CWE-250

Medium likelihood

Execution with Unnecessary Privileges

Parent: CWE-269 - Improper Privilege Management

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

303 vulnerabilities with CWE-250
CVE-2026-23742 HIGH
Skipper <0.23.0 - Info Disclosure
CVSS 8.8
CVE-2026-23528 MEDIUM
Dask distributed <2026.1.0 - XSS
CVSS 6.1
CVE-2025-69783 HIGH
OpenEDR 2.5.1.0 - Privilege Escalation
CVSS 7.8
CVE-2025-12690 HIGH
Forcepoint NGFW Engine <=7.3.0 - Privilege Escalation
CVE-2025-1790 MEDIUM
Genetec Sipelia Plugin - Privilege Escalation
CVE-2025-13375 CRITICAL
IBM CCA 7.5.52-8.4.82 - Privilege Escalation
CVSS 9.8
CVE-2025-58383 HIGH
Brocade Fabric OS <9.2.1c2 - Privilege Escalation
CVSS 7.2
CVE-2025-58379 MEDIUM
Brocade Fabric OS <9.2.1 - Info Disclosure
CVSS 5.5
CVE-2025-36184 HIGH
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 1...
CVSS 7.2
CVE-2025-36059 MEDIUM
IBM Business Automation Workflow <25.0.0-24.0.0 - Privilege Escalation
CVSS 4.7
CVE-2025-40942 HIGH
Siemens Telecontrol Server Basic < 3.1.2.4 - Privilege Escalation
CVSS 8.8
CVE-2025-12420 CRITICAL
ServiceNow AI Platform - Privilege Escalation
CVSS 9.8
CVE-2025-46696 MEDIUM
Dell Secure Connect Gateway (SCG) <5.31 - Privilege Escalation
CVSS 6.4
CVE-2025-1977 HIGH
NPort 6100-G2/6200-G2 Series - Privilege Escalation
CVE-2025-33224 CRITICAL
NVIDIA Isaac Launchable - Privilege Escalation
CVSS 9.8
CVE-2025-33223 CRITICAL
NVIDIA Isaac Launchable - Privilege Escalation
CVSS 9.8
CVE-2025-34290 HIGH
Versa SASE Client for Windows <7.9.4 - Privilege Escalation
CVE-2025-13911 MEDIUM
Ignition SCADA - Privilege Escalation
CVSS 6.4
CVE-2025-40602 MEDIUM KEV
Sonicwall Sma6200 Firmware < 12.4.3-03245 - Privilege Escalation
CVSS 6.6
CVE-2025-14096 HIGH
Radiometer Products - Info Disclosure
CVSS 8.4
CVE-2025-13506 HIGH
Nebim V3 ERP <3.0.1 - Privilege Escalation
CVSS 8.8
CVE-2025-67510 CRITICAL
Neuron <2.8.11 - SQL Injection
CVSS 9.4
CVE-2025-48573 HIGH
MediaSessionRecord - Privilege Escalation
CVSS 7.8
CVE-2025-62876 MEDIUM
lightdm-kde-greeter <6.0.4 - Privilege Escalation
CVE-2025-9055 MEDIUM
VAPIX Edge - Privilege Escalation
CVSS 6.4
Details
Vulnerabilities 303
Exploit Likelihood Medium