Skip to main content

CWE archive

CWE-274 CVEs

Programmatic archive

42 CVEs tagged with CWE-2742 Critical, 23 High, 16 Medium, 1 Low, 0 Unrated.

CVE-2026-62764

Published Jul 17, 2026

Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user without system permissions may issue a remote command to g…

CVSS 5.7 · Medium
evidence mentions
5
Buzz score
34.4

CVE-2025-54511

Published May 15, 2026

Improper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an attacker to provide an input value to a function without sufficient privileges and su…

CVSS 5.3 · Medium

CVE-2026-33005

Published Apr 9, 2026

Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of a…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-62175

Published Oct 13, 2025

Mastodon is a free, open-source social network server based on ActivityPub. In versions before 4.4.6, 4.3.14, and 4.2.27, disabling or suspending a user account does not disconnec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-20516

Published Sep 6, 2025

Improper handling of insufficiency privileges in the ASP could allow a privileged attacker to modify Translation Map Registers (TMRs) potentially resulting in loss of confidential…

CVSS 3.3 · Low

CVE-2025-31275

Published Jul 30, 2025

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A sandboxed process may be able to launch any installed app.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-46974

Published Jan 31, 2025

Software installed and run as a non-privileged user may conduct improper read/write operations on imported/exported DMA buffers.

CVSS 7.8 · High

CVE-2025-20156

Published Jan 22, 2025

A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privileges to elevate privileges to administrator on an affected…

CVSS 9.9 · Critical
evidence mentions
7
Buzz score
35.3
Vendor/product tagsBeta · best-effort

CVE-2024-12666

Published Dec 16, 2024

A vulnerability has been found in ClassCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin?do=admin:user:editPo…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0106

Published Nov 1, 2024

NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability where an attacker may cause an improper handling of insufficient privileges iss…

CVSS 8.7 · High

CVE-2024-0105

Published Nov 1, 2024

NVIDIA ConnectX Firmware contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue. A successful exploit of this vulnerability may…

CVSS 8.9 · High

CVE-2024-41942

Published Aug 8, 2024

JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the `admin:users` scope, they m…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-20324

Published Mar 27, 2024

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, low-privileged, local attacker to access WLAN configuration details including passwords. This…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21648

Published Jan 9, 2024

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The rollback action is missing a right protection, a user can rollback to…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32494

Published Aug 16, 2023

Dell PowerScale OneFS, 8.0.x-9.5.x, contains an improper handling of insufficient privileges vulnerability. A local privileged attacker could potentially exploit this vulnerabili…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-35928

Published Jun 23, 2023

Nextcloud Server is a space for data storage on Nextcloud, a self-hosted productivity playform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcl…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-45101

Published Feb 1, 2023

Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS. A remote unauthenticated attacker could potentially exploit…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-0668

Published Jan 8, 2023

JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated us…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25782

Published May 4, 2022

Improper Handling of Insufficient Privileges vulnerability in Web UI of Secomea GateManager allows logged in user to access and update privileged information. This issue affects:…

CVSS 5.4 · Medium

CVE-2022-23160

Published Apr 12, 2022

Dell PowerScale OneFS, versions 8.2.0-9.3.0, contains an Improper Handling of Insufficient Permissions vulnerability. An remote malicious user could potentially exploit this vulne…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32006

Published Mar 10, 2022

This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Permission Issues vulnerability in LinkManager web portal of Secomea GateManager allows logge…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 42 CVEsPage 1 of 2