Skip to main content

CWE archive

CWE-250 CVEs

Programmatic archive

338 CVEs tagged with CWE-25056 Critical, 188 High, 88 Medium, 6 Low, 0 Unrated.

CVE-2022-44544

Published Nov 6, 2022

Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote shell if the site is running o…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-22239

Published Oct 18, 2022

An Execution with Unnecessary Privileges vulnerability in Management Daemon (mgd) of Juniper Networks Junos OS Evolved allows a locally authenticated attacker with low privileges…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30695

Published May 16, 2022

Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Snap Deploy (Windows) before build 3640

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-0071

Published Apr 19, 2022

Incomplete fix for CVE-2021-3101. Hotdog, prior to v1.0.2, did not mimic the resource limits, device restrictions, or syscall filters of the target JVM process. This would allow a…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2022-0070

Published Apr 19, 2022

Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the Linux capabilities and cgroups…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2021-3101

Published Apr 19, 2022

Hotdog, prior to v1.0.1, did not mimic the capabilities or the SELinux label of the target JVM process. This would allow a container to gain full privileges on the host, bypassing…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2021-3100

Published Apr 19, 2022

The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges.

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2022-20676

Published Apr 15, 2022

A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS XE Software could allow an authenticated, local attacker to escalate from privilege level 15 to root-le…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-27578

Published Apr 11, 2022

An attacker can perform a privilege escalation through the SICK OEE if the application is installed in a directory where non authenticated or low privilege users can modify its co…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-34998

Published Jan 13, 2022

This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Free Antivirus 20.2.0.0. An attacker must first obtain the ability to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-1118

Published Oct 29, 2021

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where there is the potential to execute privileged operations by the guest OS, which may le…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41035

Published Oct 25, 2021

In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 276-300 of 338 CVEsPage 12 of 14