CWE-280
Improper Handling of Insufficient Permissions or Privileges
The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.
155 vulnerabilities with CWE-280
CVE-2025-27025
HIGH
Infinera G42 6.1.3 through 7.1 - Directory Traversal
CVSS 8.8
CVE-2025-27024
MEDIUM
Infinera G42 R6.1.3 - Info Disclosure
CVSS 6.5
CVE-2025-46708
MEDIUM
ImaginationTech DDK 23.2-24.2 - Improper Handling of Insufficient Permissions or Privileges
CVSS 4.3
CVE-2025-22256
MEDIUM
Fortinet FortiPAM <1.4.1 - Privilege Escalation
CVSS 6.3
CVE-2025-25179
HIGH
ImaginationTech DDK < 24.3 - Unauthenticated Arbitrary Physical Memory Write via GPU System Calls
CVSS 7.8
CVE-2025-3931
HIGH
Yggdrasil - Unauthenticated Privilege Escalation via DBus Method Dispatch
CVSS 7.8
CVE-2025-29826
HIGH
Microsoft Dataverse < 3.4.0.1406 - Privilege Escalation via Insufficient Permission Handling
CVSS 7.3
CVE-2025-30453
HIGH
macOS < 13.7.6, < 14.7.6, < 15.4 - Privilege Escalation to Root
CVSS 7.8
CVE-2025-46740
HIGH
SEL Blueframe OS 1.12.0 - Administrator Account Name Modification
CVSS 7.5
CVE-2025-46584
HIGH
File System Module - Info Disclosure
CVSS 7.8
CVE-2025-31173
HIGH
Kernel Futex - Privilege Escalation
CVSS 8.8
CVE-2025-31172
HIGH
Kernel Futex - Privilege Escalation
CVSS 7.8
CVE-2025-0468
HIGH
Software installed - Memory Corruption
CVSS 7.1
CVE-2025-0478
HIGH
Software installed - Memory Corruption
CVSS 7.8
CVE-2025-27521
MEDIUM
Huawei HarmonyOS - Improper Access Control
CVSS 6.8
CVE-2025-20649
MEDIUM
MediaTek Software Development Kit < 3.6 - Unauthenticated Information Disclosure via Bluetooth Stack
CVSS 6.5
CVE-2025-24029
MEDIUM
Tuleap < 16.2-7 and < 16.3.99.1737562605 - Unauthenticated Insufficient Permission Enforcement in Dashboard Widget
CVSS 5.3
CVE-2025-22129
MEDIUM
Tuleap < 16.2-5 and < 16.3.99.1736242932 - Unauthorized Information Disclosure
CVSS 4.3
CVE-2025-22395
HIGH
Dell Update Package Framework < 22.01.02 - Local Privilege Escalation and Denial of Service
CVSS 8.2
CVE-2024-55604
MEDIUM
Appsmith < 1.51 - Information Disclosure via Datasource List Access
CVSS 4.3
CVE-2024-8315
MEDIUM
B&R APROL <4.4-00P5 - Info Disclosure
CVE-2024-51459
HIGH
IBM InfoSphere Information Server 11.7 - Privilege Escalation
CVSS 8.4
CVE-2024-6697
MEDIUM
Hitachi Vantara Pentaho <10.2.0.0-9.3.0.9 - DoS
CVSS 6.5
CVE-2024-12430
HIGH
ABB AC500 V3 < 3.8.0 - Authenticated OS Command Injection via Crafted File
CVSS 7.0
CVE-2024-43705
HIGH
GPU Kernel Driver - Info Disclosure
CVSS 7.8
Details
Vulnerabilities
155