CWE-280

Improper Handling of Insufficient Permissions or Privileges

Parent: CWE-755 - Improper Handling of Exceptional Conditions

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

155 vulnerabilities with CWE-280
CVE-2024-42194 LOW
HCL BigFix Inventory - Privilege Escalation
CVSS 3.1
CVE-2024-46874 HIGH
Ruijie Reyee OS <2.320 - Privilege Escalation
CVSS 8.1
CVE-2024-43702 HIGH
Imagination Technologies Graphics DDK 1.13 RTM-24.2 - Unprivileged Physical Memory Access via GPU
CVSS 8.1
CVE-2024-4692 LOW
OpenText Application Automation Tools <24.1 - Privilege Escalation
CVSS 2.4
CVE-2024-4211 LOW
OpenText Application Automation Tools - Info Disclosure
CVSS 2.4
CVE-2024-47767 MEDIUM
Tuleap <15.13.99.113, <15.13-5, <15.12-5 - Info Disclosure
CVSS 4.3
CVE-2024-47766 MEDIUM
Tuleap <15.13.99.110, <15.13-5, <15.12-5 - Info Disclosure
CVSS 4.9
CVE-2024-46988 MEDIUM
Tuleap < 15.12-6 and < 15.13.99.40 - Unauthorized Information Disclosure via Email Notifications
CVSS 4.8
CVE-2024-24116 CRITICAL
Ruijie RG-NBS2009G-P - Improper Authentication
CVSS 9.8
CVE-2024-8451 HIGH
PLANET Technology - Privilege Escalation
CVSS 7.5
CVE-2024-6660 HIGH
BookingPress - Privilege Escalation
CVSS 8.8
CVE-2024-36451 HIGH
Webmin <2.003 - Privilege Escalation
CVSS 8.8
CVE-2024-39691 MEDIUM
matrix-appservice-irc < 2.0.1 - Information Disclosure via Homeserver Timestamp Manipulation
CVSS 4.3
CVE-2024-6302 HIGH
Conduit <0.6.0 - Privilege Escalation
CVSS 8.1
CVE-2024-5163 CRITICAL
com.transsion.carlcare - Info Disclosure
CVSS 9.8
CVE-2024-4468 MEDIUM
WordPress <9.9 - Privilege Escalation
CVSS 4.3
CVE-2024-35228 MEDIUM
Wagtail 6.0.0-6.0.4 and 6.1.0-6.1.1 - Authenticated Improper Permission Handling in Settings Module
CVSS 5.5
CVE-2024-36112 MEDIUM
Nautobot <1.6.22 & 2.0.0 - Info Disclosure
CVSS 6.3
CVE-2024-29852 LOW
Veeam Backup Enterprise Manager - Info Disclosure
CVSS 2.7
CVE-2024-35301 MEDIUM
JetBrains TeamCity <2024.03.1 - Info Disclosure
CVSS 5.5
CVE-2024-27837 LOW
macOS Sonoma <14.5 - Info Disclosure
CVSS 3.3
CVE-2024-23704 HIGH
Android - Missing Authorization in WifiDialogActivity
CVSS 7.8
CVE-2024-32882 LOW
Wagtail 6.0.0-6.0.3 - Permission Bypass via FieldPanel Permission Argument
CVSS 2.7
CVE-2024-32488 HIGH
Foxit PDF Reader & Editor <2024.1 - Privilege Escalation
CVSS 7.8
CVE-2024-32000 MEDIUM
matrix-appservice-irc <2.0.0 - Info Disclosure
CVSS 4.3
Details
Vulnerabilities 155