Skip to main content

CWE archive

CWE-842 CVEs

Programmatic archive

10 CVEs tagged with CWE-8420 Critical, 8 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-6970

Published Apr 27, 2026

authd prior to version 0.6.4 contains a logic error in primary group ID assignment that can lead to local privilege escalation. When a user's primary group ID (GID) differs from t…

CVSS 7.3 · High
evidence mentions
2
Buzz score
16.0

CVE-2024-10082

Published Nov 6, 2024

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication method confusion allows logging in as the bu…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9412

Published Oct 8, 2024

An improper authorization vulnerability exists in the Rockwell Automation affected products that could allow an unauthorized user to sign in. While removal of all role mappings is…

CVSS 8.4 · High

CVE-2024-25632

Published Oct 1, 2024

eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a user account with certain privileges to manage users and cont…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25575

Published Feb 28, 2023

API Platform Core is the server component of API Platform: hypermedia and GraphQL APIs. Resource properties secured with the `security` option of the `ApiPlatform\Metadata\ApiProp…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-45097

Published Feb 1, 2023

Dell PowerScale OneFS 9.0.0.x-9.4.0.x contains an Incorrect User Management vulnerability. A low privileged network attacker could potentially exploit this vulnerability, leading…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3650

Published Jan 17, 2023

A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root in the form of a crash dump, and dump privileged informati…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31007

Published May 31, 2022

eLabFTW is an electronic lab notebook manager for research teams. Prior to version 4.3.0, a vulnerability allows an authenticated user with an administrator role in a team to assi…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1