CWE-250

Medium likelihood

Execution with Unnecessary Privileges

Parent: CWE-269 - Improper Privilege Management

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

341 vulnerabilities with CWE-250
CVE-2025-46696 MEDIUM
Dell Secure Connect Gateway (SCG) <5.31 - Privilege Escalation
CVSS 6.4
CVE-2025-1977 HIGH
NPort 6100-G2/6200-G2 Series - Privilege Escalation
CVE-2025-33224 CRITICAL
NVIDIA Isaac Launchable - Privilege Escalation
CVSS 9.8
CVE-2025-33223 CRITICAL
NVIDIA Isaac Launchable - Privilege Escalation
CVSS 9.8
CVE-2025-34290 HIGH
Versa SASE Client for Windows <7.9.4 - Privilege Escalation
CVE-2025-13911 MEDIUM
Ignition SCADA - Privilege Escalation
CVSS 6.4
CVE-2025-40602 MEDIUM KEV
SonicWall SMA6200/SMA6210/SMA7200/SMA7210/SMA8200v < 12.4.3-03245 Local Privilege Escalation
CVSS 6.6
CVE-2025-14096 HIGH
Radiometer Products - Info Disclosure
CVSS 8.4
CVE-2025-13506 HIGH
Nebim V3 ERP <3.0.1 - Privilege Escalation
CVSS 8.8
CVE-2025-67510 CRITICAL
neuron-ai < 2.8.12 - Unauthenticated Arbitrary SQL Execution via MySQLWriteTool
CVSS 9.4
CVE-2025-48573 HIGH
MediaSessionRecord - Privilege Escalation
CVSS 7.8
CVE-2025-62876 MEDIUM
lightdm-kde-greeter <6.0.4 - Privilege Escalation
CVE-2025-9055 MEDIUM
AXIS OS 12.0.0-12.7.31 - Authenticated Privilege Escalation via VAPIX Edge Storage API
CVSS 6.4
CVE-2025-46430 HIGH
Dell Display and Peripheral Manager <2.1.2.12 - Privilege Escalation
CVSS 7.3
CVE-2025-36186 HIGH
IBM Db2 <12.1.4 - Privilege Escalation
CVSS 7.4
CVE-2025-10885 HIGH
Autodesk Installer < 2.19 - Privilege Escalation via Insufficient Binary Validation
CVSS 7.8
CVE-2025-43990 HIGH
Dell Command Monitor <10.12.3.28 - Privilege Escalation
CVSS 7.3
CVE-2025-33003 HIGH
IBM InfoSphere Information Server <11.7.1.6 - Privilege Escalation
CVSS 7.8
CVE-2025-34274 CRITICAL
Nagios Log Server <2024R2.0.3 - Privilege Escalation
CVSS 9.8
CVE-2025-36137 HIGH
IBM Sterling Connect Direct - Privilege Escalation
CVSS 7.2
CVE-2025-62503 MEDIUM
Apache Airflow 3.0.0 through 3.1.1 - Privilege Escalation
CVSS 4.6
CVE-2025-62402 MEDIUM
Apache Airflow 3.0.0-3.1.0 - Unauthenticated Remote Code Execution via /api/v2/dagReports
CVSS 5.4
CVE-2025-43017 CRITICAL
HP ThinPro 8.1 - Privilege Escalation
CVSS 9.8
CVE-2025-6949 CRITICAL
Moxa EDR-G9010/EDR-8010/EDF-G1002-BP/TN-4900/NAT-102/NAT-108/OnCell G4302-LTE4 - Privilege Escalation via API
CVE-2025-6894 MEDIUM
Moxa EDR-G9010/EDR-8010/EDF-G1002-BP/TN-4900/NAT-102/NAT-108/OnCell G4302-LTE4 - Privilege Escalation via API Bypass
Details
Vulnerabilities 341
Exploit Likelihood Medium