CWE-250
Medium likelihoodExecution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
326 vulnerabilities with CWE-250
CVE-2026-4667
HIGH
HP System Optimizer - Escalation of Privilege
CVE-2026-33793
HIGH
Junos OS and Junos OS Evolved: When an unsigned Python op script configuration is present, a local low privileged user can compromise the system
CVSS 7.8
CVE-2026-4498
HIGH
Execution with Unnecessary Privileges in Kibana Leading to reading index data beyond their direct Elasticsearch RBAC scope
CVSS 7.7
CVE-2026-1346
CRITICAL
Security Vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
CVSS 9.3
CVE-2026-34877
CRITICAL
Mbed TLS 2.19.0-3.6.5, 4.0.0 - Memory Corruption
CVSS 9.8
CVE-2026-25212
CRITICAL
Percona PMM <3.7 - Privilege Escalation
CVSS 9.9
CVE-2026-4606
CRITICAL
GeoVision ERM Improper Privilege Assignment Leads to SYSTEM-Level Privilege
CVE-2026-3315
HIGH
ASSA ABLOY Visionline <1.33 - Privilege Escalation
CVSS 7.8
CVE-2026-30225
MEDIUM
OliveTin <3000.11.1 - Privilege Escalation
CVSS 5.3
CVE-2026-20017
MEDIUM
Cisco Secure FTD Software - Command Injection
CVSS 6.0
CVE-2026-21426
MEDIUM
Dell PowerScale OneFS <9.10.1.6/9.11.0.0-9.12.0.1 - Privilege Escal...
CVSS 6.7
CVE-2026-21424
MEDIUM
Dell PowerScale OneFS <9.10.1.6/9.11.0.0-9.12.0.1 - Privilege Escal...
CVSS 6.7
CVE-2026-21421
MEDIUM
Dell PowerScale OneFS <9.10.1.6/9.11.0.0-9.12.0.1 - Privilege Escal...
CVSS 6.7
CVE-2026-21882
HIGH
theshit <0.2.0 - Privilege Escalation
CVSS 8.4
CVE-2026-20037
MEDIUM
Cisco UCS Manager - Privilege Escalation
CVSS 4.4
CVE-2026-27208
CRITICAL
bleon-ethical/api-gateway-deploy 1.0.0 - Command Injection
CVSS 9.2
CVE-2026-27002
CRITICAL
OpenClaw <2026.2.15 - Privilege Escalation
CVSS 9.8
CVE-2026-25740
MEDIUM
Captive Browser <25.11-26.05 - Command Injection
CVE-2026-0870
HIGH
GIGABYTE MacroHub < 2.3.1 - Authenticated Local Privilege Escalation via Improper Privilege Management
CVSS 7.8
CVE-2026-25643
CRITICAL
Frigate < 0.16.4 - Remote Command Execution via go2rtc exec Directive
CVSS 9.1
CVE-2026-22549
MEDIUM
F5 BIG-IP Container Ingress Services 1.0.0-1.13.9 - Unauthenticated Excessive Privilege Assignment
CVSS 4.9
CVE-2026-1680
HIGH
Edgemo Local Admin Service 1.2.7.23180 - Privilege Escalation
CVSS 7.8
CVE-2026-23742
HIGH
Skipper < 0.23.0 - Unauthenticated Information Disclosure via Lua Filter Script Injection
CVSS 8.8
CVE-2026-23528
MEDIUM
Dask distributed < 2026.1.0 - Cross-Site Scripting via Jupyter Lab Dashboard Proxy
CVSS 6.1
CVE-2025-12694
HIGH
Forcepoint - Local Privilege Escalation in VPN Client
Details
Vulnerabilities
326
Exploit Likelihood
Medium