CWE-280

Improper Handling of Insufficient Permissions or Privileges

Parent: CWE-755 - Improper Handling of Exceptional Conditions

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

132 vulnerabilities with CWE-280
CVE-2025-6573 CRITICAL
Kernel - Info Disclosure
CVSS 9.8
CVE-2025-8109 HIGH
Software - Memory Corruption
CVSS 8.8
CVE-2025-49731 LOW
Microsoft Teams - Privilege Escalation
CVSS 3.1
CVE-2025-27025 HIGH
Infinera G42 6.1.3 through 7.1 - Directory Traversal
CVSS 8.8
CVE-2025-27024 MEDIUM
Infinera G42 R6.1.3 - Info Disclosure
CVSS 6.5
CVE-2025-46708 MEDIUM
VMware - Info Disclosure
CVSS 4.3
CVE-2025-22256 MEDIUM
Fortinet FortiPAM <1.4.1 - Privilege Escalation
CVSS 6.3
CVE-2025-25179 HIGH
Software - Memory Corruption
CVSS 7.8
CVE-2025-3931 HIGH
Yggdrasil - Privilege Escalation
CVSS 7.8
CVE-2025-29826 HIGH
Microsoft Dataverse < 3.4.0.1406 - Improper Exception Handling
CVSS 7.3
CVE-2025-30453 HIGH
macOS - Privilege Escalation
CVSS 7.8
CVE-2025-46740 HIGH
Unknown Product <Unknown Version - Privilege Escalation
CVSS 7.5
CVE-2025-46584 HIGH
File System Module - Info Disclosure
CVSS 7.8
CVE-2025-31173 HIGH
Kernel Futex - Privilege Escalation
CVSS 8.8
CVE-2025-31172 HIGH
Kernel Futex - Privilege Escalation
CVSS 7.8
CVE-2025-0468 HIGH
Software installed - Memory Corruption
CVSS 7.1
CVE-2025-0478 HIGH
Software installed - Memory Corruption
CVSS 7.8
CVE-2025-27521 MEDIUM
Huawei HarmonyOS - Improper Access Control
CVSS 6.8
CVE-2025-20649 MEDIUM
Mediatek Software Development Kit < 3.6 - Information Disclosure
CVSS 6.5
CVE-2025-24029 MEDIUM
Tuleap <16.3 - Info Disclosure
CVSS 5.3
CVE-2025-22129 MEDIUM
Tuleap <16.3 - Info Disclosure
CVSS 4.3
CVE-2025-22395 HIGH
Dell Update Package Framework < 22.01.02 - Denial of Service
CVSS 8.2
CVE-2024-55604 MEDIUM
Appsmith < 1.51 - Information Disclosure
CVSS 4.3
CVE-2024-8315 MEDIUM
B&R APROL <4.4-00P5 - Info Disclosure
CVE-2024-51459 HIGH
IBM InfoSphere Information Server 11.7 - Privilege Escalation
CVSS 8.4
Details
Vulnerabilities 132