CWE-250

Medium likelihood

Execution with Unnecessary Privileges

Parent: CWE-269 - Improper Privilege Management

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

303 vulnerabilities with CWE-250
CVE-2024-43583 HIGH
Winlogon - Privilege Escalation
CVSS 7.8
CVE-2024-8903 MEDIUM
Acronis Cyber Protect Cloud Agent <38565 - Privilege Escalation
CVSS 4.7
CVE-2024-38813 HIGH KEV
Vmware Cloud Foundation < 5.2 - Privilege Escalation
CVSS 7.5
CVE-2024-8767 CRITICAL
Acronis Backup - Info Disclosure
CVSS 9.9
CVE-2024-7387 CRITICAL
Openshift Builder - Path Traversal
CVSS 9.1
CVE-2024-35783 CRITICAL
SIMATIC BATCH V9.1, SIMATIC Information Server 2020 <V2020 SP2 Upda...
CVSS 9.1
CVE-2024-42024 HIGH
Veeam One < 12.2.0.4093 - Remote Code Execution
CVSS 8.8
CVE-2024-45034 HIGH
Apache Airflow <2.10.1 - Code Injection
CVSS 8.8
CVE-2024-5623 HIGH
B&R APROL <= R 4.4-00P3 - Privilege Escalation
CVSS 7.8
CVE-2024-5622 HIGH
B&R APROL <4.2.07P3, <4.4-00P3 - Privilege Escalation
CVSS 7.8
CVE-2024-20478 MEDIUM
Cisco APIC/Cloud Network Controller - Code Injection
CVSS 6.5
CVE-2024-36398 HIGH
SINEC NMS <V3.0 - Privilege Escalation
CVSS 7.8
CVE-2024-6913 HIGH
PerkinElmer ProcessPlus <1.11.6507.0 - Privilege Escalation
CVSS 8.8
CVE-2024-20435 HIGH
Cisco AsyncOS - Command Injection
CVSS 8.8
CVE-2024-6834 CRITICAL
APIML Spring Cloud Gateway - Privilege Escalation
CVSS 9.0
CVE-2024-21184 HIGH
Oracle Database <19.23 - Privilege Escalation
CVSS 7.2
CVE-2024-35154 HIGH
IBM WebSphere Application Server <9.0 - Authenticated RCE
CVSS 7.2
CVE-2024-32853 MEDIUM
Dell PowerScale OneFS <9.7.0.2 - Privilege Escalation
CVSS 4.4
CVE-2024-3330 CRITICAL
Spotfire - RCE
CVSS 9.9
CVE-2024-31890 HIGH
IBM TCP/IP <7.5 - Privilege Escalation
CVSS 7.8
CVE-2024-3498 HIGH
Printer <version> - Privilege Escalation
CVSS 7.8
CVE-2024-27147 HIGH
Toshiba Printers - Privilege Escalation
CVSS 7.4
CVE-2024-27146 MEDIUM
Toshiba Printers - Privilege Escalation
CVSS 6.7
CVE-2024-27143 CRITICAL
Toshiba Printers - RCE
CVSS 9.8
CVE-2024-0084 HIGH
Nvidia Virtual Gpu < 13.11 - Denial of Service
CVSS 7.8
Details
Vulnerabilities 303
Exploit Likelihood Medium