CWE-280

Improper Handling of Insufficient Permissions or Privileges

Parent: CWE-755 - Improper Handling of Exceptional Conditions

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

125 vulnerabilities with CWE-280
CVE-2026-21736
Non-privileged Software - Privilege Escalation
CVE-2026-0047 HIGH
ActivityManagerService - Privilege Escalation
CVSS 8.4
CVE-2026-1772 MEDIUM
RTU500 - Info Disclosure
CVSS 5.3
CVE-2026-23857 HIGH
Dell Update Package (DUP) Framework <24.12.00 - Privilege Escalation
CVSS 8.2
CVE-2025-67848 HIGH
Moodle < 4.1.22 - Authentication Bypass
CVSS 8.1
CVE-2026-20817 HIGH
Windows Error Reporting - Privilege Escalation
CVSS 7.8
CVE-2025-46066 CRITICAL
Automai Director <25.2.0 - Privilege Escalation
CVSS 9.9
CVE-2025-64997 MEDIUM
Checkmk - Information Disclosure
CVSS 6.5
CVE-2025-43527 HIGH
macOS Tahoe <26.2 - Privilege Escalation
CVSS 7.8
CVE-2025-58770 HIGH
APTIov - Privilege Escalation
CVSS 8.8
CVE-2025-58122 MEDIUM
Checkmk - Information Disclosure
CVSS 5.4
CVE-2025-58121 MEDIUM
Checkmk <2.4.0p16 - Info Disclosure
CVSS 5.4
CVE-2025-58410 HIGH
Software - Memory Corruption
CVSS 7.5
CVE-2025-62510 HIGH
Filerise < 1.5.0 - Improper Access Control
CVSS 8.1
CVE-2025-62509 HIGH
Filerise < 1.4.0 - Improper Access Control
CVSS 8.1
CVE-2025-62176 MEDIUM
Mastodon <4.4.6-4.2.27 - Info Disclosure
CVSS 4.3
CVE-2025-45376 HIGH
Dell Repository Manager <3.4.8 - Privilege Escalation
CVSS 7.5
CVE-2025-58457 MEDIUM
Apache ZooKeeper <3.9.4 - Privilege Escalation
CVSS 4.3
CVE-2025-59040 MEDIUM
Tuleap - Info Disclosure
CVSS 4.3
CVE-2025-50170 HIGH
Windows Cloud Files Mini Filter Driver - Privilege Escalation
CVSS 7.8
CVE-2025-6573 CRITICAL
Kernel - Info Disclosure
CVSS 9.8
CVE-2025-8109 HIGH
Software - Memory Corruption
CVSS 8.8
CVE-2025-49731 LOW
Microsoft Teams - Privilege Escalation
CVSS 3.1
CVE-2025-27025 HIGH
Unknown - Path Traversal
CVSS 8.8
CVE-2025-27024 MEDIUM
Infinera G42 R6.1.3 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 125