Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-280

MITRE ↗

CWE-280

1
CRITICAL
16
HIGH
19
MEDIUM
39 CVEs
9.9
CVE-2025-46066

An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges

8.8
CVE-2026-24096

Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5

8.8
CVE-2026-40371

Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized

8.8
CVE-2026-59567

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an un

8.7
CVE-2026-18860

Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can cr

8.4
CVE-2026-0047

In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due

8.2
CVE-2026-23857

Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient P

8.1
CVE-2025-67848

A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the

7.8
CVE-2026-20817

Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to

7.8
CVE-2026-2123

A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under speci

7.8
CVE-2026-27910

Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevat

7.8
CVE-2026-45195

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memor

7.8
CVE-2026-45196

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU r

7.5
CVE-2026-6805

Vulnerability on the external sharing feature in Cryptobox allows an attacker knowing a sharing link URL to retrieve inf

7.3
CVE-2026-21733

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to re

7.1
CVE-2026-46054

In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access

7.1
CVE-2026-58416

Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

6.7
CVE-2026-20448

In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local es

6.7
CVE-2026-20463

In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation o

6.5
CVE-2026-44197

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without

6.5
CVE-2026-44199

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with lim

6.5
CVE-2026-44200

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with lim

6.5
CVE-2026-2340

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections

6.5
CVE-2026-9792

A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When cer

6.5
CVE-2026-54261

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, due to

6.5
CVE-2026-73239

Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura.

5.3
CVE-2026-1772

RTU500 web interface: An unprivileged user can read user management information. The information cannot be accessed via

5.3
CVE-2026-44201

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and I

5.2
CVE-2026-11804

Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux

4.4
CVE-2026-21736

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to re

4.3
CVE-2026-3190

A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to

4.3
CVE-2026-44198

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without

4.3
CVE-2026-54259

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, the Do

4.3
CVE-2026-54262

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, a low-

4.3
CVE-2026-62393

Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job

4.3
CVE-2026-55468

Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 o

CVE-2026-10549

LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP crede

CVE-2026-11764

When creating an export of all reusable media, the secrets of connected gift cards were included in the export even if

CVE-2026-41566

Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. This issue affects Apache

Frequently Asked Questions

What is CWE-280?

CWE-280 (CWE-280) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-280?

There are 39 CVE records associated with CWE-280 in our database. Of these, 1 are critical severity, 16 are high severity, and 19 are medium severity.

How can I protect against CWE-280 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-280 using AI-powered security agents.

Detect CWE-280 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-280 vulnerabilities across your infrastructure.

Get Started