Skip to main content

CWE archive

CWE-279 CVEs

Programmatic archive

26 CVEs tagged with CWE-2791 Critical, 11 High, 12 Medium, 2 Low, 0 Unrated.

CVE-2026-46388

Published Jul 10, 2026

osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, an unprivileged attacker can read the contents of an osquery file…

CVSS 4.4 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-4948

Published Mar 27, 2026

A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicyS…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-20062

Published Mar 4, 2026

A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in multiple context mode could allow an authenticated, local attacker with administr…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-14025

Published Jan 8, 2026

A flaw was found in Ansible Automation Platform (AAP). Read-only scoped OAuth2 API Tokens in AAP, are enforced at the Gateway level for Gateway-specific operations. However, this…

CVSS 8.5 · High
evidence mentions
7
Buzz score
30.8

CVE-2025-36228

Published Dec 26, 2025

IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API allowed users to access features that appeared disabled, p…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-13663

Published Dec 11, 2025

Under certain circumstances, the Quartus Prime Pro Installer for Windows does not check the permissions of the Quartus target installation directory if the target installation dir…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-25621

Published Nov 6, 2025

containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4 and 2.2.0-beta.0 through 2.2.0-rc.1 have an o…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-30001

Published Oct 10, 2025

Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to v…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58437

Published Sep 6, 2025

Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3, 2.25.0 and 2.25.1, Coder can be compromised through inse…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-26422

Published Sep 4, 2025

In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permission check. This could lead to local escala…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-23263

Published Jul 17, 2025

NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause escalation of privileges and denial of service on the VLAN.

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-23233

Published May 13, 2025

Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable escalation of…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-22843

Published May 13, 2025

Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable escalation of…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-20612

Published May 13, 2025

Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable escalation of…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-39286

Published Feb 12, 2025

Incorrect execution-assigned permissions in the Linux kernel mode driver for the Intel(R) 800 Series Ethernet Driver before version 1.15.4 may allow an authenticated user to poten…

CVSS 2.0 · Low

CVE-2024-37025

Published Nov 13, 2024

Incorrect execution-assigned permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installer before version 23.1.1 may allow an authenticated user to poten…

CVSS 5.4 · Medium

CVE-2024-37734

Published Jun 26, 2024

An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-50914

Published Apr 30, 2024

A Privilege Escalation issue in the inter-process communication procedure from GOG Galaxy (Beta) 2.0.67.2 through v2.0.71.2 allows authentictaed users to change the DACL of arbitr…

CVSS 6.7 · Medium

CVE-2023-4665

Published Sep 15, 2023

Incorrect Execution-Assigned Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation. This issue affects Saphira Connect: before 9.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3915

Published Sep 1, 2023

An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 b…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4383

Published Aug 16, 2023

A vulnerability, which was classified as critical, was found in MicroWorld eScan Anti-Virus 7.0.32 on Linux. This affects an unknown part of the file runasroot. The manipulation l…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 26 CVEsPage 1 of 2