An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges
Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an un
Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can cr
In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due
Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient P
A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the
Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to
A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under speci
Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevat
Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memor
Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU r
Vulnerability on the external sharing feature in Cryptobox allows an attacker knowing a sharing link URL to retrieve inf
Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to re
In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local es
In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation o
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with lim
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with lim
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections
A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When cer
Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, due to
Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura.
RTU500 web interface: An unprivileged user can read user management information. The information cannot be accessed via
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and I
Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux
Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to re
A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without
Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, the Do
Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, a low-
Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job
Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 o
LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP crede
When creating an export of all reusable media, the secrets of connected gift cards were included in the export even if
Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. This issue affects Apache
Frequently Asked Questions
What is CWE-280?
CWE-280 (CWE-280) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-280?
There are 39 CVE records associated with CWE-280 in our database. Of these, 1 are critical severity, 16 are high severity, and 19 are medium severity.
How can I protect against CWE-280 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-280 using AI-powered security agents.
Detect CWE-280 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-280 vulnerabilities across your infrastructure.
Get Started