Skip to main content

CWE archive

CWE-648 CVEs

Programmatic archive

67 CVEs tagged with CWE-64812 Critical, 36 High, 19 Medium, 0 Low, 0 Unrated.

CVE-2026-63727

Published Jul 28, 2026

Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is abl…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-54424

Published Jul 4, 2026

An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. Th…

CVSS 8.4 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-11877

Published Jun 24, 2026

An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue affects Access Manager before 5.1.3.

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-9560

Published May 26, 2026

Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC c…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41386

Published Apr 28, 2026

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pairing. Attackers can…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-41329

Published Apr 21, 2026

OpenClaw before 2026.3.31 contains a sandbox bypass vulnerability allowing attackers to escalate privileges via heartbeat context inheritance and senderIsOwner parameter manipulat…

CVSS 9.0 · Critical
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-54502

Published Apr 16, 2026

Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privilege escalation…

CVSS 7.1 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-35669

Published Apr 10, 2026

OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plugin HTTP routes that incorrectly mint operator.admin runtime scope regardless o…

CVSS 8.7 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-35663

Published Apr 10, 2026

OpenClaw before 2026.3.25 contains a privilege escalation vulnerability allowing non-admin operators to self-request broader scopes during backend reconnect. Attackers can bypass…

CVSS 8.7 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-35645

Published Apr 9, 2026

OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in the gateway plugin subagent fallback deleteSession function that uses a synthetic operator.admin runtime…

CVSS 6.1 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-35639

Published Apr 9, 2026

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the device.pair.approve method that allows an operator.pairing approver to approve pending device reques…

CVSS 8.7 · High
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-35625

Published Apr 9, 2026

OpenClaw before 2026.3.25 contains a privilege escalation vulnerability where silent local shared-auth reconnects auto-approve scope-upgrade requests, widening paired device permi…

CVSS 8.5 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-20126

Published Feb 25, 2026

A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gain root privileges on the underlying operating system. Th…

CVSS 8.8 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-20122

Published Feb 25, 2026

A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vu…

CVSS 5.4 · Medium
evidence mentions
18
Buzz score
74.4
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2026-22922

Published Feb 9, 2026

Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that can allow an authenticated user with custom permissions limited to task access to view task logs wit…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-1161

Published Dec 10, 2025

Incorrect Use of Privileged APIs vulnerability in NomySoft Information Technology Training and Consulting Inc. Nomysem allows Privilege Escalation. This issue affects Nomysem: th…

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-63291

Published Nov 14, 2025

When processing API requests, the Alteryx server 2022.1.1.42654 and 2024.1 used MongoDB object IDs to uniquely identify the data being requested by the caller. The Alteryx server…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32008

Published Nov 11, 2025

A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to a local privilege escalation due to an expo…

CVSS 8.5 · High

CVE-2025-54769

Published Jul 29, 2025

An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwri…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54768

Published Jul 29, 2025

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint can be used t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54767

Published Jul 29, 2025

An authenticated, read-only user can kill any processes running on the Xormon Original virtual appliance as the lpar2rrd user.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54766

Published Jul 29, 2025

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint can be used t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54765

Published Jul 29, 2025

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint can be used t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5997

Published Jul 28, 2025

Incorrect Use of Privileged APIs vulnerability in Beamsec PhishPro allows Privilege Abuse. This issue affects PhishPro: before 7.5.4.2.

CVSS 8.8 · High
Showing 1-25 of 67 CVEsPage 1 of 3