CWE-264
1,444 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-264page 4 of 29
- CVE-2016-6394CRITICALCVSS 9.1EG 9.12016-09-12
Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hijack web sessions via a session identifier, aka Bug ID CSCuz80503.
- CVE-2016-3065CRITICALCVSS 9.1EG 9.12016-04-11
The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows attackers to bypass intended access restrictions and consequently obtain sensitive server memory inform…
- CVE-2015-8753CRITICALCVSS 9.1EG 9.12016-01-08
SAP Afaria 7.0.6001.5 allows remote attackers to bypass authorization checks and wipe or lock mobile devices via a crafted request, related to "Insecure signature," aka SAP Security Note 2134905.
- CVE-2022-36793CRITICALCVSS 6.5EG 9.12022-09-09
Unauthenticated Plugin Settings Change & Data Deletion vulnerabilities in WP Shop plugin <= 3.9.6 at WordPress.
- CVE-2023-52106CRITICALCVSS 4.4EG 9.12024-01-16
Vulnerability of permission verification for APIs in the DownloadProviderMain module. Impact: Successful exploitation of this vulnerability will affect integrity and availability.
- CVE-2016-4435CRITICALCVSS 9.0EG 9.02017-05-25
An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read or write blobs or cause a denial of service attack on the Director VM. This vulnerability…
- CVE-2014-0050CRITICALCVSS 7.5EG 9.02014-04-01
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type he…
- CVE-2004-2700HIGHCVSS v2 9.0EG 9.02004-12-31
Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.aspx.
- CVE-2016-3213HIGHCVSS 8.8EG 8.92016-06-16
The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Inte…
- CVE-2026-20046HIGHCVSS 8.8EG 8.82026-03-11
A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges and gain full administrative control of an affected device. This vulnerabili…
- CVE-2022-41978HIGHCVSS 8.8EG 8.82022-11-09
Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress.
- CVE-2022-34868HIGHCVSS 8.8EG 8.82022-08-23
Authenticated Arbitrary Settings Update vulnerability in YooMoney ЮKassa для WooCommerce plugin <= 2.3.0 at WordPress.
- CVE-2021-33036HIGHCVSS 8.8EG 8.82022-06-15
In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 …
- CVE-2021-27644HIGHCVSS 8.8EG 8.82021-11-01
In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password)
- CVE-2020-3443HIGHCVSS 8.8EG 8.82020-08-26
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges and execute commands with higher privileges. The vulnerability is due to insufficient authorization o…
- CVE-2020-3229HIGHCVSS 8.8EG 8.82020-06-03
A vulnerability in Role Based Access Control (RBAC) functionality of Cisco IOS XE Web Management Software could allow a Read-Only authenticated, remote attacker to execute commands or configuration changes as an Admin user. The vulnerabili…
- CVE-2020-3112HIGHCVSS 8.8EG 8.82020-02-19
A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to elevate privileges on the application. The vulnerability is due to insufficient access control validation…
- CVE-2020-3115HIGHCVSS 8.8EG 8.82020-01-26
A vulnerability in the CLI of the Cisco SD-WAN Solution vManage software could allow an authenticated, local attacker to elevate privileges to root-level privileges on the underlying operating system. The vulnerability is due to insufficie…
- CVE-2017-8230HIGHCVSS 8.8EG 8.82019-07-03
On Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices, the users on the device are divided into 2 groups "admin" and "user". However, as a part of security analysis it was identified that a low privileged user who belongs to the "user" gro…
- CVE-2017-8228HIGHCVSS 8.8EG 8.82019-07-03
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices mishandle reboots within the past two hours. Amcrest cloud services does not perform a thorough verification when allowing the user to add a new camera to the user's account to ensure that…
- CVE-2019-1626HIGHCVSS 8.8EG 8.82019-06-20
A vulnerability in the vManage web-based UI (Web UI) of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges on an affected vManage device. The vulnerability is due to a failure to properly au…
- CVE-2019-2003HIGHCVSS 8.8EG 8.82019-06-19
In addLinks of Linkify.java, there is a possible phishing vector due to an unusual root cause. This could lead to remote code execution or misdirection of clicks with no additional execution privileges needed. User interaction is needed fo…
- CVE-2019-2102HIGHCVSS 8.8EG 8.82019-06-07
In the Bluetooth Low Energy (BLE) specification, there is a provided example Long Term Key (LTK). If a BLE device were to use this as a hardcoded LTK, it is theoretically possible for a proximate attacker to remotely inject keystrokes on a…
- CVE-2017-18376HIGHCVSS 8.8EG 8.82019-06-02
An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to escalate their privileges to the administrator's privileges. This affects app/controllers/Use…
- CVE-2019-10132HIGHCVSS 8.8EG 8.82019-05-22
A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd…
- CVE-2015-3965HIGHCVSS 8.8EG 8.82019-03-23
Hospira Symbiq Infusion System 3.13 and earlier allows remote authenticated users to trigger "unanticipated operations" by leveraging "elevated privileges" for an unspecified call to an incorrectly exposed function.
- CVE-2019-3779HIGHCVSS 8.8EG 8.82019-03-08
Cloud Foundry Container Runtime, versions prior to 0.29.0, deploys Kubernetes clusters utilize the same CA (Certificate Authority) to sign and trust certs for ETCD as used by the Kubernetes API. This could allow a user authenticated with a…
- CVE-2018-13801HIGHCVSS 8.8EG 8.82018-10-10
A vulnerability has been identified in ROX II (All versions < V2.12.1). An attacker with network access to port 22/tcp and valid low-privileged user credentials for the target device could perform a privilege escalation and gain root privi…
- CVE-2018-0432HIGHCVSS 8.8EG 8.82018-10-05
A vulnerability in the error reporting feature of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to properly validate certain…
- CVE-2016-9489HIGHCVSS 8.8EG 8.82018-07-13
In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own group, i.e. changing their group to one with higher privileges like "ADMIN". A user is als…
- CVE-2018-0330HIGHCVSS 8.8EG 8.82018-06-20
A vulnerability in the NX-API management application programming interface (API) in devices running, or based on, Cisco NX-OS Software could allow an authenticated, remote attacker to execute commands with elevated privileges. The vulnerab…
- CVE-2018-0293HIGHCVSS 8.8EG 8.82018-06-20
A vulnerability in role-based access control (RBAC) for Cisco NX-OS Software could allow an authenticated, remote attacker to execute CLI commands that should be restricted for a nonadministrative user. The attacker would have to possess v…
- CVE-2018-0336HIGHCVSS 8.8EG 8.82018-06-07
A vulnerability in the batch provisioning feature of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to escalate privileges to the Administrator level. The vulnerability is due to insufficient authoriza…
- CVE-2018-0322HIGHCVSS 8.8EG 8.82018-06-07
A vulnerability in the web management interface of Cisco Prime Collaboration Provisioning (PCP) could allow an authenticated, remote attacker to modify sensitive data that is associated with arbitrary accounts on an affected device. The vu…
- CVE-2018-0317HIGHCVSS 8.8EG 8.82018-06-07
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning (PCP) could allow an authenticated, remote attacker to escalate their privileges. The vulnerability is due to insufficient web portal access control checks. An …
- CVE-2014-1946HIGHCVSS 8.8EG 8.82018-04-10
OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restrictions and assign administrative privileges to themselves via a crafted request to signup.p…
- CVE-2018-0152HIGHCVSS 8.8EG 8.82018-03-28
A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to gain elevated privileges on an affected device. The vulnerability exists because the affected software does …
- CVE-2018-0213HIGHCVSS 8.8EG 8.82018-03-08
A vulnerability in the credential reset functionality for Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to gain elevated privileges. The vulnerability is due to a lack of proper input validation. An att…
- CVE-2013-0267HIGHCVSS 8.8EG 8.82018-02-21
The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 allow remote authenticated users with nodeAdmin, manageGroup, resourceGrant, or userGrant permissions to gain privileges,…
- CVE-2016-8534HIGHCVSS 8.8EG 8.82018-02-15
A remote privilege elevation vulnerability in HPE Matrix Operating Environment version 7.6 was found.
- CVE-2016-8533HIGHCVSS 8.8EG 8.82018-02-15
A remote priviledge escalation vulnerability in HPE Matrix Operating Environment version 7.6 was found.
- CVE-2016-8528HIGHCVSS 8.8EG 8.82018-02-15
A Remote Escalation of Privilege vulnerability in HPE Helion Eucalyptus version 3.3.0 through 4.3.1 was found.
- CVE-2014-5070HIGHCVSS 8.8EG 8.82018-01-11
Symmetricom s350i 2.70.15 allows remote authenticated users to gain privileges via vectors related to pushing unauthenticated users to the login page.
- CVE-2014-0087HIGHCVSS 8.8EG 8.82018-01-11
The check_privileges method in vmdb/app/controllers/application_controller.rb in ManageIQ, as used in Red Hat CloudForms Management Engine (CFME), allows remote authenticated users to bypass authorization and gain privileges by leveraging …
- CVE-2016-10700HIGHCVSS 8.8EG 8.82017-11-24
auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database, because the guest user is not considered. NOTE: thi…
- CVE-2015-2673HIGHCVSS 8.8EG 8.82017-10-06
The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyCart plugin 1.1.30 through 3.0.20 for WordPress allow remote attackers to gain administrator privileges and execute arbi…
- CVE-2017-12230HIGHCVSS 8.8EG 8.82017-09-29
A vulnerability in the web-based user interface (web UI) of Cisco IOS XE 16.2 could allow an authenticated, remote attacker to elevate their privileges on an affected device. The vulnerability is due to incorrect default permission setting…
- CVE-2017-12226HIGHCVSS 8.8EG 8.82017-09-29
A vulnerability in the web-based Wireless Controller GUI of Cisco IOS XE Software for Cisco 5760 Wireless LAN Controllers, Cisco Catalyst 4500E Supervisor Engine 8-E (Wireless) Switches, and Cisco New Generation Wireless Controllers (NGWC)…
- CVE-2017-12214HIGHCVSS 8.8EG 8.82017-09-21
A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to gain elevated privileges.…
- CVE-2016-5861HIGHCVSS 8.8EG 8.82017-08-16
In a display driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a variable controlled by userspace is used to calculate offsets and sizes for copy operations, which could result in heap overflow.
Map vulnerabilities like CWE-264 to your infrastructure
EchelonGraph correlates every CVE — across CWE-264 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →