEDIUM
SnapCenter Plugin for VMware vSphere <4.9 - Privilege Escalation
CVSS 5.4
CVE-2023-1943 HIGH
kOps <GCE/GCP Provider - Privilege Escalation
CVSS 8.0
CVE-2023-5207 HIGH
GitLab CE/EE <16.2.8-16.4.1 - Authenticated RCE
CVSS 8.2
CVE-2023-4003 HIGH
One Identity Password Manager <5.9.7.1 - Privilege Escalation
CVSS 7.6
CVE-2023-4662 CRITICAL
Adobe Connect < 9.0 - Remote Code Inclusion via Unnecessary Privileges
CVSS 9.8
CVE-2023-4814 HIGH
Trellix Windows DLP - Privilege Escalation
CVSS 7.1
CVE-2023-31175 HIGH
SEL-5037 SEL Grid Configurator <4.5.0.20 - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities 341
Exploit Likelihood Medium