CWE-250
Medium likelihoodExecution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
341 vulnerabilities with CWE-250
CVE-2023-20217
MEDIUM
Cisco ThousandEyes Enterprise Agent - Privilege Escalation
CVSS 5.5
CVE-2023-32486
MEDIUM
Dell PowerScale OneFS 9.5.0.0-9.5.0.3 - Privilege Escalation
CVSS 6.7
CVE-2023-38641
HIGH
SICAM TOOLBOX II <V07.10 - Privilege Escalation
CVSS 7.8
CVE-2023-39508
HIGH
Apache Airflow < 2.6.0 - Authenticated Privilege Escalation and DAG Access Bypass via Run Task Feature
CVSS 8.8
CVE-2023-39261
MEDIUM
JetBrains IntelliJ IDEA <2023.2 - Privilege Escalation
CVSS 5.2
CVE-2023-20210
MEDIUM
Cisco BroadWorks - Privilege Escalation
CVSS 6.0
CVE-2023-34118
HIGH
Zoom Rooms for Windows <5.14.5 - Privilege Escalation
CVSS 7.3
CVE-2023-25521
HIGH
NVIDIA DGX A100/A800 Firmware < 1.21 - Privilege Escalation via SBIOS Input Parameter Validation
CVSS 7.5
CVE-2023-2002
MEDIUM
Linux Kernel < 6.4 - Unauthorized Bluetooth Management Command Execution via HCI Sockets
CVSS 6.8
CVE-2023-32080
CRITICAL
Wings <1.7.5 & 1.11.0 <1.11.6 - Code Injection
CVSS 9.0
CVE-2023-1966
HIGH
Instruments with Illumina Universal Copy Service v1.x-v2.x - Privil...
CVSS 7.4
CVE-2023-0664
HIGH
QEMU Guest Agent - Privilege Escalation
CVSS 7.8
CVE-2023-27247
MEDIUM
Cynet Client Agent <4.6.0.8010 - Privilege Escalation
CVSS 4.4
CVE-2023-27010
HIGH
Wondershare Dr.Fone <12.9.6 - Privilege Escalation
CVSS 7.8
CVE-2022-38695
HIGH
Unisoc SC9863A/T310/T610/T618/T606/T612/T616/T760/T770/T820/S8000 - Local Privilege Escalation via BootRom Command Index
CVSS 7.8
CVE-2022-38694
HIGH
Unisoc SC9863A/T310/T610/T618 - Local Privilege Escalation via Unchecked BootRom Write Address
CVSS 7.8
CVE-2022-38691
HIGH
Unisoc SC9863A/T310/T610/T618 - Local Privilege Escalation via BootROM Certificate Type Validation Bypass
CVSS 7.8
CVE-2022-34384
HIGH
Dell SupportAssist and Update < 4.5.0 - Local Privilege Escalation in Advanced Driver Restore
CVSS 7.8
CVE-2022-41290
HIGH
IBM AIX <7.4 - Privilege Escalation
CVSS 8.4
CVE-2022-43553
HIGH
EdgeMax EdgeRouter Firmware < 2.0.9-hotfix.5 - Authenticated Remote Code Execution via Operator Account
CVSS 8.8
CVE-2022-3088
HIGH
UC-8100A-ME-T <v3.5 - Path Traversal
CVSS 7.8
CVE-2022-41950
MEDIUM
super_xray 0.2-beta - Privilege Escalation via Inaccurate Default Permissions
CVSS 6.4
CVE-2022-44544
CRITICAL
Mahara 21.04.0-21.04.6, 21.10.0-21.10.4, 22.04.0-22.04.2 - Remote Code Execution via PDF Export with Ghostscript
CVSS 9.8
CVE-2022-39286
HIGH
Jupyter Core <4.11.2 - Code Injection
CVSS 8.8
CVE-2022-22239
HIGH
Juniper Networks Junos OS Evolved - Privilege Escalation
CVSS 8.2
Details
Vulnerabilities
341
Exploit Likelihood
Medium