Skip to main content

CWE archive

CWE-278 CVEs

Programmatic archive

6 CVEs tagged with CWE-2780 Critical, 5 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2026-6265

Published Apr 27, 2026

Insecure preserved inherited permissions vulnerability in Cerberus FTP Server on Windows allows Privilege Escalation.This issue has been resolved in Cerberus FTP Server: 2026.1

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-2947

Published Apr 17, 2025

IBM i 7.6  contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command.  A malicious actor can use the command to elevate privileges to gain…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36538

Published Jul 24, 2024

Insecure permissions in chaos-mesh v2.6.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37769

Published Jul 5, 2024

Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-38531

Published Jun 28, 2024

Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible. A build process has access to and can change the permissions of…

CVSS 3.6 · Low
Showing 1-6 of 6 CVEsPage 1 of 1