CWE-264
1,435 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-264page 29 of 29
- CVE-2025-58312MEDIUMCVSS 5.1EG 5.12025-11-28
Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2025-58315MEDIUMCVSS 5.5EG 5.52025-11-28
Permission control vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2025-5874MEDIUMCVSS 4.6EG 5.52025-06-09
A vulnerability was found in Redash up to 10.1.0/25.1.0. It has been rated as problematic. This issue affects the function run_query of the file /query_runner/python.py of the component getattr Handler. The manipulation leads to sandbox is…
- CVE-2025-64315HIGHCVSS 7.1EG 7.12025-11-28
Configuration defect vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect app data confidentiality and integrity.
- CVE-2025-66319MEDIUMCVSS 5.5EG 5.52026-03-05
Permission control vulnerability in the resource scheduling module. Impact: Successful exploitation of this vulnerability may affect service integrity.
- CVE-2025-66325MEDIUMCVSS 5.5EG 6.22025-12-08
Permission control vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2025-66329MEDIUMCVSS 5.5EG 5.52025-12-08
Permission control vulnerability in the window management module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2025-68967MEDIUMCVSS 5.5EG 5.72026-01-14
Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2026-14784MEDIUMCVSS 6.3EG 6.32026-07-06
A vulnerability was identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown function of the file backend/pkg/docker/client.go of the component Docker API. The manipulation leads to sandbox issue. The attack may be initiated re…
- CVE-2026-18593MEDIUMCVSS 5.6EG 5.62026-08-03
A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/templates/prompts/pentester.tmpl of the component Tool Management Protocol Handler. Executing a manipulation can lead to …
- CVE-2026-20046HIGHCVSS 8.8EG 8.82026-03-11
A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges and gain full administrative control of an affected device. This vulnerabili…
- CVE-2026-24920MEDIUMCVSS 5.5EG 6.22026-02-06
Permission control vulnerability in the AMS module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-24923MEDIUMCVSS 5.5EG 6.32026-02-06
Permission control vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2026-24924MEDIUMCVSS 5.5EG 6.12026-02-06
Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2026-24931MEDIUMCVSS 5.5EG 5.92026-02-06
Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2026-28541MEDIUMCVSS 5.5EG 5.52026-03-05
Permission control vulnerability in the cellular_data module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-41962LOWCVSS 3.6EG 3.62026-05-15
Permission control vulnerability in the app management and control module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2026-41974LOWCVSS 3.6EG 3.62026-06-09
Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-41987MEDIUMCVSS 6.2EG 6.22026-09-09
Permission control vulnerability in the app management module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-49303MEDIUMCVSS 5.1EG 5.12026-08-17
Permission control vulnerability in the notification module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-49304MEDIUMCVSS 6.2EG 6.22026-08-17
Permission control vulnerability in the device key management module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-49308MEDIUMCVSS 5.5EG 5.52026-08-17
Permission control vulnerability in the clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2026-49309MEDIUMCVSS 4.8EG 4.82026-09-09
Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2026-49310HIGHCVSS 8.6EG 8.62026-09-09
Permission control vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2026-49312MEDIUMCVSS 4.0EG 4.02026-09-09
Permission control vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2026-49313MEDIUMCVSS 5.5EG 5.52026-09-09
Permission control vulnerability in the app lock module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2026-49315HIGHCVSS 7.1EG 7.12026-09-09
DoS vulnerability in the input device module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-58555MEDIUMCVSS 6.6EG 6.62026-07-15
Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-58556MEDIUMCVSS 5.1EG 5.12026-07-15
Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-6117MEDIUMCVSS 6.3EG 6.32026-04-12
A vulnerability was found in AstrBotDevs AstrBot up to 4.22.1. This issue affects the function install_plugin_upload of the file astrbot/dashboard/routes/plugin.py of the component install-upload Endpoint. The manipulation of the argument …
- CVE-2026-6224HIGHCVSS 7.3EG 7.32026-04-13
A security flaw has been discovered in nocobase plugin-workflow-javascript up to 2.0.23. This issue affects the function createSafeConsole of the file packages/plugins/@nocobase/plugin-workflow-javascript/src/server/Vm.js. Performing a man…
- CVE-2026-6878MEDIUMCVSS 5.6EG 5.62026-04-23
A vulnerability was identified in ByteDance verl up to 0.7.0. Affected is the function math_equal of the file prime_math/grader.py. The manipulation leads to sandbox issue. It is possible to initiate the attack remotely. The complexity of …
- CVE-2026-76412HIGHCVSS 8.5EG 8.52026-09-16
A vulnerability in the remote diagnostics debugger of Cisco Secure FMC Software could allow an authenticated, remote attacker to enable the remote diagnostics debugger service. This vulnerability is due to an error when checking the pri…
- CVE-2026-81644MEDIUMCVSS 4.3EG 4.32026-09-09
DoS vulnerability in the preview service module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-9368HIGHCVSS 7.3EG 7.32026-05-24
A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This impacts the function execute_code of the file tools/code_execution_tool.py of the component Environment Variable Handler. Such manipulation leads to sandbox …
Map vulnerabilities like CWE-264 to your infrastructure
EchelonGraph correlates every CVE — across CWE-264 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →