CWE-250
362 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Execution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
CVEs (362)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Dell PowerScale OneFS 9.5.x version contain a privilege escalation vulnerability. A low privilege local attacker could potentially exploit this vulnerability, leading to escalation of privileges.
|
A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.10). The affected application's database service is executed as `NT AUTHORITY\SYSTEM`. This could allow a local attacker to execute operating s...Show more |
Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Airflow.The "Run Task" feature enables authenticated user to bypass s...Show more |
In JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissions |
1Cisco 16Broadworks Application Delivery Platform Firmware Broadworks Application Server FirmwareBroadworks Database Server Firmware+13 moreJun 17, 2026 Jul 12, 2023 N/A· v4 6.0 MEDIUM· v3 N/A· v2 A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating...Show more |
Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access. |
1Nvidia 2Dgx A100 Firmware Dgx A800 FirmwareJun 17, 2026 Jul 4, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause execution with unnecessary privileges by leveraging a weakness whereby proper input parameter validation is not performed. A succes...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 May 26, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2 A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows an attacker to unauthorized execution of management commands...Show more |
Wings is the server control plane for Pterodactyl Panel. A vulnerability affecting versions prior to 1.7.5 and versions 1.11.0 prior to 1.11.6 impacts anyone running the affected versions of Wings. This vulnerability ca...Show more |
1Illumina 11Iscan Firmware Iseq 100 FirmwareMiniseq Firmware+8 moreJun 17, 2026 Apr 28, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability. An unauthenticated malicious actor could upload and execute code remotely at the operating system level, whi...Show more |
3Fedoraproject QemuRedhat3Enterprise Linux FedoraQemuJun 17, 2026 Mar 29, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's Windows installer via repair custom actions to elevate their privileges on the syst...Show more |
Cynet Client Agent v4.6.0.8010 allows attackers with Administrator rights to disable the EDR functions by disabling process privilege tokens. |
Wondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst. This vulnerability allows attackers to escalate privileges via modifying or overwriting the executable. |
1Dell 5Alienware Update Command UpdateSupportassist For Business Pcs+2 moreJun 17, 2026 Feb 11, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | Update, Dell Update, and Alienware Update versions before 4.5 contain a Local Privil...Show more |
man-db before 2.8.5 on Gentoo allows local users (with access to the man user account) to gain root privileges because /usr/bin/mandb is executed by root but not owned by root. (Also, the owner can strip the setuid and s...Show more |
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the rm_rlcache_file command to obtain root privileges. IBM X-Force ID: 236690. |
A remote code execution vulnerability in EdgeRouters (Version 2.0.9-hotfix.4 and earlier) allows a malicious actor with an operator account to run arbitrary administrator commands.This vulnerability is fixed in Version 2...Show more |
1Moxa 64Aig 301 Ap Azu Lx Firmware Aig 301 Azu Lx FirmwareAig 301 Cn Azu Lx Firmware+61 moreJun 17, 2026 Nov 28, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Image: Versions v1.0 to v1.12, UC-2100-W System Image: Versions v1.0 to v 1.12, UC-3100 System Image: Versions v1.0 to v1.6, UC-5100 System Imag...Show more |
super-xray is the GUI alternative for vulnerability scanning tool xray. In 0.2-beta, a privilege escalation vulnerability was discovered. This caused inaccurate default xray permissions. Note: this vulnerability only aff...Show more |
Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote shell if the site is running on Ubuntu and the flag -dSAFER is not set...Show more |