CWE-264
1,421 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-264page 26 of 29
- CVE-2020-13922MEDIUMCVSS 6.5EG 6.52021-01-11
Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.
- CVE-2020-1619MEDIUMCVSS 6.0EG 6.02020-04-08
A privilege escalation vulnerability in Juniper Networks QFX10K Series, EX9200 Series, MX Series, and PTX Series with Next-Generation Routing Engine (NG-RE), allows a local authenticated high privileged user to access the underlying WRL ho…
- CVE-2020-1630MEDIUMCVSS 5.0EG 5.02020-04-08
A privilege escalation vulnerability in Juniper Networks Junos OS devices configured with dual Routing Engines (RE), Virtual Chassis (VC) or high-availability cluster may allow a local authenticated low-privileged user with access to the s…
- CVE-2020-3112HIGHCVSS 8.8EG 8.82020-02-19
A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to elevate privileges on the application. The vulnerability is due to insufficient access control validation…
- CVE-2020-3115HIGHCVSS 8.8EG 8.82020-01-26
A vulnerability in the CLI of the Cisco SD-WAN Solution vManage software could allow an authenticated, local attacker to elevate privileges to root-level privileges on the underlying operating system. The vulnerability is due to insufficie…
- CVE-2020-3180HIGHCVSS 7.8EG 7.82020-07-16
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that has a default, static password. This account has root privileges. The vulnerability exis…
- CVE-2020-3208MEDIUMCVSS 6.7EG 6.72020-06-03
A vulnerability in the image verification feature of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) could allow an authenticated, local attacker to boot a malicious software image on an af…
- CVE-2020-3213MEDIUMCVSS 6.7EG 6.72020-06-03
A vulnerability in the ROMMON of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to those of the root user of the underlying operating system. The vulnerability is due to the ROMMON allowing for spe…
- CVE-2020-3214MEDIUMCVSS 6.7EG 6.72020-06-03
A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to escalate their privileges to a user with root-level privileges. The vulnerability is due to insufficient validation of user-supplied content. This vul…
- CVE-2020-3215MEDIUMCVSS 6.7EG 6.72020-06-03
A vulnerability in the Virtual Services Container of Cisco IOS XE Software could allow an authenticated, local attacker to gain root-level privileges on an affected device. The vulnerability is due to insufficient validation of a user-supp…
- CVE-2020-3227CRITICALCVSS 9.8EG 9.82020-06-03
A vulnerability in the authorization controls for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an unauthenticated, remote attacker to execute Cisco IOx API commands without proper authorization. The…
- CVE-2020-3229HIGHCVSS 8.8EG 8.82020-06-03
A vulnerability in Role Based Access Control (RBAC) functionality of Cisco IOS XE Web Management Software could allow a Read-Only authenticated, remote attacker to execute commands or configuration changes as an Admin user. The vulnerabili…
- CVE-2020-3265HIGHCVSS 7.8EG 7.82020-03-19
A vulnerability in Cisco SD-WAN Solution software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating system. The vulnerability is due to insufficient input validation. An attacker could e…
- CVE-2020-3379HIGHCVSS 7.8EG 7.82020-07-16
A vulnerability in Cisco SD-WAN Solution Software could allow an authenticated, local attacker to elevate privileges to Administrator on the underlying operating system. The vulnerability is due to insufficient input validation. An attacke…
- CVE-2020-3426HIGHCVSS 7.5EG 7.52020-09-24
A vulnerability in the implementation of the Low Power, Wide Area (LPWA) subsystem of Cisco IOS Software for Cisco 800 Series Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) c…
- CVE-2020-3443HIGHCVSS 8.8EG 8.82020-08-26
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges and execute commands with higher privileges. The vulnerability is due to insufficient authorization o…
- CVE-2020-3473HIGHCVSS 7.8EG 7.82020-09-04
A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local CLI shell user to elevate privileges and gain full administrative control of the device. The vulnerability is …
- CVE-2020-3485MEDIUMCVSS 6.3EG 6.32020-08-26
A vulnerability in the role-based access control (RBAC) functionality of the web management software of Cisco Vision Dynamic Signage Director could allow an authenticated, remote attacker to access resources that they should not be able to…
- CVE-2020-3530HIGHCVSS 8.4EG 8.42020-09-04
A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to execute that command, even though administrative privileges should be required. The attacker must …
- CVE-2020-36528MEDIUMCVSS 5.5EG 6.52022-06-07
A vulnerability, which was classified as critical, was found in Platinum Mobile 1.0.4.850. Affected is /MobileHandler.ashx which leads to broken access control. The attack requires authentication. Upgrading to version 1.0.4.851 is able to …
- CVE-2020-7254HIGHCVSS 7.7EG 7.72020-03-12
Privilege Escalation vulnerability in the command line interface in McAfee Advanced Threat Defense (ATD) 4.x prior to 4.8.2 allows local users to execute arbitrary code via improper access controls on the sudo command.
- CVE-2020-7255LOWCVSS 3.9EG 3.92020-04-15
Privilege escalation vulnerability in the administrative user interface in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows local users to gain elevated privileges via ENS not checking user permissions…
- CVE-2020-7257HIGHCVSS 8.4EG 8.42020-04-15
Privilege escalation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows local users to cause the deletion and creation of files they would not normally have permission to through alterin…
- CVE-2020-7259MEDIUMCVSS 6.6EG 6.62020-04-15
Exploitation of Privilege/Trust vulnerability in file in McAfee Endpoint Security (ENS) Prior to 10.7.0 February 2020 Update allows local users to bypass local security protection via a carefully crafted input file
- CVE-2020-7260HIGHCVSS 7.3EG 7.32020-03-26
DLL Side Loading vulnerability in the installer for McAfee Application and Change Control (MACC) prior to 8.3 allows local users to execute arbitrary code via execution from a compromised folder.
- CVE-2020-7263MEDIUMCVSS 6.5EG 6.72020-04-01
Improper access control vulnerability in ESconfigTool.exe in McAfee Endpoint Security (ENS) for Windows all current versions allows local administrator to alter ENS configuration up to and including disabling all protection offered by ENS …
- CVE-2020-7352HIGHCVSS 8.4EG 8.82020-08-06
The GalaxyClientService component of GOG Galaxy runs with elevated SYSTEM privileges in a Windows environment. Due to the software shipping with embedded, static RSA private key, an attacker with this key material and local user permission…
- CVE-2020-8092LOWCVSS 1.6EG 1.62020-01-30
A privilege escalation vulnerability in BDLDaemon as used in Bitdefender Antivirus for Mac allows a local attacker to obtain authentication tokens for requests submitted to the Bitdefender Cloud. This issue affects: Bitdefender Bitdefender…
- CVE-2020-8093MEDIUMCVSS 5.3EG 5.32020-01-30
A vulnerability in the AntivirusforMac binary as used in Bitdefender Antivirus for Mac allows an attacker to inject a library using DYLD environment variable to cause third-party code execution
- CVE-2020-8478MEDIUMCVSS 5.3EG 5.32020-04-29
Insufficient protection of the inter-process communication functions in ABB System 800xA products OPC Server for AC 800M, MMS Server for AC 800M and Base Software for SoftControl (all published versions) enables an attacker authenticated o…
- CVE-2020-8484HIGHCVSS 7.8EG 7.82020-04-29
Insufficient protection of the inter-process communication functions in ABB System 800xA for DCI (all published versions) enables an attacker authenticated on the local system to inject data, allowing reads and writes to the controllers or…
- CVE-2020-8485HIGHCVSS 7.8EG 7.82020-04-29
Insufficient protection of the inter-process communication functions in ABB System 800xA for MOD 300 (all published versions) enables an attacker authenticated on the local system to inject data, allowing reads and writes to the controller…
- CVE-2020-8486HIGHCVSS 6.6EG 7.82020-04-29
Insufficient protection of the inter-process communication functions in ABB System 800xA RNRP (all published versions) enables an attacker authenticated on the local system to inject data, affect node redundancy handling.
- CVE-2020-8487HIGHCVSS 6.6EG 7.82020-04-29
Insufficient protection of the inter-process communication functions in ABB System 800xA Base (all published versions) enables an attacker authenticated on the local system to inject data, affect node redundancy handling.
- CVE-2020-8488HIGHCVSS 7.8EG 7.82020-04-29
Insufficient protection of the inter-process communication functions in ABB System 800xA Batch Management (all published versions) enables an attacker authenticated on the local system to inject data, affecting User Interface update during…
- CVE-2020-8489HIGHCVSS 7.8EG 7.82020-04-29
Insufficient protection of the inter-process communication functions in ABB System 800xA Information Management (all published versions) enables an attacker authenticated on the local system to inject data, affecting the runtime values to …
- CVE-2021-1258MEDIUMCVSS 5.5EG 5.52021-01-13
A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges to read arbitrary files on the underlying operating system (OS) of an affected device. The…
- CVE-2021-21436LOWCVSS 3.5EG 3.52021-02-08
Agents are able to see and link Config Items without permissions, which are defined in General Catalog. This issue affects: OTRS AG OTRSCIsInCustomerFrontend 7.0.x version 7.0.14 and prior versions.
- CVE-2021-21437MEDIUMCVSS 3.5EG 4.32021-03-22
Agents are able to see linked Config Items without permissions, which are defined in General Catalog. This issue affects: OTRSCIsInCustomerFrontend 7.0.15 and prior versions, ITSMConfigurationManagement 7.0.24 and prior versions
- CVE-2021-21438LOWCVSS 3.5EG 3.52021-03-22
Agents are able to see linked FAQ articles without permissions (defined in FAQ Category). This issue affects: FAQ version 6.0.29 and prior versions, OTRS version 7.0.24 and prior versions.
- CVE-2021-22661HIGHCVSS 7.5EG 7.52021-02-26
Changing the password on the module webpage does not require the user to type in the current password first. Thus, the password could be changed by a user or external process without knowledge of the current password on the ICX35-HWC-A and…
- CVE-2021-25472MEDIUMCVSS 4.0EG 4.02021-10-06
An improper access control vulnerability in BluetoothSettingsProvider prior to SMR Oct-2021 Release 1 allows untrusted application to overwrite some Bluetooth information.
- CVE-2021-25482MEDIUMCVSS 5.9EG 5.92021-10-06
SQL injection vulnerabilities in CMFA framework prior to SMR Oct-2021 Release 1 allow untrusted application to overwrite some CMFA framework information.
- CVE-2021-27644HIGHCVSS 8.8EG 8.82021-11-01
In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password)
- CVE-2021-27851MEDIUMCVSS 5.5EG 5.52021-04-26
A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’. It affects multi-user setups in which ’guix-daemon’ runs locally. The attack consists in having an unprivileged user spawn a buil…
- CVE-2021-28052HIGHCVSS 7.5EG 7.52022-09-26
A tenant administrator Hitachi Content Platform (HCP) may modify the configuration in another tenant without authorization, potentially allowing unauthorized access to data in the other tenant. Also, a tenant user (non-administrator) may v…
- CVE-2021-28497MEDIUMCVSS 4.4EG 4.42021-09-09
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, the bash shell might be accessible to unprivileged users in situations where they should not have access. This issu…
- CVE-2021-33036HIGHCVSS 8.8EG 8.82022-06-15
In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 …
- CVE-2021-36879CRITICALCVSS 9.8EG 9.82021-09-27
Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPress configuration allows user registration.
- CVE-2022-0237HIGHCVSS 4.0EG 7.82022-03-17
Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execution due to an unquoted argument to the runas.exe command used by the ir_agent.exe compone…
Map vulnerabilities like CWE-264 to your infrastructure
EchelonGraph correlates every CVE — across CWE-264 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →