CWE-264
1,421 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-264page 28 of 29
- CVE-2023-39380HIGHCVSS 7.5EG 7.52023-08-13
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally.
- CVE-2023-39384HIGHCVSS 7.5EG 7.52023-08-13
Vulnerability of incomplete permission verification in the input method module. Successful exploitation of this vulnerability may cause features to perform abnormally.
- CVE-2023-39387MEDIUMCVSS 5.3EG 5.32023-08-13
Vulnerability of permission control in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up windows.
- CVE-2023-39391HIGHCVSS 7.5EG 7.52023-08-13
Vulnerability of system file information leakage in the USB Service module. Successful exploitation of this vulnerability may affect confidentiality.
- CVE-2023-39394HIGHCVSS 7.5EG 7.52023-08-13
Vulnerability of API privilege escalation in the wifienhance module. Successful exploitation of this vulnerability may cause the arp list to be modified.
- CVE-2023-39406HIGHCVSS 7.5EG 7.52023-08-13
Permission control vulnerability in the XLayout component. Successful exploitation of this vulnerability may cause apps to forcibly restart.
- CVE-2023-42005HIGHCVSS 7.4EG 7.42024-05-29
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4.8 could allow a user with access to the Kubernetes pod, to make system calls compromising the security of containers. IBM X-Force ID: 2652…
- CVE-2023-44281MEDIUMCVSS 6.6EG 6.62024-01-24
Dell Pair Installer version prior to 1.2.1 contains an elevation of privilege vulnerability. A low privilege user with local access to the system could potentially exploit this vulnerability to delete arbitrary files and result in Denial …
- CVE-2023-52106CRITICALCVSS 4.4EG 9.12024-01-16
Vulnerability of permission verification for APIs in the DownloadProviderMain module. Impact: Successful exploitation of this vulnerability will affect integrity and availability.
- CVE-2023-52721MEDIUMCVSS 6.2EG 6.22024-05-14
The WindowManager module has a vulnerability in permission control. Impact: Successful exploitation of this vulnerability may affect confidentiality.
- CVE-2023-52955MEDIUMCVSS 6.5EG 6.52025-01-08
Vulnerability of improper authentication in the ANS system service module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
- CVE-2023-7265MEDIUMCVSS 4.0EG 4.02024-08-08
Permission verification vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect availability
- CVE-2024-20361MEDIUMCVSS 5.8EG 5.82024-05-22
A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass configured access controls on managed devices that a…
- CVE-2024-20370MEDIUMCVSS 6.0EG 6.02024-10-23
A vulnerability in the Cisco FXOS CLI feature on specific hardware platforms for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to elevate the…
- CVE-2024-20371MEDIUMCVSS 5.3EG 5.32024-11-06
A vulnerability in the access control list (ACL) programming of Cisco Nexus 3550-F Switches could allow an unauthenticated, remote attacker to send traffic that should be blocked to the management interface of an affected device. …
- CVE-2024-21469HIGHCVSS 7.3EG 7.32024-07-01
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
- CVE-2024-22452HIGHCVSS 7.3EG 7.32024-03-04
Dell Display and Peripheral Manager for macOS prior to 1.3 contains an improper access control vulnerability. A low privilege user could potentially exploit this vulnerability by modifying files in the installation folder to execute arbitr…
- CVE-2024-32996MEDIUMCVSS 6.2EG 6.22024-05-14
Privilege escalation vulnerability in the account module Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2024-39670MEDIUMCVSS 6.2EG 6.22024-07-25
Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2024-43064HIGHCVSS 7.5EG 7.52025-01-06
Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU.
- CVE-2024-45442MEDIUMCVSS 5.1EG 5.12024-09-04
Vulnerability of permission verification for APIs in the DownloadProviderMain module Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2024-45449MEDIUMCVSS 5.1EG 5.12024-09-04
Access permission verification vulnerability in the ringtone setting module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-51524MEDIUMCVSS 4.0EG 4.02024-11-05
Permission control vulnerability in the Wi-Fi module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-51527MEDIUMCVSS 5.1EG 5.12024-11-05
Permission control vulnerability in the Gallery app Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-53011HIGHCVSS 7.9EG 7.92025-03-03
Information disclosure may occur due to improper permission and access controls to Video Analytics engine.
- CVE-2024-54103MEDIUMCVSS 6.1EG 6.12024-12-12
Vulnerability of improper access control in the album module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-54104MEDIUMCVSS 6.2EG 6.22024-12-12
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-5465MEDIUMCVSS 5.9EG 5.92024-06-14
Function vulnerabilities in the Calendar module Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2024-56440MEDIUMCVSS 6.2EG 6.22025-01-08
Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
- CVE-2024-56444HIGHCVSS 7.5EG 7.52025-01-08
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2025-20145MEDIUMCVSS 5.8EG 5.82025-03-12
A vulnerability in the access control list (ACL) processing in the egress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability exists because certain packets a…
- CVE-2025-46587MEDIUMCVSS 6.2EG 6.22025-05-06
Permission control vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2025-48903HIGHCVSS 7.8EG 7.82025-06-06
Permission bypass vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2025-53177LOWCVSS 3.9EG 3.92025-07-07
Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule syncing function of watches.
- CVE-2025-53178MEDIUMCVSS 4.8EG 4.82025-07-07
Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule reminder function of head units.
- CVE-2025-53186MEDIUMCVSS 5.9EG 5.92025-07-07
Vulnerability that allows third-party call apps to send broadcasts without verification in the audio framework module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2025-5321CRITICALCVSS 9.9EG 9.92025-05-29
A vulnerability classified as critical was found in aimhubio aim up to 3.29.1. This vulnerability affects the function RestrictedPythonQuery of the file /aim/storage/query.py of the component run_view Object Handler. The manipulation of th…
- CVE-2025-54608MEDIUMCVSS 6.2EG 6.22025-08-06
Vulnerability that allows setting screen rotation direction without permission verification in the screen management module. Impact: Successful exploitation of this vulnerability may cause device screen orientation to be arbitrarily set.
- CVE-2025-54654MEDIUMCVSS 6.2EG 6.22025-10-11
Permission control vulnerability in the Gallery module. Successful exploitation of this vulnerability may affect service confidentiality
- CVE-2025-58276MEDIUMCVSS 6.8EG 6.82025-09-05
Permission verification vulnerability in the home screen module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2025-58282LOWCVSS 2.8EG 2.82025-10-11
Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2025-58283MEDIUMCVSS 5.5EG 5.52025-10-11
Permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2025-58284MEDIUMCVSS 5.9EG 5.92025-10-11
Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2025-58285MEDIUMCVSS 5.3EG 5.32025-10-11
Permission control vulnerability in the media module. Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2025-58293MEDIUMCVSS 5.5EG 5.52025-10-11
Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability.
- CVE-2025-58294MEDIUMCVSS 6.2EG 6.22025-11-28
Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2025-58302HIGHCVSS 8.4EG 8.42025-11-28
Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2025-58309MEDIUMCVSS 6.8EG 6.82025-11-28
Permission control vulnerability in the startup recovery module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
- CVE-2025-58312MEDIUMCVSS 5.1EG 5.12025-11-28
Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2025-58315MEDIUMCVSS 5.5EG 5.52025-11-28
Permission control vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Map vulnerabilities like CWE-264 to your infrastructure
EchelonGraph correlates every CVE — across CWE-264 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →