CWE-280
140 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-280page 2 of 3
- CVE-2024-22077MEDIUMCVSS 5.3EG 5.32024-03-20
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The SQLite database file has weak permissions.
- CVE-2024-22078HIGHCVSS 8.8EG 8.82024-03-20
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable files. The network configuration script has weak filesystem permissions. This results in write acce…
- CVE-2024-23704HIGHCVSS 7.8EG 7.02024-05-07
In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges …
- CVE-2024-24116CRITICALCVSS 9.8EG 9.82024-10-02
An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.
- CVE-2024-25108CRITICALCVSS 9.9EG 9.92024-02-12
Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functionality than users intended, including to the administrative a…
- CVE-2024-25844HIGHCVSS 7.5EG 7.52024-03-03
An issue was discovered in Common-Services "So Flexibilite" (soflexibilite) module for PrestaShop before version 4.1.26, allows remote attackers to escalate privileges and obtain sensitive information via debug file.
- CVE-2024-27837LOWCVSS 3.3EG 7.72024-05-14
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.5. A local attacker may gain access to Keychain items.
- CVE-2024-29748HIGHCVSS 7.8EG 9.0⚠ KEV2024-04-05
there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
- CVE-2024-29852LOWCVSS 2.7EG 2.72024-05-22
Veeam Backup Enterprise Manager allows high-privileged users to read backup session logs.
- CVE-2024-30418HIGHCVSS 7.5EG 7.52024-04-07
Vulnerability of insufficient permission verification in the app management module. Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2024-32000MEDIUMCVSS 4.3EG 4.32024-04-12
matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. matrix-appservice-irc before version 2.0.0 can be exploited to leak the truncated body of a message if a malicious user sends a Matrix reply to an event ID th…
- CVE-2024-32488HIGHCVSS 7.8EG 7.82024-04-15
In Foxit PDF Reader and Editor before 2024.1, Local Privilege Escalation could occur during update checks because weak permissions on the update-service folder allow attackers to place crafted DLL files there.
- CVE-2024-32882LOWCVSS 2.7EG 2.72024-05-02
Wagtail is an open source content management system built on Django. In affected versions if a model has been made available for editing through the `wagtail.contrib.settings` module or `ModelViewSet`, and the `permission` argument on `Fie…
- CVE-2024-35228MEDIUMCVSS 5.5EG 5.52024-05-30
Wagtail is an open source content management system built on Django. Due to an improperly applied permission check in the `wagtail.contrib.settings` module, a user with access to the Wagtail admin and knowledge of the URL of the edit view …
- CVE-2024-35301MEDIUMCVSS 5.5EG 5.52024-05-16
In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token
- CVE-2024-36112MEDIUMCVSS 6.3EG 6.32024-05-28
Nautobot is a Network Source of Truth and Network Automation Platform. A user with permissions to view Dynamic Group records (`extras.view_dynamicgroup` permission) can use the Dynamic Group detail UI view (`/extras/dynamic-groups/<uuid>/`…
- CVE-2024-36451HIGHCVSS 8.8EG 8.82024-07-10
Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003. If this vulnerability is exploited, a console session may be hijacked by an unauthorized user. As a result, data …
- CVE-2024-39691MEDIUMCVSS 4.3EG 4.32024-07-05
matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The fix for GHSA-wm4w-7h2q-3pf7 / CVE-2024-32000 included in matrix-appservice-irc 2.0.0 relied on the Matrix homeserver-provided timestamp to determine wheth…
- CVE-2024-4211LOWCVSS 2.4EG 2.42024-10-16
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - ALM job conf…
- CVE-2024-42194LOWCVSS 3.1EG 3.12024-12-17
An improper handling of insufficient permissions or privileges affects HCL BigFix Inventory. An attacker having access via a read-only account can possibly change certain configuration parameters by crafting a specific REST API call.
- CVE-2024-43702HIGHCVSS 8.1EG 8.12024-11-30
Software installed and run as a non-privileged user may conduct improper GPU system calls to allow unprivileged access to arbitrary physical memory page.
- CVE-2024-43705HIGHCVSS 7.8EG 7.82024-12-28
Software installed and run as a non-privileged user can trigger the GPU kernel driver to write to arbitrary read-only system files that have been mapped into application memory.
- CVE-2024-4468MEDIUMCVSS 4.3EG 4.32024-06-08
The Salon booking system plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions hooked into admin_init in all versions up to, and including, 9.9. This makes…
- CVE-2024-46874HIGHCVSS 8.1EG 8.12024-12-06
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow MQTT clients connecting with device credentials to send messages to some topics. Attackers with device credentials could issue commands to other devices on behalf…
- CVE-2024-4692LOWCVSS 2.4EG 2.42024-10-16
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - Service Virt…
- CVE-2024-46988MEDIUMCVSS 4.8EG 4.82024-10-14
Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.40, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6, users might receive email notific…
- CVE-2024-47766MEDIUMCVSS 4.9EG 4.92024-10-14
Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, administrators of a project can …
- CVE-2024-47767MEDIUMCVSS 4.3EG 4.32024-10-14
Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.113, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, users might see tracker names th…
- CVE-2024-51459HIGHCVSS 8.4EG 8.42025-03-19
IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handling of permissions.
- CVE-2024-5163CRITICALCVSS 9.8EG 9.82024-06-17
Improper permission settings for mobile applications (com.transsion.carlcare) may lead to user password and account security risks.
- CVE-2024-55604MEDIUMCVSS 4.3EG 4.32025-03-25
Appsmith is a platform to build admin panels, internal tools, and dashboards. Users invited as "App Viewer" should not have access to development information of a workspace. Datasources are such a component in a workspace. Yet, in versions…
- CVE-2024-6302HIGHCVSS 8.1EG 8.12024-06-25
Lack of privilege checking when processing a redaction in Conduit versions v0.6.0 and lower, allowing a local user to redact any message from users on the same server, given that they are able to send redaction events.
- CVE-2024-6660HIGHCVSS 8.8EG 8.82024-07-17
The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the bo…
- CVE-2024-6697MEDIUMCVSS 6.5EG 6.52025-02-20
The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in …
- CVE-2024-7314CRITICALCVSS 9.8EG 9.82024-08-02
anji-plus AJ-Report is affected by an authentication bypass vulnerability. A remote and unauthenticated attacker can append ";swagger-ui" to HTTP requests to bypass authentication and execute arbitrary Java on the victim server. Exploitat…
- CVE-2024-8315MEDIUMCVSS 6.8EG 0.02025-03-25
An Improper Handling of Insufficient Permissions or Privileges vulnerability in scripts used in B&R APROL <4.4-00P5 may allow an authenticated local attacker to read credential information.
- CVE-2024-8451HIGHCVSS 7.5EG 7.52024-09-30
Certain switch models from PLANET Technology have an SSH service that improperly handles insufficiently authenticated connection requests, allowing unauthorized remote attackers to exploit this weakness to occupy connection slots and preve…
- CVE-2025-0468HIGHCVSS 7.1EG 7.12025-04-04
Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allo…
- CVE-2025-0478HIGHCVSS 7.8EG 7.82025-03-24
Software installed and run as a non-privileged user may conduct improper GPU system calls to issue reads and writes to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not alloc…
- CVE-2025-20649MEDIUMCVSS 6.5EG 6.52025-03-03
In Bluetooth Stack SW, there is a possible information disclosure due to a missing permission check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is n…
- CVE-2025-22129MEDIUMCVSS 4.3EG 4.32025-02-03
Tuleap is an Open Source Suite to improve management of software developments and collaboration. In affected versions an unauthorized user might get access to restricted information. This issue has been addressed in Tuleap Community Editio…
- CVE-2025-22256MEDIUMCVSS 6.3EG 6.32025-06-10
A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSRA 1.4.0 through 1.4.1 allows attacker to improper access control via spe…
- CVE-2025-22395HIGHCVSS 8.2EG 8.22025-01-07
Dell Update Package Framework, versions prior to 22.01.02, contain(s) a Local Privilege Escalation Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary remote sc…
- CVE-2025-24029MEDIUMCVSS 5.3EG 5.32025-02-03
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users (possibly anonymous ones if the widget is used in the dashboard of a public project) might get access to artifacts they should not see. …
- CVE-2025-2503HIGHCVSS 7.1EG 7.12025-05-30
An improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to perform arbitrary file deletions as an elevated user.
- CVE-2025-25179HIGHCVSS 7.8EG 7.82025-06-02
Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages.
- CVE-2025-27024MEDIUMCVSS 6.5EG 6.52025-07-02
Unrestricted access to OS file system in SFTP service in Infinera G42 version R6.1.3 allows remote authenticated users to read/write OS files via SFTP connections. Details: Account members of the Network Administrator profile can acces…
- CVE-2025-27025HIGHCVSS 8.8EG 8.82025-07-02
The target device exposes a service on a specific TCP port with a configured endpoint. The access to that endpoint is granted using a Basic Authentication method. The endpoint accepts also the PUT method and it is possible to write file…
- CVE-2025-27521MEDIUMCVSS 6.8EG 6.82025-03-04
Vulnerability of improper access permission in the process management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2025-29826HIGHCVSS 7.3EG 7.32025-05-13
Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
Map vulnerabilities like CWE-280 to your infrastructure
EchelonGraph correlates every CVE — across CWE-280 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →