CWE-1220: CWE-1220
Yearly Trend
Top Affected Vendors
All CWE-1220 CVEs (27)
This CVE describes an access control vulnerability in OpenText Flipper where low-privilege users can interact with backend APIs without proper authori...
Oct 20, 2025This CVE-2025-7493 is a privilege escalation vulnerability in FreeIPA where an attacker can gain domain administrator privileges by exploiting insuffi...
Sep 30, 2025This CVE describes a privilege escalation vulnerability in FreeIPA where attackers can create services with the same canonical name as the realm admin...
Jun 17, 2025CVE-2025-8049 is an access control vulnerability in OpenText Flipper that allows low-privilege users to escalate their privileges within the applicati...
Oct 20, 2025This vulnerability allows a local malicious user with low privileges on Dell PowerProtect DD systems to escalate their privileges through improper acc...
Feb 1, 2025This vulnerability allows a local malicious user with low privileges on Dell PowerProtect DD systems to escalate their privileges, potentially gaining...
Dec 14, 2023This vulnerability allows a privileged attacker to execute arbitrary code at the System Management Mode (SMM) level by exploiting improper input valid...
Sep 6, 2025This vulnerability allows a privileged user on affected Intel Xeon 6 Scalable processors to potentially escalate privileges via adjacent access due to...
Aug 12, 2025This CVE describes a memory corruption vulnerability in Qualcomm's ADSP (Audio Digital Signal Processor) when handling memory allocation from the HLOS...
Apr 7, 2025This vulnerability allows a privileged attacker to bypass System Management Mode (SMM) protections by exploiting improper input validation in SMM hand...
Feb 11, 2025This vulnerability allows a privileged attacker to bypass System Management Mode (SMM) protections through improper input validation in the SMM handle...
Feb 11, 2025This vulnerability in Drupal's Email Contact module allows attackers to bypass access controls through forceful browsing, potentially accessing restri...
Jan 9, 2025An unauthenticated adjacent attacker can send crafted Ethernet frames to Cisco Nexus 3000/9000 Series Switches in standalone NX-OS mode, causing the d...
Feb 26, 2025This vulnerability allows authenticated users in lunary-ai/lunary to delete prompts belonging to other organizations through ID manipulation. The appl...
Feb 2, 2026This UEFI firmware vulnerability in certain Intel processors allows authenticated local users to potentially cause denial of service by exploiting ins...
Feb 12, 2025This vulnerability in IBM Spectrum Fusion HCI allows attackers to perform unauthorized actions in RGW (RADOS Gateway) for Ceph due to improper bucket ...
May 14, 2024This vulnerability allows users with developer role in GitLab to exfiltrate protected CI/CD variables via the CI lint feature. It affects GitLab Commu...
Jan 24, 2025This vulnerability in Drupal Paragraphs table module allows attackers to spoof content by manipulating table data due to insufficient access controls....
Jan 9, 2025This vulnerability in Outlook for Android allows attackers to elevate privileges within the app, potentially accessing sensitive data or performing un...
Oct 8, 2024This vulnerability allows authenticated local attackers with CLI access to cause Cisco APIC devices to unexpectedly reload by issuing crafted commands...
Feb 25, 2026This vulnerability allows authenticated GitLab users with specific permissions to remove all project runners from unrelated projects by manipulating G...
Jan 9, 2026ChatLuck's guest user invitation system has insufficient access control, allowing uninvited users to register as guests. This affects all ChatLuck dep...
Oct 16, 2025This vulnerability allows users to bypass IP-based access restrictions in GitLab, potentially exposing sensitive information they shouldn't have acces...
Apr 10, 2025This vulnerability allows authenticated internal users in GitLab to bypass access controls and view internal projects they shouldn't have permission t...
Mar 28, 2025This vulnerability in Cisco ISE allows authenticated read-only administrators to view sensitive passwords that should only be accessible to high-privi...
Nov 5, 2025This vulnerability allows privileged GitLab users to access resource_group information through the API that should have been restricted. It affects Gi...
Jul 24, 2025CVE-2025-8306 is an access control vulnerability in Asseco InfoMedica healthcare management software that allows low-privileged users to obtain encode...
Jan 8, 2026About CWE-1220 (CWE-1220)
Our database tracks 27 CVEs classified as CWE-1220, with 3 rated critical and 10 rated high severity. The average CVSS score for CWE-1220 vulnerabilities is 6.8.
External reference: View CWE-1220 on MITRE CWE →
Monitor CWE-1220 Vulnerabilities
Get alerted when new CWE-1220 CVEs affect your infrastructure.
Start Monitoring Free