CWE-250: CWE-250

147
Total CVEs
18
Critical
96
High
7.7
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
16
2025
69
2024
35
2023
13
2022
6

Top Affected Vendors

1 Ibm 22
2 Dell 9
3 Siemens 5
4 Cisco 5
5 F5 4
6 Google 3
7 Broadcom 3
8 Zimaspace 2
9 Papercut 2
10 Gitlab 2

All CWE-250 CVEs (147)

CVE-2022-21699
8.2

CVE-2022-21699 is an arbitrary code execution vulnerability in IPython where improper management of cross-user temporary files allows one user to exec...

Jan 19, 2022
CVE-2021-1579
8.1

This vulnerability allows authenticated remote attackers with Administrator read-only credentials to elevate privileges to Administrator with write pr...

Aug 25, 2021
CVE-2025-23180
8.0

CVE-2025-23180 is a privilege escalation vulnerability where software runs with higher privileges than necessary, allowing attackers to gain elevated ...

Apr 29, 2025
CVE-2023-1943
8.0

This vulnerability allows attackers to escalate privileges in kOps clusters using the GCE/GCP provider in gossip mode. Attackers can gain cluster-admi...

Oct 12, 2023
CVE-2021-25653
8.0

This CVE describes a local privilege escalation vulnerability in Avaya Aura Appliance Virtualization Platform Utilities (AVPU) that allows authenticat...

Jun 24, 2021
CVE-2026-0870
7.8

GIGABYTE MacroHub has a local privilege escalation vulnerability where authenticated local attackers can execute arbitrary code with SYSTEM privileges...

Feb 9, 2026
CVE-2026-1680
7.8

This vulnerability allows any local Windows user to escalate their privileges to local administrator by directly communicating with the LocalAdminServ...

Jan 30, 2026
CVE-2025-48573
7.8

This vulnerability allows malicious Android apps to launch foreground services while running in the background, bypassing Android's Foreground Service...

Dec 8, 2025
CVE-2025-10885
7.8

This vulnerability allows local attackers with low privileges to escalate to SYSTEM-level privileges by exploiting insufficient binary validation. It ...

Nov 6, 2025
CVE-2025-33003
7.8

This vulnerability in IBM InfoSphere Information Server allows non-root users within a container environment to escalate their privileges to root-leve...

Oct 31, 2025
CVE-2021-47700
7.8

Nagios XI versions before 5.8.7 use insecure permissions on a temporary directory for Highcharts exports, allowing local or co-hosted processes to rea...

Oct 30, 2025
CVE-2025-8486
7.8

This vulnerability in PC Manager allows a local authenticated user to execute arbitrary code with elevated privileges, potentially gaining full system...

Oct 15, 2025
CVE-2025-50505
7.8

This vulnerability allows local users to execute arbitrary commands with elevated privileges by exploiting an unauthorized HTTP API endpoint in Clash ...

Oct 7, 2025
CVE-2025-58432
7.8

This vulnerability allows any user with localhost access to upload files as root on ZimaOS systems. It affects all versions up to 1.4.1, enabling priv...

Sep 17, 2025
CVE-2022-38695
7.8

This vulnerability in BootRom allows local attackers to escalate privileges without needing additional execution permissions. It affects devices with ...

Sep 1, 2025
CVE-2025-0080
7.8

This CVE describes a tapjacking/overlay vulnerability in Android that allows malicious apps to overlay installation confirmation dialogs. This enables...

Aug 26, 2025
CVE-2025-33120
7.8

CVE-2025-33120 is a privilege escalation vulnerability in IBM QRadar SIEM where authenticated users can gain elevated privileges through a misconfigur...

Aug 22, 2025
CVE-2025-40767
7.8

SINEC Traffic Analyzer runs Docker containers without proper isolation controls, allowing attackers to escape container boundaries and access host sys...

Aug 12, 2025
CVE-2025-1411
7.8

This vulnerability in IBM Security Verify Directory Container allows local users to execute arbitrary commands with root privileges due to unnecessary...

Jun 15, 2025
CVE-2025-3925
7.8

This CVE describes a privilege escalation vulnerability in BrightSign digital signage players. Once an attacker gains initial code execution on the de...

May 7, 2025
CVE-2024-12673
7.8

A local privilege escalation vulnerability in Lenovo Vantage's BIOS customization feature allows attackers with local access to gain elevated system p...

Feb 12, 2025
CVE-2024-47978
7.8

Dell NativeEdge version 2.1.0.0 contains an execution with unnecessary privileges vulnerability (CWE-250). A low-privileged attacker with local access...

Dec 25, 2024
CVE-2024-35141
7.8

This vulnerability in IBM Security Verify Access Docker allows local users to escalate privileges due to unnecessary privilege execution. It affects I...

Dec 19, 2024
CVE-2024-31891
7.8

This CVE describes a local privilege escalation vulnerability in IBM Storage Scale GUI where an authenticated attacker with command line access to the...

Dec 14, 2024
CVE-2020-26074
7.8

This vulnerability in Cisco SD-WAN vManage software allows authenticated local attackers to gain escalated privileges by exploiting improper path vali...

Nov 18, 2024
CVE-2024-48837
7.8

Dell SmartFabric OS10 Software contains a privilege escalation vulnerability where low-privileged local attackers can execute commands with elevated p...

Nov 12, 2024
CVE-2024-5622
7.8

An untrusted search path vulnerability in B&R APROL's AprolConfigureCCServices allows authenticated local attackers to execute arbitrary code with ele...

Aug 29, 2024
CVE-2024-36398
7.8

A local privilege escalation vulnerability in Siemens SINEC NMS allows attackers to execute operating system commands with SYSTEM privileges. This aff...

Aug 13, 2024
CVE-2023-30997
7.8

This vulnerability in IBM Security Access Manager Docker allows a local user to escalate privileges to root due to improper access controls. It affect...

Jun 27, 2024
CVE-2024-31890
7.8

This CVE describes a local privilege escalation vulnerability in IBM TCP/IP Connectivity Utilities for i on IBM i 7.3, 7.4, and 7.5. An attacker with ...

Jun 21, 2024
CVE-2023-38042
7.8

This CVE describes a local privilege escalation vulnerability in Ivanti Secure Access Client for Windows. It allows authenticated low-privileged users...

May 31, 2024
CVE-2024-34477
7.8

CVE-2024-34477 is a local privilege escalation vulnerability in FOG Project's configureNFS function that allows authenticated local users to gain root...

May 27, 2024
CVE-2024-24245
7.8

A local privilege escalation vulnerability in ClamXAV's helper tool component allows attackers with local access to gain elevated privileges. This aff...

Apr 9, 2024
CVE-2023-6006
7.8

This CVE allows local attackers with write access to the C drive to escalate privileges to SYSTEM level by exploiting an insecure executable loading m...

Nov 14, 2023
CVE-2023-38641
7.8

A local privilege escalation vulnerability in SICAM TOOLBOX II allows attackers to execute operating system commands with SYSTEM privileges. This affe...

Aug 8, 2023
CVE-2023-0664
7.8

This vulnerability allows a local unprivileged user on Windows systems running QEMU Guest Agent to manipulate the installer's repair custom actions, l...

Mar 29, 2023
CVE-2022-34384
7.8

This CVE describes a local privilege escalation vulnerability in Dell's Advanced Driver Restore component. A local malicious user can exploit this to ...

Feb 11, 2023
CVE-2021-34591
7.8

This vulnerability allows authenticated attackers to escalate privileges to root on Bender/ebee Charge Controllers by exploiting SUID permissions on s...

Apr 27, 2022
CVE-2022-24113
7.8

This CVE describes a local privilege escalation vulnerability in Acronis Windows products where child processes receive excessive permissions. An atta...

Feb 4, 2022
CVE-2021-1118
7.8

This vulnerability in NVIDIA vGPU software allows guest operating systems to execute privileged operations on the host system. It affects organization...

Oct 29, 2021
CVE-2021-1528
7.8

This vulnerability in Cisco SD-WAN Software allows authenticated local attackers to escalate privileges to root by exploiting improper access restrict...

Jun 4, 2021
CVE-2021-27454
7.8

CVE-2021-27454 is a privilege escalation vulnerability in Reason DR60 industrial routers where the software runs with higher privileges than necessary...

Mar 25, 2021
CVE-2021-25650
7.7

A local privilege escalation vulnerability in Avaya Aura Utility Services allows authenticated local users to execute arbitrary scripts with elevated ...

Jun 24, 2021
CVE-2023-4003
7.6

This vulnerability allows an unauthenticated attacker with physical access to a workstation running One Identity Password Manager 5.9.7.1 to escalate ...

Sep 27, 2023
CVE-2025-33109
7.5

IBM i operating systems versions 7.2 through 7.6 contain a database authority check vulnerability that allows unauthorized execution of database proce...

Jul 24, 2025
CVE-2025-1137
7.5

IBM Storage Scale versions 5.2.2.0 and 5.2.2.1 contain an input validation vulnerability that allows authenticated users to execute privileged command...

May 10, 2025
CVE-2025-36186
7.4

IBM Db2 12.1.0 through 12.1.3 on Linux, UNIX, and Windows (including Db2 Connect Server) contains a local privilege escalation vulnerability. Under sp...

Nov 7, 2025
CVE-2025-55077
7.4

This vulnerability in Tyler Technologies ERP Pro 9 SaaS allows authenticated users to escape the application sandbox and execute limited operating sys...

Aug 7, 2025
CVE-2024-27147
7.4

CVE-2024-27147 is a local privilege escalation vulnerability in Toshiba printers that allows attackers to gain elevated privileges on affected devices...

Jun 14, 2024
CVE-2025-43990
7.3

Dell Command Monitor versions before 10.12.3.28 contain a privilege escalation vulnerability where local low-privileged users can execute code with un...

Nov 5, 2025

About CWE-250 (CWE-250)

Our database tracks 147 CVEs classified as CWE-250, with 18 rated critical and 96 rated high severity. The average CVSS score for CWE-250 vulnerabilities is 7.7.

External reference: View CWE-250 on MITRE CWE →

Monitor CWE-250 Vulnerabilities

Get alerted when new CWE-250 CVEs affect your infrastructure.

Start Monitoring Free