An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileg
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a networ
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator
A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersona
IBM Common Cryptographic Architecture (CCA) 7.5.52 and 8.4.82 could allow an unauthenticated user to execute arbitrary c
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a configuration injection issue in the Docker tool sand
An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of seriali
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems.
Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who
Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had comp
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1
bleon-ethical/api-gateway-deploy provides API gateway deployment. Version 1.0.0 is vulnerable to an attack chain involvi
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a critic
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized a
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4). Affected application contains
Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was
OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code exec
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a bina
A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Ac
A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in a
Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker t
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain sensit
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vulnerabil
Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engin
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the
A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administra
A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permission
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdav
theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to versi
A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper
Improper access control in the WCF endpoint in Edgemo (now owned by Danoffice IT) Local Admin Service 1.2.7.23180 on Win
MacroHub developed by GIGABYTE has a Local Privilege Escalation vulnerability. Due to the MacroHub application launching
Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical R
Execution with unnecessary privileges in Forcepoint NGFW Engine allows local privilege escalation.This issue affects NGF
A local attacker can bypass OpenEDR's 2.5.1.0 self-defense mechanism by renaming a malicious executable to match a trust
An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos
IBM Netezza Performance Server Replication Services 3.0.2.0 through 3.0.5.0 allows an attacker with low‑privileged acces
A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user t
A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges befor
A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by
The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the
Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalatio
NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use imp
A local privilege escalation vulnerability exists in the Restricted Access (Kiosk) Mode implementation of Scheidt & Bach
Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index dat
Frequently Asked Questions
What is CWE-250?
CWE-250 (CWE-250) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-250?
There are 95 CVE records associated with CWE-250 in our database. Of these, 17 are critical severity, 41 are high severity, and 17 are medium severity.
How can I protect against CWE-250 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-250 using AI-powered security agents.
Detect CWE-250 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-250 vulnerabilities across your infrastructure.
Get Started