CWE-280

Improper Handling of Insufficient Permissions or Privileges

Parent: CWE-755 - Improper Handling of Exceptional Conditions

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

144 vulnerabilities with CWE-280
CVE-2025-58770 HIGH
AMI APTIO V 5.0-5.041 - Privilege Escalation via BIOS Local Access
CVSS 8.8
CVE-2025-58122 MEDIUM
Checkmk 2.4.0 - Insufficient Permission Validation in REST API
CVSS 5.4
CVE-2025-58121 MEDIUM
Checkmk <2.4.0p16 - Info Disclosure
CVSS 5.4
CVE-2025-58410 HIGH
ImaginationTech DDK - Privilege Escalation via GPU System Call Memory Protection Bypass
CVSS 7.5
CVE-2025-62510 HIGH
FileRise < 1.5.0 - Improper Access Control via Folder Name Inference
CVSS 8.1
CVE-2025-62509 HIGH
FileRise < 1.4.0 - Unauthorized File Operations via Insecure Folder Ownership Inference
CVSS 8.1
CVE-2025-62176 MEDIUM
Mastodon <4.4.6-4.2.27 - Info Disclosure
CVSS 4.3
CVE-2025-45376 HIGH
Dell Repository Manager <3.4.8 - Privilege Escalation
CVSS 7.5
CVE-2025-58457 MEDIUM
Apache ZooKeeper <3.9.4 - Privilege Escalation
CVSS 4.3
CVE-2025-59040 MEDIUM
Tuleap < 16.11.99.1757427600 - Insufficient Permission Validation in Backlog Item Representation
CVSS 4.3
CVE-2025-50170 HIGH
Windows Cloud Files Mini Filter Driver - Privilege Escalation
CVSS 7.8
CVE-2025-6573 CRITICAL
Imagination Technologies Graphics DDK <=25.1 RTM - Kernel Information Disclosure
CVSS 9.8
CVE-2025-8109 HIGH
Imagination Technologies Graphics DDK 1.13 RTM-24.2 RTM2 and >=24.3 RTM - Unauthorized Memory Write via ptrace
CVSS 8.8
CVE-2025-49731 LOW
Microsoft Teams - Privilege Escalation
CVSS 3.1
CVE-2025-27025 HIGH
Infinera G42 6.1.3 through 7.1 - Directory Traversal
CVSS 8.8
CVE-2025-27024 MEDIUM
Infinera G42 R6.1.3 - Info Disclosure
CVSS 6.5
CVE-2025-46708 MEDIUM
ImaginationTech DDK 23.2-24.2 - Improper Handling of Insufficient Permissions or Privileges
CVSS 4.3
CVE-2025-22256 MEDIUM
Fortinet FortiPAM <1.4.1 - Privilege Escalation
CVSS 6.3
CVE-2025-25179 HIGH
ImaginationTech DDK < 24.3 - Unauthenticated Arbitrary Physical Memory Write via GPU System Calls
CVSS 7.8
CVE-2025-3931 HIGH
Yggdrasil - Unauthenticated Privilege Escalation via DBus Method Dispatch
CVSS 7.8
CVE-2025-29826 HIGH
Microsoft Dataverse < 3.4.0.1406 - Privilege Escalation via Insufficient Permission Handling
CVSS 7.3
CVE-2025-30453 HIGH
macOS < 13.7.6, < 14.7.6, < 15.4 - Privilege Escalation to Root
CVSS 7.8
CVE-2025-46740 HIGH
SEL Blueframe OS 1.12.0 - Administrator Account Name Modification
CVSS 7.5
CVE-2025-46584 HIGH
File System Module - Info Disclosure
CVSS 7.8
CVE-2025-31173 HIGH
Kernel Futex - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities 144