CWE-264
1,444 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-264page 8 of 29
- CVE-2016-7070HIGHCVSS 8.0EG 8.02018-09-11
A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to gain admin level acc…
- CVE-2016-9070HIGHCVSS 8.0EG 8.02018-06-11
A maliciously crafted page loaded to the sidebar through a bookmark can reference a privileged chrome window and engage in limited JavaScript operations violating cross-origin protections. This vulnerability affects Firefox < 50.
- CVE-2015-0864HIGHCVSS 8.0EG 8.02017-03-27
Samsung Account (AKA com.osp.app.signin) before 1.6.0069 and 2.x before 2.1.0069 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code.
- CVE-2015-0863HIGHCVSS 8.0EG 8.02017-03-27
GALAXY Apps (aka Samsung Apps, Samsung Updates, or com.sec.android.app.samsungapps) before 14120405.03.012 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code.
- CVE-2015-0721HIGHCVSS 8.0EG 8.02016-10-06
Cisco NX-OS 4.0 through 7.3 on Multilayer Director and Nexus 1000V, 2000, 3000, 3500, 4000, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote authenticated users to bypass intended AAA restrictions and obtain privileged CL…
- CVE-2015-1328HIGHCVSS 7.8EG 8.02016-11-28
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain ro…
- CVE-2024-53011HIGHCVSS 7.9EG 7.92025-03-03
Information disclosure may occur due to improper permission and access controls to Video Analytics engine.
- CVE-2025-48903HIGHCVSS 7.8EG 7.82025-06-06
Permission bypass vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2022-23714HIGHCVSS 7.8EG 7.82022-07-06
A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
- CVE-2022-23731HIGHCVSS 7.8EG 7.82022-03-11
V8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models.
- CVE-2020-3473HIGHCVSS 7.8EG 7.82020-09-04
A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local CLI shell user to elevate privileges and gain full administrative control of the device. The vulnerability is …
- CVE-2020-3379HIGHCVSS 7.8EG 7.82020-07-16
A vulnerability in Cisco SD-WAN Solution Software could allow an authenticated, local attacker to elevate privileges to Administrator on the underlying operating system. The vulnerability is due to insufficient input validation. An attacke…
- CVE-2020-3180HIGHCVSS 7.8EG 7.82020-07-16
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that has a default, static password. This account has root privileges. The vulnerability exis…
- CVE-2020-8489HIGHCVSS 7.8EG 7.82020-04-29
Insufficient protection of the inter-process communication functions in ABB System 800xA Information Management (all published versions) enables an attacker authenticated on the local system to inject data, affecting the runtime values to …
- CVE-2020-8488HIGHCVSS 7.8EG 7.82020-04-29
Insufficient protection of the inter-process communication functions in ABB System 800xA Batch Management (all published versions) enables an attacker authenticated on the local system to inject data, affecting User Interface update during…
- CVE-2020-8485HIGHCVSS 7.8EG 7.82020-04-29
Insufficient protection of the inter-process communication functions in ABB System 800xA for MOD 300 (all published versions) enables an attacker authenticated on the local system to inject data, allowing reads and writes to the controller…
- CVE-2020-8484HIGHCVSS 7.8EG 7.82020-04-29
Insufficient protection of the inter-process communication functions in ABB System 800xA for DCI (all published versions) enables an attacker authenticated on the local system to inject data, allowing reads and writes to the controllers or…
- CVE-2020-3265HIGHCVSS 7.8EG 7.82020-03-19
A vulnerability in Cisco SD-WAN Solution software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating system. The vulnerability is due to insufficient input validation. An attacker could e…
- CVE-2019-11773HIGHCVSS 7.8EG 7.82019-09-12
Prior to 0.1, AIX builds of Eclipse OMR contain unused RPATHs which may facilitate code injection and privilege elevation by local users.
- CVE-2019-1966HIGHCVSS 7.8EG 7.82019-08-30
A vulnerability in a specific CLI command within the local management (local-mgmt) context for Cisco UCS Fabric Interconnect Software could allow an authenticated, local attacker to gain elevated privileges as the root user on an affected …
- CVE-2019-14257HIGHCVSS 7.8EG 7.82019-08-21
pyraw in Zenoss 2.5.3 allows local privilege escalation by modifying environment variables to redirect execution before privileges are dropped, aka ZEN-31765.
- CVE-2019-12808HIGHCVSS 7.8EG 7.82019-08-13
ALTOOLS update service 18.1 and earlier versions contains a local privilege escalation vulnerability due to insecure permission. An attacker can overwrite an executable that is launched as a service to exploit this vulnerability and execut…
- CVE-2017-18413HIGHCVSS 7.8EG 7.82019-08-02
In cPanel before 67.9999.103, the backup system overwrites root's home directory when a mount disappears (SEC-299).
- CVE-2017-18383HIGHCVSS 7.8EG 7.82019-08-02
cPanel before 68.0.15 writes home-directory backups to an incorrect location (SEC-309).
- CVE-2019-11771HIGHCVSS 7.8EG 7.82019-07-17
AIX builds of Eclipse OpenJ9 before 0.15.0 contain unused RPATHs which may facilitate code injection and privilege elevation by local users.
- CVE-2019-13125HIGHCVSS 7.8EG 7.82019-07-01
HaboMalHunter through 2.0.0.3 in Tencent Habo allows attackers to evade dynamic malware analysis via PIE compilation.
- CVE-2019-1625HIGHCVSS 7.8EG 7.82019-06-20
A vulnerability in the CLI of Cisco SD-WAN Solution could allow an authenticated, local attacker to elevate lower-level privileges to the root user on an affected device. The vulnerability is due to insufficient authorization enforcement. …
- CVE-2019-0128HIGHCVSS 7.8EG 7.82019-06-13
Improper permissions in the installer for Intel(R) Chipset Device Software (INF Update Utility) before version 10.1.1.45 may allow an authenticated user to escalate privilege via local access.
- CVE-2019-1682HIGHCVSS 7.8EG 7.82019-05-03
A vulnerability in the FUSE filesystem functionality for Cisco Application Policy Infrastructure Controller (APIC) software could allow an authenticated, local attacker to escalate privileges to root on an affected device. The vulnerabilit…
- CVE-2019-1592HIGHCVSS 7.8EG 7.82019-05-03
A vulnerability in the background operations functionality of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an authenticated, local attacker to gain elevated privileges as root on an affe…
- CVE-2019-0731HIGHCVSS 7.8EG 7.82019-04-09
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0796, CVE-2019-080…
- CVE-2019-0730HIGHCVSS 7.8EG 7.82019-04-09
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0731, CVE-2019-0796, CVE-2019-080…
- CVE-2019-10885HIGHCVSS 7.8EG 7.82019-04-05
An issue was discovered in Ivanti Workspace Control before 10.3.90.0. Local authenticated users with low privileges in a Workspace Control managed session can bypass Workspace Control security features configured for this session by resett…
- CVE-2019-0135HIGHCVSS 7.8EG 7.82019-03-14
Improper permissions in the installer for Intel(R) Accelerated Storage Manager in Intel(R) RSTe before version 5.5.0.2015 may allow an authenticated user to potentially enable escalation of privilege via local access. L-SA-00206
- CVE-2019-0129HIGHCVSS 7.8EG 7.82019-03-14
Improper permissions for Intel(R) USB 3.0 Creator Utility all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2019-0121HIGHCVSS 7.8EG 7.82019-03-14
Improper permissions in Intel(R) Matrix Storage Manager 8.9.0.1023 and before may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2019-1602HIGHCVSS 7.8EG 7.82019-03-08
A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive data that could be used to elevate their privileges to administrator. The vulnerability is due to improp…
- CVE-2019-1596HIGHCVSS 7.8EG 7.82019-03-07
A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level to root. The attacker must authenticate with valid user credentials. The vulnerability…
- CVE-2019-1593HIGHCVSS 7.8EG 7.82019-03-06
A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level by executing commands authorized to other user roles. The attacker must authenticate w…
- CVE-2019-1591HIGHCVSS 7.8EG 7.82019-03-06
A vulnerability in a specific CLI command implementation of Cisco Nexus 9000 Series ACI Mode Switch Software could allow an authenticated, local attacker to escape a restricted shell on an affected device. The vulnerability is due to insuf…
- CVE-2019-3475HIGHCVSS 7.8EG 7.82019-02-20
A local privilege escalation vulnerability in the famtd component of Micro Focus Filr 3.0 allows a local attacker authenticated as a low privilege user to escalate to root. This vulnerability affects all versions of Filr 3.x prior to Secur…
- CVE-2019-1648HIGHCVSS 7.8EG 7.82019-01-24
A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to properly validate certain…
- CVE-2019-1646HIGHCVSS 7.8EG 7.82019-01-24
A vulnerability in the local CLI of the Cisco SD-WAN Solution could allow an authenticated, local attacker to escalate privileges and modify device configuration files. The vulnerability exists because user input is not properly sanitized …
- CVE-2016-10730HIGHCVSS 7.8EG 7.82018-10-24
An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Application API script. It should not be run by users directly. It uses star to backup and restore d…
- CVE-2018-0417HIGHCVSS 7.8EG 7.82018-10-17
A vulnerability in TACACS authentication with Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to perform certain operations within the GUI that are not normally available to that user on the CLI. T…
- CVE-2018-0437HIGHCVSS 7.8EG 7.82018-10-05
A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administrator. To exploit the vulnerability, the attacker must authenticate with valid local user c…
- CVE-2016-8657HIGHCVSS 7.8EG 7.82018-07-31
It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuration files. The file is writable to jboss group (root:jboss, 664). On systems using classic /…
- CVE-2016-9486HIGHCVSS 7.8EG 7.82018-07-13
On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full functionality of the agent. The typical configuration is for the agent to run as a Windows ser…
- CVE-2016-9485HIGHCVSS 7.8EG 7.82018-07-13
On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full functionality of the agent. The typical configuration is for the agent to run as a Windows ser…
- CVE-2016-5295HIGHCVSS 7.8EG 7.82018-06-11
This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Maintenance Service invoke the Mozilla Updater to run malicious local files. This vulnerability requires local system access a…
Map vulnerabilities like CWE-264 to your infrastructure
EchelonGraph correlates every CVE — across CWE-264 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →