CWE-1220: CWE-1220

27
Total CVEs
3
Critical
10
High
6.8
Avg CVSS

Yearly Trend

2026
4
2025
20
2024
2
2023
1

Top Affected Vendors

1 Gitlab 5
2 Dell 2
3 Opentext 2
4 Microsoft 1
5 Ibm 1
6 Qualcomm 1
7 Cisco 1
8 Lunary 1
9 Paragraphs Table Project 1
10 Email Contact Project 1

All CWE-1220 CVEs (27)

CVE-2025-8053
9.1

This CVE describes an access control vulnerability in OpenText Flipper where low-privilege users can interact with backend APIs without proper authori...

Oct 20, 2025
CVE-2025-7493
9.1

This CVE-2025-7493 is a privilege escalation vulnerability in FreeIPA where an attacker can gain domain administrator privileges by exploiting insuffi...

Sep 30, 2025
CVE-2025-4404
9.1

This CVE describes a privilege escalation vulnerability in FreeIPA where attackers can create services with the same canonical name as the realm admin...

Jun 17, 2025
CVE-2025-8049
8.8

CVE-2025-8049 is an access control vulnerability in OpenText Flipper that allows low-privilege users to escalate their privileges within the applicati...

Oct 20, 2025
CVE-2024-53295
7.8

This vulnerability allows a local malicious user with low privileges on Dell PowerProtect DD systems to escalate their privileges through improper acc...

Feb 1, 2025
CVE-2023-44285
7.8

This vulnerability allows a local malicious user with low privileges on Dell PowerProtect DD systems to escalate their privileges, potentially gaining...

Dec 14, 2023
CVE-2024-21947
7.5

This vulnerability allows a privileged attacker to execute arbitrary code at the System Management Mode (SMM) level by exploiting improper input valid...

Sep 6, 2025
CVE-2025-22839
7.5

This vulnerability allows a privileged user on affected Intel Xeon 6 Scalable processors to potentially escalate privileges via adjacent access due to...

Aug 12, 2025
CVE-2024-33058
7.5

This CVE describes a memory corruption vulnerability in Qualcomm's ADSP (Audio Digital Signal Processor) when handling memory allocation from the HLOS...

Apr 7, 2025
CVE-2023-31342
7.5

This vulnerability allows a privileged attacker to bypass System Management Mode (SMM) protections by exploiting improper input validation in SMM hand...

Feb 11, 2025
CVE-2023-31343
7.5

This vulnerability allows a privileged attacker to bypass System Management Mode (SMM) protections through improper input validation in the SMM handle...

Feb 11, 2025
CVE-2024-13256
7.5

This vulnerability in Drupal's Email Contact module allows attackers to bypass access controls through forceful browsing, potentially accessing restri...

Jan 9, 2025
CVE-2025-20111
7.4

An unauthenticated adjacent attacker can send crafted Ethernet frames to Cisco Nexus 3000/9000 Series Switches in standalone NX-OS mode, causing the d...

Feb 26, 2025
CVE-2024-4147
6.5

This vulnerability allows authenticated users in lunary-ai/lunary to delete prompts belonging to other organizations through ID manipulation. The appl...

Feb 2, 2026
CVE-2024-39279
6.5

This UEFI firmware vulnerability in certain Intel processors allows authenticated local users to potentially cause denial of service by exploiting ins...

Feb 12, 2025
CVE-2023-43040
6.5

This vulnerability in IBM Spectrum Fusion HCI allows attackers to perform unauthorized actions in RGW (RADOS Gateway) for Ceph due to improper bucket ...

May 14, 2024
CVE-2024-11931
6.4

This vulnerability allows users with developer role in GitLab to exfiltrate protected CI/CD variables via the CI lint feature. It affects GitLab Commu...

Jan 24, 2025
CVE-2024-13272
6.3

This vulnerability in Drupal Paragraphs table module allows attackers to spoof content by manipulating table data due to insufficient access controls....

Jan 9, 2025
CVE-2024-43604
5.7

This vulnerability in Outlook for Android allows attackers to elevate privileges within the app, potentially accessing sensitive data or performing un...

Oct 8, 2024
CVE-2026-20107
5.5

This vulnerability allows authenticated local attackers with CLI access to cause Cisco APIC devices to unexpectedly reload by issuing crafted commands...

Feb 25, 2026
CVE-2025-11246
5.4

This vulnerability allows authenticated GitLab users with specific permissions to remove all project runners from unrelated projects by manipulating G...

Jan 9, 2026
CVE-2025-54461
5.3

ChatLuck's guest user invitation system has insufficient access control, allowing uninvited users to register as guests. This affects all ChatLuck dep...

Oct 16, 2025
CVE-2025-2408
5.3

This vulnerability allows users to bypass IP-based access restrictions in GitLab, potentially exposing sensitive information they shouldn't have acces...

Apr 10, 2025
CVE-2024-12619
5.2

This vulnerability allows authenticated internal users in GitLab to bypass access controls and view internal projects they shouldn't have permission t...

Mar 28, 2025
CVE-2025-20305
4.3

This vulnerability in Cisco ISE allows authenticated read-only administrators to view sensitive passwords that should only be accessible to high-privi...

Nov 5, 2025
CVE-2025-7001
4.3

This vulnerability allows privileged GitLab users to access resource_group information through the API that should have been restricted. It affects Gi...

Jul 24, 2025
CVE-2025-8306
N/A

CVE-2025-8306 is an access control vulnerability in Asseco InfoMedica healthcare management software that allows low-privileged users to obtain encode...

Jan 8, 2026

About CWE-1220 (CWE-1220)

Our database tracks 27 CVEs classified as CWE-1220, with 3 rated critical and 10 rated high severity. The average CVSS score for CWE-1220 vulnerabilities is 6.8.

External reference: View CWE-1220 on MITRE CWE →

Monitor CWE-1220 Vulnerabilities

Get alerted when new CWE-1220 CVEs affect your infrastructure.

Start Monitoring Free