CWE-648
Low likelihoodIncorrect Use of Privileged APIs
The product does not conform to the API requirements for a function call that requires extra privileges. This could allow attackers to gain privileges by causing the function to be called incorrectly.
61 vulnerabilities with CWE-648
CVE-2024-11068
CRITICAL
D-Link DSL6740C - Privilege Escalation
CVSS 9.8
CVE-2024-46978
MEDIUM
XWiki Platform <14.10.21 - Info Disclosure
CVSS 6.5
CVE-2024-37018
CRITICAL
OpenDaylight 0.15.3 - SSRF
CVSS 9.1
CVE-2024-22042
HIGH
Unicam FX - Privilege Escalation
CVSS 7.8
CVE-2023-6522
HIGH
ExtremePacs Extreme XDS <3914 - Privilege Escalation
CVSS 7.2
CVE-2023-4993
HIGH
SoliPay Mobile App <5.0.8 - Privilege Escalation
CVSS 7.5
CVE-2023-6151
HIGH
ESKOM Computer e-municipality <v.105 - Privilege Escalation
CVSS 7.5
CVE-2023-6150
HIGH
ESKOM Computer e-municipality <v.105 - Privilege Escalation
CVSS 7.5
CVE-2023-4972
CRITICAL
Yepas Digital Yepas <1.0.1 - Privilege Escalation
CVSS 9.8
CVE-2023-4009
HIGH
MongoDB Ops Manager <5.0.22, <6.0.17 - Privilege Escalation
CVSS 7.2
CVE-2023-20136
MEDIUM
Cisco Secure Workload - Privilege Escalation
CVSS 4.3
CVE-2023-29507
CRITICAL
XWiki Commons - Info Disclosure
CVSS 9.1
CVE-2023-28062
HIGH
Dell PPDM <19.12-19.10 - Privilege Escalation
CVSS 8.8
CVE-2022-26323
HIGH
OpenText Operations Bridge Manager - Privilege Escalation
CVE-2022-20965
MEDIUM
Cisco Identity Services Engine - Privilege Escalation
CVSS 4.3
CVE-2022-4805
MEDIUM
usememos/memos <0.9.1 - Privilege Escalation
CVSS 4.3
CVE-2022-4796
HIGH
usememos/memos <0.9.1 - Privilege Escalation
CVSS 8.1
CVE-2022-4687
HIGH
usememos/memos <0.9.0 - Privilege Escalation
CVSS 8.1
CVE-2022-20956
HIGH
Cisco ISE - Auth Bypass
CVSS 7.1
CVE-2022-23720
HIGH
PingID Windows Login <2.8 - Privilege Escalation
CVSS 7.5
CVE-2022-2023
CRITICAL
polonel/trudesk <1.2.4 - Privilege Escalation
CVSS 9.8
CVE-2022-24821
MEDIUM
XWiki Platform - SSRF
CVSS 6.8
CVE-2022-24073
HIGH
Whale browser <3.12.129.18 - SSRF
CVSS 7.1
CVE-2022-24071
MEDIUM
Whale browser <3.12.129.46 - RCE
CVSS 4.3
CVE-2020-7927
HIGH
MongoDB Ops Manager <4.2.17, <4.3.9, <4.4.2 - Info Disclosure
CVSS 8.1
Details
Vulnerabilities
61
Exploit Likelihood
Low