CWE-280
154 CVEs • Abstraction: Base
Improper Handling of Insufficient Permissions or Privileges
The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.
CVEs (154)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Unprotected dynamic receiver in Telecom prior to SMR Feb-2022 Release 1 allows untrusted applications to launch arbitrary activity. |
1Nvidia 6Geforce Gpu Display DriverNvs+3 moreJun 17, 2026 Feb 7, 2022 N/A· v4 6.1 MEDIUM· v3 3.6 LOW· v2 NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver package, where improper handling of insufficient permissions or privileges may allow an unprivileged local user limited write access to pr...Show more |
1Siemens 10Ruggedcom Rox Mx5000 Firmware Ruggedcom Rox Rx1400 FirmwareRuggedcom Rox Rx1500 Firmware+7 moreJun 17, 2026 Sep 14, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM ROX RX1400 (All versions < V2.14.1), RUGGEDCOM ROX RX1500 (All versions < V2.14.1), RUGGEDCOM ROX RX1501 (All versions < V2....Show more |
1Redux 1Gutenberg Template Library & Redux Framework Jun 17, 2026 Sep 2, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress used an incorrect authorization check in the REST API endpoints registered under the “redux/v1/templates/” REST Route in “redux-templates/cl...Show more |
Improper Handling of Insufficient Permissions or Privileges in zephyr. Zephyr versions >= v1.14.2, >= v2.2.0 contain Improper Handling of Insufficient Permissions or Privileges (CWE-280). For more information, see https:...Show more |
1Secomea 4Gatemanager 4250 Firmware Gatemanager 4260 FirmwareGatemanager 8250 Firmware+1 moreJun 17, 2026 Feb 15, 2021 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privil...Show more |
Dell EMC PowerScale OneFS versions 8.1.2 – 9.1.0 contain an issue where the OneFS SMB directory auto-create may erroneously create a directory for a user. A remote unauthenticated attacker may take advantage of this issu...Show more |
1Cisco 1Duo Authentication For Windows Logon And Rdp Jun 17, 2026 Oct 14, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The Windows Logon installer prior to 4.1.2 did not properly validate file installation paths. This allows an attacker with local user privileges to coerce the installer to write to arbitrary privileged directories. If su...Show more |
2Ivanti Pulsesecure4Connect Secure Policy SecurePulse Connect Secure+1 moreJun 17, 2026 Jul 30, 2020 N/A· v4 7.2 HIGH· v3 4.0 MEDIUM· v2 An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change the password of a full administrator. |
Improper preservation of permissions in Nextcloud Server 14.0.3 causes the event details to be leaked when sharing a non-public event. |
An improper authentication check in Palo Alto Networks PAN-OS may allow an authenticated low privileged non-superuser custom role user to elevate privileges and become superuser. This issue affects PAN-OS 7.1 versions pr...Show more |
Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users can gain read access to data they are not authorized to see. |
1Siemens 1Sinema Remote Connect Server Jun 17, 2026 Apr 17, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Due to insufficient checking of user permissions, an attacker may access URLs that require special authorization. An attacker mus...Show more |
1Redhat 1Jboss Enterprise Application Platform May 14, 2026 Jan 5, 2013 N/A· v4 5.3 MEDIUM· v3 6.4 MEDIUM· v2 A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly call the necessary authorization modules. This preven...Show more |