CWE-648

Low likelihood

Incorrect Use of Privileged APIs

Parent: CWE-269 - Improper Privilege Management

The product does not conform to the API requirements for a function call that requires extra privileges. This could allow attackers to gain privileges by causing the function to be called incorrectly.

61 vulnerabilities with CWE-648
CVE-2024-11068 CRITICAL
D-Link DSL6740C - Privilege Escalation
CVSS 9.8
CVE-2024-46978 MEDIUM
XWiki Platform <14.10.21 - Info Disclosure
CVSS 6.5
CVE-2024-37018 CRITICAL
OpenDaylight 0.15.3 - SSRF
CVSS 9.1
CVE-2024-22042 HIGH
Unicam FX - Privilege Escalation
CVSS 7.8
CVE-2023-6522 HIGH
ExtremePacs Extreme XDS <3914 - Privilege Escalation
CVSS 7.2
CVE-2023-4993 HIGH
SoliPay Mobile App <5.0.8 - Privilege Escalation
CVSS 7.5
CVE-2023-6151 HIGH
ESKOM Computer e-municipality <v.105 - Privilege Escalation
CVSS 7.5
CVE-2023-6150 HIGH
ESKOM Computer e-municipality <v.105 - Privilege Escalation
CVSS 7.5
CVE-2023-4972 CRITICAL
Yepas Digital Yepas <1.0.1 - Privilege Escalation
CVSS 9.8
CVE-2023-4009 HIGH
MongoDB Ops Manager <5.0.22, <6.0.17 - Privilege Escalation
CVSS 7.2
CVE-2023-20136 MEDIUM
Cisco Secure Workload - Privilege Escalation
CVSS 4.3
CVE-2023-29507 CRITICAL
XWiki Commons - Info Disclosure
CVSS 9.1
CVE-2023-28062 HIGH
Dell PPDM <19.12-19.10 - Privilege Escalation
CVSS 8.8
CVE-2022-26323 HIGH
OpenText Operations Bridge Manager - Privilege Escalation
CVE-2022-20965 MEDIUM
Cisco Identity Services Engine - Privilege Escalation
CVSS 4.3
CVE-2022-4805 MEDIUM
usememos/memos <0.9.1 - Privilege Escalation
CVSS 4.3
CVE-2022-4796 HIGH
usememos/memos <0.9.1 - Privilege Escalation
CVSS 8.1
CVE-2022-4687 HIGH
usememos/memos <0.9.0 - Privilege Escalation
CVSS 8.1
CVE-2022-20956 HIGH
Cisco ISE - Auth Bypass
CVSS 7.1
CVE-2022-23720 HIGH
PingID Windows Login <2.8 - Privilege Escalation
CVSS 7.5
CVE-2022-2023 CRITICAL
polonel/trudesk <1.2.4 - Privilege Escalation
CVSS 9.8
CVE-2022-24821 MEDIUM
XWiki Platform - SSRF
CVSS 6.8
CVE-2022-24073 HIGH
Whale browser <3.12.129.18 - SSRF
CVSS 7.1
CVE-2022-24071 MEDIUM
Whale browser <3.12.129.46 - RCE
CVSS 4.3
CVE-2020-7927 HIGH
MongoDB Ops Manager <4.2.17, <4.3.9, <4.4.2 - Info Disclosure
CVSS 8.1
Details
Vulnerabilities 61
Exploit Likelihood Low