Skip to main content

CWE archive

CWE-268 CVEs

Programmatic archive

22 CVEs tagged with CWE-2681 Critical, 13 High, 7 Medium, 1 Low, 0 Unrated.

CVE-2026-32325

Published Jun 1, 2026

Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploited, a local authenticated attacker who can log in to the se…

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-3888

Published Mar 17, 2026

Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to autom…

CVSS 7.8 · High
evidence mentions
12
Buzz score
45.6
Vendor/product tagsBeta · best-effort

CVE-2025-64701

Published Dec 11, 2025

QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability, which may allow a user who can log in to a Windows system with the affected produ…

CVSS 8.5 · High

CVE-2025-7973

Published Aug 14, 2025

A security issue exists in FactoryTalk ViewPoint version 14.0 or below due to improper handling of MSI repair operations. During a repair, attackers can hijack the cscript.exe con…

CVSS 8.5 · High

CVE-2025-36124

Published Aug 12, 2025

IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security restrictions caused by a failure to honor JMS messaging configu…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2297

Published Jul 28, 2025

Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certa…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-20112

Published May 21, 2025

A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate privileges to root on an aff…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-32955

Published Apr 21, 2025

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Versions from 0.12.0 to before 2.12.0 are vulnerable to `disable-sudo` bypass. Harden-Ru…

CVSS 6.0 · Medium

CVE-2025-2903

Published Apr 17, 2025

An attacker with knowledge of creating user accounts during VM deployment on Google Cloud Platform (GCP) using the OS Login feature, can login via SSH gaining command-line control…

CVSS 8.5 · High

CVE-2024-4877

Published Apr 3, 2025

OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it t…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-0889

Published Feb 26, 2025

Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows installed, via the manipulation of COM objects under certain…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-47045

Published Sep 26, 2024

Privilege chaining issue exists in the installer of e-Tax software(common program). If this vulnerability is exploited, a malicious DLL prepared by an attacker may be executed wit…

CVSS 7.8 · High

CVE-2024-1299

Published Mar 7, 2024

A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user with custom role of `man…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1250

Published Feb 12, 2024

An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assigned a custom role with manage_group_access_tokens permission…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-20194

Published Sep 7, 2023

A vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device. To expl…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0971

Published Jun 21, 2023

A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be rec…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-2250

Published Apr 24, 2023

A flaw was found in the Open Cluster Management (OCM) when a user have access to the worker nodes which has the cluster-manager-registration-controller or cluster-manager deployme…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1003

Published Mar 18, 2022

One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/cap…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1