CWE-280
Improper Handling of Insufficient Permissions or Privileges
The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.
144 vulnerabilities with CWE-280
CVE-2025-31172
HIGH
Kernel Futex - Privilege Escalation
CVSS 7.8
CVE-2025-0468
HIGH
Software installed - Memory Corruption
CVSS 7.1
CVE-2025-0478
HIGH
Software installed - Memory Corruption
CVSS 7.8
CVE-2025-27521
MEDIUM
Huawei HarmonyOS - Improper Access Control
CVSS 6.8
CVE-2025-20649
MEDIUM
MediaTek Software Development Kit < 3.6 - Unauthenticated Information Disclosure via Bluetooth Stack
CVSS 6.5
CVE-2025-24029
MEDIUM
Tuleap < 16.2-7 and < 16.3.99.1737562605 - Unauthenticated Insufficient Permission Enforcement in Dashboard Widget
CVSS 5.3
CVE-2025-22129
MEDIUM
Tuleap < 16.2-5 and < 16.3.99.1736242932 - Unauthorized Information Disclosure
CVSS 4.3
CVE-2025-22395
HIGH
Dell Update Package Framework < 22.01.02 - Local Privilege Escalation and Denial of Service
CVSS 8.2
CVE-2024-55604
MEDIUM
Appsmith < 1.51 - Information Disclosure via Datasource List Access
CVSS 4.3
CVE-2024-8315
MEDIUM
B&R APROL <4.4-00P5 - Info Disclosure
CVE-2024-51459
HIGH
IBM InfoSphere Information Server 11.7 - Privilege Escalation
CVSS 8.4
CVE-2024-6697
MEDIUM
Hitachi Vantara Pentaho <10.2.0.0-9.3.0.9 - DoS
CVSS 6.5
CVE-2024-12430
HIGH
ABB AC500 V3 < 3.8.0 - Authenticated OS Command Injection via Crafted File
CVSS 7.0
CVE-2024-43705
HIGH
GPU Kernel Driver - Info Disclosure
CVSS 7.8
CVE-2024-42194
LOW
HCL BigFix Inventory - Privilege Escalation
CVSS 3.1
CVE-2024-46874
HIGH
Ruijie Reyee OS <2.320 - Privilege Escalation
CVSS 8.1
CVE-2024-43702
HIGH
Imagination Technologies Graphics DDK 1.13 RTM-24.2 - Unprivileged Physical Memory Access via GPU
CVSS 8.1
CVE-2024-4692
LOW
OpenText Application Automation Tools <24.1 - Privilege Escalation
CVSS 2.4
CVE-2024-4211
LOW
OpenText Application Automation Tools - Info Disclosure
CVSS 2.4
CVE-2024-47767
MEDIUM
Tuleap <15.13.99.113, <15.13-5, <15.12-5 - Info Disclosure
CVSS 4.3
CVE-2024-47766
MEDIUM
Tuleap <15.13.99.110, <15.13-5, <15.12-5 - Info Disclosure
CVSS 4.9
CVE-2024-46988
MEDIUM
Tuleap < 15.12-6 and < 15.13.99.40 - Unauthorized Information Disclosure via Email Notifications
CVSS 4.8
CVE-2024-24116
CRITICAL
Ruijie RG-NBS2009G-P - Improper Authentication
CVSS 9.8
CVE-2024-8451
HIGH
PLANET Technology - Privilege Escalation
CVSS 7.5
CVE-2024-6660
HIGH
BookingPress - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities
144