CWE-264
1,421 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-264page 27 of 29
- CVE-2022-1548HIGHCVSS 3.7EG 8.82022-05-03
Mattermost Playbooks plugin 1.25 and earlier fails to properly restrict user-level permissions, which allows playbook members to escalate their membership privileges and perform actions restricted to playbook admins.
- CVE-2022-23708MEDIUMCVSS 4.3EG 4.32022-03-03
A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with “*” index permissions acces…
- CVE-2022-23709MEDIUMCVSS 4.3EG 4.32022-03-03
A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite existing ones. However, any new or modifi…
- CVE-2022-23714HIGHCVSS 7.8EG 7.82022-07-06
A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
- CVE-2022-23731HIGHCVSS 7.8EG 7.82022-03-11
V8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models.
- CVE-2022-25649HIGHCVSS 5.0EG 8.82022-08-05
Multiple Improper Access Control vulnerabilities in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress.
- CVE-2022-27235HIGHCVSS 6.3EG 8.82022-07-22
Multiple Broken Access Control vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.
- CVE-2022-29423CRITICALCVSS 3.8EG 9.82022-05-06
Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress.
- CVE-2022-29444MEDIUMCVSS 6.5EG 6.52022-05-02
Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerability in Cloudways Breeze plugin <= 2.0.2 on WordPress allows users with a subscriber or higher user role to execute any of the wp_ajax_* actions in the class Breeze_Conf…
- CVE-2022-33198CRITICALCVSS 9.8EG 9.82022-07-21
Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress.
- CVE-2022-33969HIGHCVSS 7.2EG 7.22022-07-25
Authenticated WordPress Options Change vulnerability in Biplob Adhikari's Flipbox plugin <= 2.6.0 at WordPress.
- CVE-2022-33970HIGHCVSS 7.2EG 7.22022-07-27
Authenticated WordPress Options Change vulnerability in Biplob018 Shortcode Addons plugin <= 3.1.2 at WordPress.
- CVE-2022-34149CRITICALCVSS 9.8EG 9.82022-08-22
Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.
- CVE-2022-3421HIGHCVSS 5.6EG 7.32022-10-17
An attacker can pre-create the `/Applications/Google\ Drive.app/Contents/MacOS` directory which is expected to be owned by root to be owned by a non-root user. When the Drive for Desktop installer is run for the first time, it will place a…
- CVE-2022-34487CRITICALCVSS 9.8EG 9.82022-07-21
Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress.
- CVE-2022-34868HIGHCVSS 8.8EG 8.82022-08-23
Authenticated Arbitrary Settings Update vulnerability in YooMoney ЮKassa для WooCommerce plugin <= 2.3.0 at WordPress.
- CVE-2022-35238MEDIUMCVSS 6.5EG 6.52022-09-23
Unauthenticated Plugin Settings Change vulnerability in Awesome Filterable Portfolio plugin <= 1.9.7 at WordPress.
- CVE-2022-35242MEDIUMCVSS 6.5EG 6.52022-08-23
Unauthenticated plugin settings change vulnerability in 59sec THE Leads Management System: 59sec LITE plugin <= 3.4.1 at WordPress.
- CVE-2022-36246CRITICALCVSS 9.8EG 9.82023-05-30
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Insecure Permissions.
- CVE-2022-36375HIGHCVSS 7.2EG 7.22022-07-25
Authenticated (high role user) WordPress Options Change vulnerability in Biplob Adhikari's Tabs plugin <= 3.6.0 at WordPress.
- CVE-2022-36387CRITICALCVSS 7.6EG 9.82022-09-06
Broken Access Control vulnerability in Alessio Caiazza's About Me plugin <= 1.0.12 at WordPress.
- CVE-2022-36425CRITICALCVSS 5.4EG 9.82022-09-06
Broken Access Control vulnerability in Beaver Builder plugin <= 2.5.4.3 at WordPress.
- CVE-2022-36427CRITICALCVSS 7.3EG 9.82022-09-06
Missing Access Control vulnerability in About Rentals. Inc. About Rentals plugin <= 1.5 at WordPress.
- CVE-2022-36793CRITICALCVSS 6.5EG 9.12022-09-09
Unauthenticated Plugin Settings Change & Data Deletion vulnerabilities in WP Shop plugin <= 3.9.6 at WordPress.
- CVE-2022-37344CRITICALCVSS 7.6EG 9.82022-09-06
Missing Access Control vulnerability in PHP Crafts Accommodation System plugin <= 1.0.1 at WordPress.
- CVE-2022-38058MEDIUMCVSS 4.3EG 4.32022-09-09
Authenticated (subscriber+) Plugin Setting change vulnerability in WP Shamsi plugin <= 4.1.1 at WordPress.
- CVE-2022-38067MEDIUMCVSS 6.5EG 6.52022-09-09
Unauthenticated Event Deletion vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.
- CVE-2022-38070HIGHCVSS 5.4EG 8.82022-09-09
Privilege Escalation (subscriber+) vulnerability in Pop-up plugin <= 1.1.5 at WordPress.
- CVE-2022-38104HIGHCVSS 7.2EG 7.22022-10-21
Auth. WordPress Options Change (siteurl, users_can_register, default_role, admin_email and new_admin_email) vulnerability in Biplob Adhikari's Accordions – Multiple Accordions or FAQs Builder plugin (versions <= 2.0.3 on WordPress.
- CVE-2022-38134HIGHCVSS 4.3EG 8.82022-09-23
Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.
- CVE-2022-38135MEDIUMCVSS 5.4EG 6.52022-09-12
Broken Access Control vulnerability in Dean Oakley's Photospace Gallery plugin <= 2.3.5 at WordPress allows users with subscriber or higher role to change plugin settings.
- CVE-2022-38461MEDIUMCVSS 5.4EG 5.42022-11-17
Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with a subscriber or higher user role to change plugin settings (selected language for legacy widgets, the default behavior for…
- CVE-2022-38974MEDIUMCVSS 4.3EG 4.32022-11-18
Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with subscriber or higher user roles to change the status of the translation jobs.
- CVE-2022-41132MEDIUMCVSS 6.1EG 6.12022-11-17
Unauthenticated Plugin Settings Change Leading To Stored XSS Vulnerability in Ezoic plugin <= 2.8.8 on WordPress.
- CVE-2022-41781CRITICALCVSS 6.5EG 9.82022-11-18
Broken Access Control vulnerability in Permalink Manager Lite plugin <= 2.2.20 on WordPress.
- CVE-2022-41839MEDIUMCVSS 5.3EG 5.32022-11-18
Broken Access Control vulnerability in WordPress LoginPress plugin <= 1.6.2 on WordPress leading to unauth. changing of Opt-In or Opt-Out tracking settings.
- CVE-2022-41978HIGHCVSS 8.8EG 8.82022-11-09
Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress.
- CVE-2022-42459HIGHCVSS 7.2EG 7.22022-11-18
Auth. WordPress Options Change vulnerability in Image Hover Effects Ultimate plugin <= 9.7.1 on WordPress.
- CVE-2022-42460MEDIUMCVSS 6.5EG 6.52022-11-10
Broken Access Control vulnerability leading to Stored Cross-Site Scripting (XSS) in Traffic Manager plugin <= 1.4.5 on WordPress.
- CVE-2022-42461HIGHCVSS 5.4EG 8.82022-11-18
Broken Access Control vulnerability in miniOrange's Google Authenticator plugin <= 5.6.1 on WordPress.
- CVE-2022-45066HIGHCVSS 5.4EG 8.82022-11-17
Auth. (subscriber+) Broken Access Control vulnerability in WooSwipe WooCommerce Gallery plugin <= 2.0.1 on WordPress.
- CVE-2022-45069HIGHCVSS 6.3EG 8.82022-11-17
Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress.
- CVE-2022-45369MEDIUMCVSS 4.3EG 4.32022-11-18
Auth. (subscriber+) Broken Access Control vulnerability in Plugin for Google Reviews plugin <= 2.2.2 on WordPress.
- CVE-2022-48508HIGHCVSS 7.5EG 7.52023-07-06
Inappropriate authorization vulnerability in the system apps. Successful exploitation of this vulnerability may affect service integrity.
- CVE-2023-20190MEDIUMCVSS 5.8EG 5.82023-09-13
A vulnerability in the classic access control list (ACL) compression feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by a configured ACL on an affected device. Th…
- CVE-2023-21641MEDIUMCVSS 6.6EG 6.62023-07-04
An app with non-privileged access can change global system brightness and cause undesired system behavior.
- CVE-2023-2255MEDIUMCVSS 5.3EG 5.32023-05-25
Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of LibreOffice documents that…
- CVE-2023-22633HIGHCVSS 7.5EG 7.52023-06-13
An improper permissions, privileges, and access controls vulnerability [CWE-264] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions 8.7.0 all versions may allow an unauthenticated attacker t…
- CVE-2023-24573HIGHCVSS 4.7EG 7.12023-02-10
Dell Command | Monitor versions prior to 10.9 contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion.
- CVE-2023-3599MEDIUMCVSS 6.3EG 6.32023-07-10
A vulnerability was found in SourceCodester Best Fee Management System 1.0. It has been rated as critical. Affected by this issue is the function save_user of the file admin_class.php of the component Add User Handler. The manipulation lea…
Map vulnerabilities like CWE-264 to your infrastructure
EchelonGraph correlates every CVE — across CWE-264 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →