Skip to main content

CWE archive

CWE-272 CVEs

Programmatic archive

35 CVEs tagged with CWE-2722 Critical, 18 High, 10 Medium, 4 Low, 1 Unrated.

CVE-2026-15271

Published Jul 9, 2026

A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 up to 20260906. Affected by this issue is some unknown funct…

CVSS 7.7 · High
evidence mentions
12
Buzz score
40.6

CVE-2026-15270

Published Jul 9, 2026

A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functionality of the file /etc/boa/boa.conf of the component Web…

CVSS 6.8 · Medium
evidence mentions
6
Buzz score
34.5
Vendor/product tagsBeta · best-effort

CVE-2026-11620

Published Jun 9, 2026

A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation results…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-11554

Published Jun 8, 2026

A vulnerability was determined in TOTOLINK CP450 4.1.0cu.747. This vulnerability affects unknown code of the file /etc/vsftpd.conf of the component vsftpd. This manipulation cause…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-11497

Published Jun 8, 2026

A vulnerability has been found in D-Link DCS-5615 1.01.00. Affected by this vulnerability is an unknown functionality of the file /etc/conf.d/boa/boa.conf of the component Boa Web…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0
Vendor/product tagsBeta · best-effort

CVE-2026-11494

Published Jun 8, 2026

A security vulnerability has been detected in TOTOLINK AC1200 T8 4.1.5cu.8611. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulat…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-11492

Published Jun 8, 2026

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05. The affected element is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Performing a man…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0
Vendor/product tagsBeta · best-effort

CVE-2026-32655

Published Apr 27, 2026

Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain a Least Privilege Violation vulnerability. A low privileged attacker with local access could potentially…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-9711

Published Feb 3, 2026

A vulnerability in Brocade Fabric OS before 9.2.1c3 could allow elevating the privileges of the local authenticated user to “root” using the export option of seccertmgmt and seccr…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2026-23634

Published Jan 16, 2026

Pepr is a type safe K8s middleware. Prior to 1.0.5 , Pepr defaults to a cluster-admin RBAC configuration and does not explicitly force or enforce least-privilege guidance for modu…

CVSS 0.0 · Unrated
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-68267

Published Dec 16, 2025

In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-8758

Published Aug 9, 2025

A vulnerability was found in TRENDnet TEW-822DRE FW103B02. It has been classified as problematic. This affects an unknown part of the component vsftpd. The manipulation leads to l…

CVSS 6.4 · Medium

CVE-2025-8757

Published Aug 9, 2025

A vulnerability was found in TRENDnet TV-IP110WN 1.2.2 and classified as problematic. Affected by this issue is some unknown functionality of the file /server/boa.conf of the comp…

CVSS 6.4 · Medium

CVE-2025-7722

Published Jul 23, 2025

The Social Streams plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.1. This is due to the plugin not properly validating a user…

CVSS 8.8 · High

CVE-2025-1384

Published Jul 14, 2025

Least Privilege Violation (CWE-272) Vulnerability exists in the communication function between the NJ/NX-series Machine Automation Controllers and the Sysmac Studio Software. An a…

CVSS 7.0 · High
evidence mentions
2
Buzz score
16.0

CVE-2025-49144

Published Jun 23, 2025

Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unpr…

CVSS 7.3 · High
evidence mentions
2
Buzz score
16.0

CVE-2025-47809

Published May 16, 2025

Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivilege…

CVSS 8.2 · High

CVE-2024-55954

Published Jan 16, 2025

OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/users/{email_id}` allows an "Admin" role user to remove a "Roo…

CVSS 8.7 · High

CVE-2024-28829

Published Aug 20, 2024

Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0p12, 2.2.0p32, 2.1.0p47 and 2.0.0 (EOL) allows local users t…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27165

Published Jun 14, 2024

Toshiba printers contain a suidperl binary and it has a Local Privilege Escalation vulnerability. A local attacker can get root privileges. As for the affected products/models/ver…

CVSS 7.8 · High
Showing 1-25 of 35 CVEsPage 1 of 2