Threats Tagged 'cwe-648'
View all threats tagged with 'cwe-648'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-648'
Click on any threat for detailed analysis and mitigation recommendations
An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. A user can generate a situation where there is an instance of parsecd.exe running as NT AUTHORITY\SYSTEM with a user-controlled value of the AppData environment variable. Join the discussion | CVE Database V5 | 07/04/2026, 00:45:24 UTC Added: 07/04/2026, 01:06:48 UTC |
An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue affects Access Manager before 5.1.3. Join the discussion | CVE Database V5 | 06/24/2026, 14:01:38 UTC Added: 06/24/2026, 14:39:57 UTC |
0 CVE-2026-9560 is a critical privilege escalation vulnerability in OpenVPN Connect versions 3.5.1 through 3.8.1 on macOS. It allows an attacker with local access to execute arbitrary commands with elevated privileges via a local inter-process communication (IPC) channel in the background service. The vulnerability is related to improper handling of IPC leading to command injection. No official patch or remediation guidance has been provided yet, and no known exploits are reported in the wild. Join the discussion | CVE Database V5 | 05/26/2026, 17:39:57 UTC Added: 05/26/2026, 18:02:39 UTC |
CVE-2026-41225 is a high-severity vulnerability in F5 BIG-IP's iControl REST interface. It allows a highly privileged, authenticated attacker with at least Manager role permissions to create configuration objects that enable execution of arbitrary commands. This vulnerability affects specific versions of BIG-IP including 21.0.0, 17.5.0, 17.1.0, and 16.1. Join the discussion | CVE Database V5 | 05/13/2026, 14:12:37 UTC Added: 05/13/2026, 15:21:53 UTC |
0 CVE-2026-22922 is an authorization vulnerability in Apache Airflow versions 3.1.0 through 3.1.6 that allows authenticated users with limited custom permissions to access task logs without proper authorization. This flaw arises from incorrect use of privileged APIs, classified under CWE-648. The vulnerability has a CVSS score of 6.5, indicating medium severity, with high impact on confidentiality but no impact on integrity or availability. Exploitation requires authentication but no user interaction, and the flaw is resolved in Apache Airflow 3.1. Join the discussion | CVE Database V5 | 02/09/2026, 10:33:49 UTC Added: 02/09/2026, 11:01:15 UTC |
Incorrect Use of Privileged APIs vulnerability in NomySoft Information Technology Training and Consulting Inc. Nomysem allows Privilege Escalation. This issue affects Nomysem: through May 2025. Join the discussion | CVE Database V5 | 12/10/2025, 09:03:16 UTC Added: 12/10/2025, 09:27:44 UTC |
0 A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to a local privilege escalation due to an exposed debug interface on the localhost. This allows any local user to gain code execution as administrative application user. Join the discussion | CVE Database V5 | 11/11/2025, 20:20:13 UTC Added: 11/11/2025, 20:46:03 UTC |
An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve remote code execution (RCE) by an attacker. Join the discussion | CVE Database V5 | 07/28/2025, 23:34:38 UTC Added: 07/28/2025, 23:47:39 UTC |
An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint can be used to download logs from the appliance configuration, exposing sensitive information. Join the discussion | CVE Database V5 | 07/28/2025, 23:31:09 UTC Added: 07/28/2025, 23:47:39 UTC |
An authenticated, read-only user can kill any processes running on the Xormon Original virtual appliance as the lpar2rrd user. Join the discussion | CVE Database V5 | 07/28/2025, 23:28:27 UTC Added: 07/28/2025, 23:47:39 UTC |
Showing 1 to 10 of 15 results