CWE-250

Medium likelihood

Execution with Unnecessary Privileges

Parent: CWE-269 - Improper Privilege Management

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

326 vulnerabilities with CWE-250
CVE-2022-38694 HIGH
Unisoc SC9863A/T310/T610/T618 - Local Privilege Escalation via Unchecked BootRom Write Address
CVSS 7.8
CVE-2022-38691 HIGH
Unisoc SC9863A/T310/T610/T618 - Local Privilege Escalation via BootROM Certificate Type Validation Bypass
CVSS 7.8
CVE-2022-34384 HIGH
Dell SupportAssist and Update < 4.5.0 - Local Privilege Escalation in Advanced Driver Restore
CVSS 7.8
CVE-2022-41290 HIGH
IBM AIX <7.4 - Privilege Escalation
CVSS 8.4
CVE-2022-43553 HIGH
EdgeMax EdgeRouter Firmware < 2.0.9-hotfix.5 - Authenticated Remote Code Execution via Operator Account
CVSS 8.8
CVE-2022-3088 HIGH
UC-8100A-ME-T <v3.5 - Path Traversal
CVSS 7.8
CVE-2022-41950 MEDIUM
super_xray 0.2-beta - Privilege Escalation via Inaccurate Default Permissions
CVSS 6.4
CVE-2022-44544 CRITICAL
Mahara 21.04.0-21.04.6, 21.10.0-21.10.4, 22.04.0-22.04.2 - Remote Code Execution via PDF Export with Ghostscript
CVSS 9.8
CVE-2022-39286 HIGH
Jupyter Core <4.11.2 - Code Injection
CVSS 8.8
CVE-2022-22239 HIGH
Juniper Networks Junos OS Evolved - Privilege Escalation
CVSS 8.2
CVE-2022-40182 HIGH
Desigo PXM30-1 <V02.20.126.11-41 - Info Disclosure
CVSS 8.8
CVE-2022-2634 CRITICAL
Digi ConnectPort X2d <2020-01-01 - Unauthenticated RCE via File Upload
CVSS 10.0
CVE-2022-1744 MEDIUM
Dominion Voting Systems ImageCast X - Privilege Escalation
CVSS 6.8
CVE-2022-1517 CRITICAL
Illumina Local Run Manager 1.3 to 3.1 - Unauthenticated Remote Code Execution
CVSS 10.0
CVE-2022-32535 MEDIUM
Bosch Ethernet switch PRA-ES8P2S <1.01.05 - Privilege Escalation
CVSS 4.8
CVE-2022-1808 HIGH
polonel/trudesk <1.2.3 - Privilege Escalation
CVSS 8.8
CVE-2022-30695 HIGH
Acronis Snap Deploy <3640 - Privilege Escalation
CVSS 7.8
CVE-2022-0071 HIGH
Hotdog <1.0.2 - Privilege Escalation
CVSS 8.8
CVE-2022-0070 HIGH
Apache Log4j - Privilege Escalation
CVSS 8.8
CVE-2022-20676 MEDIUM
Cisco IOS XE - Privilege Escalation
CVSS 5.1
CVE-2022-27578 HIGH
SICK Overall Equipment Effectiveness - Privilege Escalation via Writable Installation Directory
CVSS 7.8
CVE-2022-24113 HIGH
Acronis Agent < 27147 - Local Privilege Escalation via Excessive Child Process Permissions
CVSS 7.8
CVE-2022-21699 HIGH
IPython < 5.10.0 - Arbitrary Code Execution via Cross-User Temporary File Mismanagement
CVSS 8.2
CVE-2021-47700 HIGH
Nagios XI <5.8.7 - Privilege Escalation
CVSS 7.8
CVE-2021-38118 MEDIUM
OpenText iManager <3.2.4.0000 - Info Disclosure
CVSS 5.5
Details
Vulnerabilities 326
Exploit Likelihood Medium