CWE-250

Medium likelihood

Execution with Unnecessary Privileges

Parent: CWE-269 - Improper Privilege Management

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

341 vulnerabilities with CWE-250
CVE-2025-6893 CRITICAL
Moxa EDR-G9010/EDR-8010/EDF-G1002-BP/TN-4900/NAT-102/NAT-108/OnCell G4302-LTE4 - Privilege Escalation via API Endpoint
CVE-2025-61909 MEDIUM
Icinga 2 <2.15.1-2.14.7-2.13.13 - Privilege Escalation
CVSS 4.4
CVE-2025-34515 CRITICAL
Ilevia EVE X1 Server <4.7.18.0.eden - Privilege Escalation
CVSS 9.8
CVE-2025-57780 HIGH
F5OS-A F5OS-C - Privilege Escalation
CVSS 8.8
CVE-2025-8486 HIGH
Lenovo PCManager < 5.1.140.9262 - Authenticated Privilege Escalation
CVSS 7.8
CVE-2025-61958 HIGH
F5 BIG-IP 15.1.0-15.1.10.8 - Authenticated Privilege Escalation via iHealth Command
CVSS 8.7
CVE-2025-59481 HIGH
BIG-IP TMOS Shell - Privilege Escalation
CVSS 8.7
CVE-2025-50505 HIGH
Clash Verge Rev <2.3.0 - Privilege Escalation
CVSS 7.8
CVE-2025-36356 CRITICAL
IBM Security Verify Access <11.0.1.0 - Privilege Escalation
CVSS 9.3
CVE-2025-58432 HIGH
ZimaOS < 1.4.1 - Unauthenticated Arbitrary File Write via /v2_1/files/file/uploadV2 Endpoint
CVSS 7.8
CVE-2025-58431 MEDIUM
ZimaOS < 1.4.1 - Unauthenticated Arbitrary File Read as Root via /v2_1/files/file/download Endpoint
CVSS 6.2
CVE-2025-37128 MEDIUM
HPE Aruba Networking EdgeConnect - Privilege Escalation
CVSS 6.8
CVE-2025-56557 CRITICAL
Tuya Smart Life App <5.6.1 - Privilege Escalation
CVSS 9.1
CVE-2025-57119 CRITICAL
Online Library Management System <3.0 - Privilege Escalation
CVSS 9.8
CVE-2025-42958 CRITICAL
SAP NetWeaver - Unauthenticated Privilege Escalation via Missing Authentication Check
CVSS 9.1
CVE-2025-0080 HIGH
Google Android Tapjacking/Overlay Attack - Privilege Escalation
CVSS 7.8
CVE-2025-0079 HIGH
Multiple Locations - Privilege Escalation
CVSS 7.8
CVE-2025-0078 HIGH
Google Android SELinux Bypass - Privilege Escalation
CVSS 8.8
CVE-2025-50753 HIGH
Mitrastar GPT-2741GNAC-N2 - Command Injection
CVSS 8.4
CVE-2025-33120 HIGH
IBM QRadar SIEM <7.5.0 UP13 - Privilege Escalation
CVSS 7.8
CVE-2025-21110 MEDIUM
Dell Data Lakehouse < 1.5.0.0 - Denial of Service via Execution with Unnecessary Privileges
CVSS 6.7
CVE-2025-8907 HIGH
H3C M2 NAS V100R006 - Privilege Escalation
CVSS 7.0
CVE-2025-40767 HIGH
SINEC Traffic Analyzer <V3.0 - Privilege Escalation
CVSS 7.8
CVE-2025-3892 MEDIUM
AXIS OS 12.0.0-12.5.31 - Privilege Escalation via Unsigned ACAP Application Installation
CVSS 6.7
CVE-2025-42943 MEDIUM
SAP GUI for Windows - Info Disclosure
CVSS 4.5
Details
Vulnerabilities 341
Exploit Likelihood Medium