CWE-264
395 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-264page 7 of 8
- CVE-2022-36375HIGHCVSS 7.2EG 7.22022-07-25
Authenticated (high role user) WordPress Options Change vulnerability in Biplob Adhikari's Tabs plugin <= 3.6.0 at WordPress.
- CVE-2022-36387HIGHCVSS 7.6EG 9.82022-09-06
Broken Access Control vulnerability in Alessio Caiazza's About Me plugin <= 1.0.12 at WordPress.
- CVE-2022-36425MEDIUMCVSS 5.4EG 9.82022-09-06
Broken Access Control vulnerability in Beaver Builder plugin <= 2.5.4.3 at WordPress.
- CVE-2022-36427HIGHCVSS 7.3EG 9.82022-09-06
Missing Access Control vulnerability in About Rentals. Inc. About Rentals plugin <= 1.5 at WordPress.
- CVE-2022-36793MEDIUMCVSS 6.5EG 9.12022-09-09
Unauthenticated Plugin Settings Change & Data Deletion vulnerabilities in WP Shop plugin <= 3.9.6 at WordPress.
- CVE-2022-37344HIGHCVSS 7.6EG 9.82022-09-06
Missing Access Control vulnerability in PHP Crafts Accommodation System plugin <= 1.0.1 at WordPress.
- CVE-2022-38058MEDIUMCVSS 4.3EG 4.32022-09-09
Authenticated (subscriber+) Plugin Setting change vulnerability in WP Shamsi plugin <= 4.1.1 at WordPress.
- CVE-2022-38067MEDIUMCVSS 6.5EG 6.52022-09-09
Unauthenticated Event Deletion vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.
- CVE-2022-38070MEDIUMCVSS 5.4EG 8.82022-09-09
Privilege Escalation (subscriber+) vulnerability in Pop-up plugin <= 1.1.5 at WordPress.
- CVE-2022-38104HIGHCVSS 7.2EG 7.22022-10-21
Auth. WordPress Options Change (siteurl, users_can_register, default_role, admin_email and new_admin_email) vulnerability in Biplob Adhikari's Accordions – Multiple Accordions or FAQs Builder plugin (versions <= 2.0.3 on WordPress.
- CVE-2022-38134MEDIUMCVSS 4.3EG 8.82022-09-23
Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.
- CVE-2022-38135MEDIUMCVSS 5.4EG 6.52022-09-12
Broken Access Control vulnerability in Dean Oakley's Photospace Gallery plugin <= 2.3.5 at WordPress allows users with subscriber or higher role to change plugin settings.
- CVE-2022-38461MEDIUMCVSS 5.4EG 4.32022-11-17
Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with a subscriber or higher user role to change plugin settings (selected language for legacy widgets, the default behavior for…
- CVE-2022-38974MEDIUMCVSS 4.3EG 4.32022-11-18
Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with subscriber or higher user roles to change the status of the translation jobs.
- CVE-2022-41132MEDIUMCVSS 6.1EG 6.12022-11-17
Unauthenticated Plugin Settings Change Leading To Stored XSS Vulnerability in Ezoic plugin <= 2.8.8 on WordPress.
- CVE-2022-41781MEDIUMCVSS 6.5EG 9.82022-11-18
Broken Access Control vulnerability in Permalink Manager Lite plugin <= 2.2.20 on WordPress.
- CVE-2022-41839MEDIUMCVSS 5.3EG 5.32022-11-18
Broken Access Control vulnerability in WordPress LoginPress plugin <= 1.6.2 on WordPress leading to unauth. changing of Opt-In or Opt-Out tracking settings.
- CVE-2022-41978HIGHCVSS 8.8EG 6.52022-11-09
Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress.
- CVE-2022-42459HIGHCVSS 7.2EG 7.22022-11-18
Auth. WordPress Options Change vulnerability in Image Hover Effects Ultimate plugin <= 9.7.1 on WordPress.
- CVE-2022-42460MEDIUMCVSS 6.5EG 5.42022-11-10
Broken Access Control vulnerability leading to Stored Cross-Site Scripting (XSS) in Traffic Manager plugin <= 1.4.5 on WordPress.
- CVE-2022-42461MEDIUMCVSS 5.4EG 8.82022-11-18
Broken Access Control vulnerability in miniOrange's Google Authenticator plugin <= 5.6.1 on WordPress.
- CVE-2022-45066MEDIUMCVSS 5.4EG 8.82022-11-17
Auth. (subscriber+) Broken Access Control vulnerability in WooSwipe WooCommerce Gallery plugin <= 2.0.1 on WordPress.
- CVE-2022-45069MEDIUMCVSS 6.3EG 8.82022-11-17
Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress.
- CVE-2022-45369MEDIUMCVSS 4.3EG 4.32022-11-18
Auth. (subscriber+) Broken Access Control vulnerability in Plugin for Google Reviews plugin <= 2.2.2 on WordPress.
- CVE-2022-48508HIGHCVSS 7.5EG 7.52023-07-06
Inappropriate authorization vulnerability in the system apps. Successful exploitation of this vulnerability may affect service integrity.
- CVE-2023-20190MEDIUMCVSS 5.8EG 5.82023-09-13
A vulnerability in the classic access control list (ACL) compression feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by a configured ACL on an affected device. Th…
- CVE-2023-21641MEDIUMCVSS 6.6EG 6.62023-07-04
An app with non-privileged access can change global system brightness and cause undesired system behavior.
- CVE-2023-2255MEDIUMCVSS 5.3EG 5.32023-05-25
Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of LibreOffice documents that…
- CVE-2023-22633HIGHCVSS 7.5EG 7.52023-06-13
An improper permissions, privileges, and access controls vulnerability [CWE-264] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions 8.7.0 all versions may allow an unauthenticated attacker t…
- CVE-2023-24573MEDIUMCVSS 4.7EG 7.12023-02-10
Dell Command | Monitor versions prior to 10.9 contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion.
- CVE-2023-3599MEDIUMCVSS 6.3EG 6.32023-07-10
A vulnerability was found in SourceCodester Best Fee Management System 1.0. It has been rated as critical. Affected by this issue is the function save_user of the file admin_class.php of the component Add User Handler. The manipulation lea…
- CVE-2023-39380HIGHCVSS 7.5EG 7.52023-08-13
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally.
- CVE-2023-39384HIGHCVSS 7.5EG 7.52023-08-13
Vulnerability of incomplete permission verification in the input method module. Successful exploitation of this vulnerability may cause features to perform abnormally.
- CVE-2023-39387MEDIUMCVSS 5.3EG 5.32023-08-13
Vulnerability of permission control in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up windows.
- CVE-2023-39391HIGHCVSS 7.5EG 7.52023-08-13
Vulnerability of system file information leakage in the USB Service module. Successful exploitation of this vulnerability may affect confidentiality.
- CVE-2023-39394HIGHCVSS 7.5EG 7.52023-08-13
Vulnerability of API privilege escalation in the wifienhance module. Successful exploitation of this vulnerability may cause the arp list to be modified.
- CVE-2023-39406HIGHCVSS 7.5EG 7.52023-08-13
Permission control vulnerability in the XLayout component. Successful exploitation of this vulnerability may cause apps to forcibly restart.
- CVE-2023-42005HIGHCVSS 7.4EG 7.42024-05-29
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4.8 could allow a user with access to the Kubernetes pod, to make system calls compromising the security of containers. IBM X-Force ID: 2652…
- CVE-2023-44281MEDIUMCVSS 6.6EG 6.62024-01-24
Dell Pair Installer version prior to 1.2.1 contains an elevation of privilege vulnerability. A low privilege user with local access to the system could potentially exploit this vulnerability to delete arbitrary files and result in Denial …
- CVE-2023-52106MEDIUMCVSS 4.4EG 9.12024-01-16
Vulnerability of permission verification for APIs in the DownloadProviderMain module. Impact: Successful exploitation of this vulnerability will affect integrity and availability.
- CVE-2023-52721MEDIUMCVSS 6.2EG 6.22024-05-14
The WindowManager module has a vulnerability in permission control. Impact: Successful exploitation of this vulnerability may affect confidentiality.
- CVE-2023-52955MEDIUMCVSS 6.5EG 6.52025-01-08
Vulnerability of improper authentication in the ANS system service module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
- CVE-2023-7265MEDIUMCVSS 4.0EG 4.02024-08-08
Permission verification vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect availability
- CVE-2024-20361MEDIUMCVSS 5.8EG 5.82024-05-22
A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass configured access controls on managed devices that a…
- CVE-2024-20370MEDIUMCVSS 6.0EG 6.02024-10-23
A vulnerability in the Cisco FXOS CLI feature on specific hardware platforms for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to elevate the…
- CVE-2024-20371MEDIUMCVSS 5.3EG 5.32024-11-06
A vulnerability in the access control list (ACL) programming of Cisco Nexus 3550-F Switches could allow an unauthenticated, remote attacker to send traffic that should be blocked to the management interface of an affected device. …
- CVE-2024-21469HIGHCVSS 7.3EG 7.32024-07-01
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
- CVE-2024-22452HIGHCVSS 7.3EG 7.32024-03-04
Dell Display and Peripheral Manager for macOS prior to 1.3 contains an improper access control vulnerability. A low privilege user could potentially exploit this vulnerability by modifying files in the installation folder to execute arbitr…
- CVE-2024-32996MEDIUMCVSS 6.2EG 6.22024-05-14
Privilege escalation vulnerability in the account module Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2024-39670MEDIUMCVSS 6.2EG 6.22024-07-25
Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploitation of this vulnerability will affect availability.
Map vulnerabilities like CWE-264 to your infrastructure
EchelonGraph correlates every CVE — across CWE-264 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →