CVEs classified under CWE-842, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (9)
CVE-2024-9412: An improper authorization vulnerability exists in the Rockwell Automation affected products that could allow an unauthorized user to sign…
CVE-2022-3650 — CVSS 7.8 (high): A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root in the form of a…
CVE-2026-73439 — CVSS 7.5 (high): On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gNSI Pathz is…
CVE-2026-6970: authd prior to version 0.6.4 contains a logic error in primary group ID assignment that can lead to local privilege escalation. When a…
CVE-2022-2990 — CVSS 7.1 (high): An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or…
CVE-2022-2989 — CVSS 7.1 (high): An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or…
CVE-2022-45097 — CVSS 6.3 (medium): Dell PowerScale OneFS 9.0.0.x-9.4.0.x contains an Incorrect User Management vulnerability. A low privileged network attacker could…
CVE-2022-31007 — CVSS 4.9 (medium): eLabFTW is an electronic lab notebook manager for research teams. Prior to version 4.3.0, a vulnerability allows an authenticated user with…
CVE-2026-102585 — CVSS 4.3 (medium): A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether…