Skip to main content

CWE archive

CWE-250 CVEs

Programmatic archive

338 CVEs tagged with CWE-25056 Critical, 188 High, 88 Medium, 6 Low, 0 Unrated.

CVE-2023-5207

Published Sep 30, 2023

A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4003

Published Sep 27, 2023

One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method. C…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4662

Published Sep 15, 2023

Execution with Unnecessary Privileges vulnerability in Saphira Saphira Connect allows Remote Code Inclusion. This issue affects Saphira Connect: before 9.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-4814

Published Sep 14, 2023

A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for which the user does not have permission t…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31175

Published Aug 31, 2023

An Execution with Unnecessary Privileges vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to run system commands wit…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-32486

Published Aug 16, 2023

Dell PowerScale OneFS 9.5.x version contain a privilege escalation vulnerability. A low privilege local attacker could potentially exploit this vulnerability, leading to escalatio…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38641

Published Aug 8, 2023

A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.10). The affected application's database service is executed as `NT AUTHORITY\SYSTEM`. This could allo…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39508

Published Aug 5, 2023

Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Airflow.The "Run Task" featu…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34118

Published Jul 11, 2023

Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32080

Published May 10, 2023

Wings is the server control plane for Pterodactyl Panel. A vulnerability affecting versions prior to 1.7.5 and versions 1.11.0 prior to 1.11.6 impacts anyone running the affected…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-27247

Published Mar 28, 2023

Cynet Client Agent v4.6.0.8010 allows attackers with Administrator rights to disable the EDR functions by disabling process privilege tokens.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27010

Published Mar 13, 2023

Wondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst. This vulnerability allows attackers to escalate privileges via modifying or overw…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-25078

Published Jan 26, 2023

man-db before 2.8.5 on Gentoo allows local users (with access to the man user account) to gain root privileges because /usr/bin/mandb is executed by root but not owned by root. (A…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41290

Published Dec 23, 2022

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the rm_rlcache_file command to obtain root privileges. IBM X-Force ID:…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort
Showing 251-275 of 338 CVEsPage 11 of 14