CWE-280

Improper Handling of Insufficient Permissions or Privileges

Parent: CWE-755 - Improper Handling of Exceptional Conditions

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

155 vulnerabilities with CWE-280
CVE-2025-27025 HIGH
Infinera G42 6.1.3 through 7.1 - Directory Traversal
CVSS 8.8
CVE-2025-27024 MEDIUM
Infinera G42 R6.1.3 - Info Disclosure
CVSS 6.5
CVE-2025-46708 MEDIUM
ImaginationTech DDK 23.2-24.2 - Improper Handling of Insufficient Permissions or Privileges
CVSS 4.3
CVE-2025-22256 MEDIUM
Fortinet FortiPAM <1.4.1 - Privilege Escalation
CVSS 6.3
CVE-2025-25179 HIGH
ImaginationTech DDK < 24.3 - Unauthenticated Arbitrary Physical Memory Write via GPU System Calls
CVSS 7.8
CVE-2025-3931 HIGH
Yggdrasil - Unauthenticated Privilege Escalation via DBus Method Dispatch
CVSS 7.8
CVE-2025-29826 HIGH
Microsoft Dataverse < 3.4.0.1406 - Privilege Escalation via Insufficient Permission Handling
CVSS 7.3
CVE-2025-30453 HIGH
macOS < 13.7.6, < 14.7.6, < 15.4 - Privilege Escalation to Root
CVSS 7.8
CVE-2025-46740 HIGH
SEL Blueframe OS 1.12.0 - Administrator Account Name Modification
CVSS 7.5
CVE-2025-46584 HIGH
File System Module - Info Disclosure
CVSS 7.8
CVE-2025-31173 HIGH
Kernel Futex - Privilege Escalation
CVSS 8.8
CVE-2025-31172 HIGH
Kernel Futex - Privilege Escalation
CVSS 7.8
CVE-2025-0468 HIGH
Software installed - Memory Corruption
CVSS 7.1
CVE-2025-0478 HIGH
Software installed - Memory Corruption
CVSS 7.8
CVE-2025-27521 MEDIUM
Huawei HarmonyOS - Improper Access Control
CVSS 6.8
CVE-2025-20649 MEDIUM
MediaTek Software Development Kit < 3.6 - Unauthenticated Information Disclosure via Bluetooth Stack
CVSS 6.5
CVE-2025-24029 MEDIUM
Tuleap < 16.2-7 and < 16.3.99.1737562605 - Unauthenticated Insufficient Permission Enforcement in Dashboard Widget
CVSS 5.3
CVE-2025-22129 MEDIUM
Tuleap < 16.2-5 and < 16.3.99.1736242932 - Unauthorized Information Disclosure
CVSS 4.3
CVE-2025-22395 HIGH
Dell Update Package Framework < 22.01.02 - Local Privilege Escalation and Denial of Service
CVSS 8.2
CVE-2024-55604 MEDIUM
Appsmith < 1.51 - Information Disclosure via Datasource List Access
CVSS 4.3
CVE-2024-8315 MEDIUM
B&R APROL <4.4-00P5 - Info Disclosure
CVE-2024-51459 HIGH
IBM InfoSphere Information Server 11.7 - Privilege Escalation
CVSS 8.4
CVE-2024-6697 MEDIUM
Hitachi Vantara Pentaho <10.2.0.0-9.3.0.9 - DoS
CVSS 6.5
CVE-2024-12430 HIGH
ABB AC500 V3 < 3.8.0 - Authenticated OS Command Injection via Crafted File
CVSS 7.0
CVE-2024-43705 HIGH
GPU Kernel Driver - Info Disclosure
CVSS 7.8
Details
Vulnerabilities 155