CWE-280
Improper Handling of Insufficient Permissions or Privileges
The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.
144 vulnerabilities with CWE-280
CVE-2025-58770
HIGH
AMI APTIO V 5.0-5.041 - Privilege Escalation via BIOS Local Access
CVSS 8.8
CVE-2025-58122
MEDIUM
Checkmk 2.4.0 - Insufficient Permission Validation in REST API
CVSS 5.4
CVE-2025-58121
MEDIUM
Checkmk <2.4.0p16 - Info Disclosure
CVSS 5.4
CVE-2025-58410
HIGH
ImaginationTech DDK - Privilege Escalation via GPU System Call Memory Protection Bypass
CVSS 7.5
CVE-2025-62510
HIGH
FileRise < 1.5.0 - Improper Access Control via Folder Name Inference
CVSS 8.1
CVE-2025-62509
HIGH
FileRise < 1.4.0 - Unauthorized File Operations via Insecure Folder Ownership Inference
CVSS 8.1
CVE-2025-62176
MEDIUM
Mastodon <4.4.6-4.2.27 - Info Disclosure
CVSS 4.3
CVE-2025-45376
HIGH
Dell Repository Manager <3.4.8 - Privilege Escalation
CVSS 7.5
CVE-2025-58457
MEDIUM
Apache ZooKeeper <3.9.4 - Privilege Escalation
CVSS 4.3
CVE-2025-59040
MEDIUM
Tuleap < 16.11.99.1757427600 - Insufficient Permission Validation in Backlog Item Representation
CVSS 4.3
CVE-2025-50170
HIGH
Windows Cloud Files Mini Filter Driver - Privilege Escalation
CVSS 7.8
CVE-2025-6573
CRITICAL
Imagination Technologies Graphics DDK <=25.1 RTM - Kernel Information Disclosure
CVSS 9.8
CVE-2025-8109
HIGH
Imagination Technologies Graphics DDK 1.13 RTM-24.2 RTM2 and >=24.3 RTM - Unauthorized Memory Write via ptrace
CVSS 8.8
CVE-2025-49731
LOW
Microsoft Teams - Privilege Escalation
CVSS 3.1
CVE-2025-27025
HIGH
Infinera G42 6.1.3 through 7.1 - Directory Traversal
CVSS 8.8
CVE-2025-27024
MEDIUM
Infinera G42 R6.1.3 - Info Disclosure
CVSS 6.5
CVE-2025-46708
MEDIUM
ImaginationTech DDK 23.2-24.2 - Improper Handling of Insufficient Permissions or Privileges
CVSS 4.3
CVE-2025-22256
MEDIUM
Fortinet FortiPAM <1.4.1 - Privilege Escalation
CVSS 6.3
CVE-2025-25179
HIGH
ImaginationTech DDK < 24.3 - Unauthenticated Arbitrary Physical Memory Write via GPU System Calls
CVSS 7.8
CVE-2025-3931
HIGH
Yggdrasil - Unauthenticated Privilege Escalation via DBus Method Dispatch
CVSS 7.8
CVE-2025-29826
HIGH
Microsoft Dataverse < 3.4.0.1406 - Privilege Escalation via Insufficient Permission Handling
CVSS 7.3
CVE-2025-30453
HIGH
macOS < 13.7.6, < 14.7.6, < 15.4 - Privilege Escalation to Root
CVSS 7.8
CVE-2025-46740
HIGH
SEL Blueframe OS 1.12.0 - Administrator Account Name Modification
CVSS 7.5
CVE-2025-46584
HIGH
File System Module - Info Disclosure
CVSS 7.8
CVE-2025-31173
HIGH
Kernel Futex - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities
144