CWE-264: CWE-264

52
Total CVEs
3
Critical
17
High
6.5
Avg CVSS

Yearly Trend

2026
6
2025
22
2024
12
2023
6
2022
4

Top Affected Vendors

1 Huawei 33
2 Qualcomm 3
3 Oxilab 3
4 Fortinet 1
5 Dell 1
6 Ibm 1
7 Apache 1
8 Elastic 1
9 Cisco 1
10 Stylemixthemes 1

All CWE-264 CVEs (52)

CVE-2022-36246
9.8

Shop Beat Media Player versions 2.5.95 through 3.2.57 have insecure permissions that allow unauthorized access to sensitive functionality or data. Thi...

May 30, 2023
CVE-2022-33198
9.8

This vulnerability allows unauthenticated attackers to modify WordPress options through the Accordions plugin. Any WordPress site running the affected...

Jul 21, 2022
CVE-2021-36879
9.8

This vulnerability allows unauthenticated attackers to escalate privileges in WordPress sites using the uListing plugin (versions 2.0.5 and earlier). ...

Sep 27, 2021
CVE-2021-27644
8.8

CVE-2021-27644 is a SQL injection vulnerability in Apache DolphinScheduler's data source center that allows authorized users to execute arbitrary SQL ...

Nov 1, 2021
CVE-2025-58302
8.4

A permission control vulnerability in Huawei's Settings module allows unauthorized access to sensitive system settings. This affects Huawei devices ru...

Nov 28, 2025
CVE-2025-48903
7.8

A permission bypass vulnerability in the media library module allows unauthorized access to restricted media resources. This affects systems running t...

Jun 6, 2025
CVE-2022-23714
7.8

This CVE describes a local privilege escalation vulnerability in Elastic Endpoint Security for Windows. Unprivileged users can exploit this flaw to ga...

Jul 6, 2022
CVE-2024-56444
7.5

This CVE describes a cross-process screen stack vulnerability in Huawei's UIExtension module that could allow unauthorized access to screen content ac...

Jan 8, 2025
CVE-2024-43064
7.5

This CVE describes a denial-of-service vulnerability in Qualcomm System Memory Management Unit (SMMU) where uncontrolled resource consumption occurs w...

Jan 6, 2025
CVE-2020-25720
7.5

This Samba vulnerability allows delegated administrators with object creation permissions in Active Directory to modify security-sensitive attributes ...

Nov 17, 2024
CVE-2023-39394
7.5

This vulnerability allows API privilege escalation in Huawei/HarmonyOS wifienhance modules, enabling attackers to modify ARP tables without proper aut...

Aug 13, 2023
CVE-2023-39384
7.5

CVE-2023-39384 is an incomplete permission verification vulnerability in Huawei/HarmonyOS input method modules that could allow unauthorized access to...

Aug 13, 2023
CVE-2023-39380
7.5

This CVE describes a permission control vulnerability in Huawei audio modules that allows unauthorized access to audio device functions. Successful ex...

Aug 13, 2023
CVE-2022-48508
7.5

This CVE describes an inappropriate authorization vulnerability in Huawei HarmonyOS system apps that could allow unauthorized access to system functio...

Jul 6, 2023
CVE-2023-22633
7.5

This vulnerability allows unauthenticated attackers to perform denial-of-service (DoS) attacks on FortiNAC devices by exploiting improper access contr...

Jun 13, 2023
CVE-2023-42005
7.4

This vulnerability allows users with access to IBM Db2 Kubernetes pods to make unauthorized system calls, potentially compromising container security....

May 29, 2024
CVE-2024-21469
7.3

This vulnerability involves memory corruption when an invoke call and a TEE (Trusted Execution Environment) call target the same trusted application s...

Jul 1, 2024
CVE-2024-22452
7.3

Dell Display and Peripheral Manager for macOS contains an improper access control vulnerability that allows low-privileged users to modify files in th...

Mar 4, 2024
CVE-2022-33970
7.2

This vulnerability allows authenticated WordPress users to modify WordPress options, potentially leading to privilege escalation or site takeover. It ...

Jul 27, 2022
CVE-2022-33969
7.2

This vulnerability allows authenticated WordPress users to modify WordPress options through the Flipbox plugin. Attackers with contributor-level acces...

Jul 25, 2022
CVE-2025-58309
6.8

A permission control vulnerability in the startup recovery module allows attackers to bypass intended access restrictions. This affects availability a...

Nov 28, 2025
CVE-2017-9711
6.7

CVE-2017-9711 is a privilege escalation vulnerability in Qualcomm components where unprivileged processes can perform IOCTL calls that should be restr...

Nov 22, 2024
CVE-2026-24923
6.3

This CVE describes a permission control vulnerability in Huawei's HDC module that could allow unauthorized access to sensitive service data. The vulne...

Feb 6, 2026
CVE-2025-5321
6.3

This critical vulnerability in aimhubio aim allows remote attackers to execute arbitrary code through improper input validation in the RestrictedPytho...

May 29, 2025
CVE-2026-24920
6.2

A permission control vulnerability in the AMS module could allow attackers to disrupt system availability. This affects Huawei devices running vulnera...

Feb 6, 2026
CVE-2025-66325
6.2

A permission control vulnerability in Huawei's package management module could allow unauthorized access to sensitive information. This affects Huawei...

Dec 8, 2025
CVE-2025-58294
6.2

A permission control vulnerability in the print module allows unauthorized access to sensitive information. This affects systems running vulnerable Hu...

Nov 28, 2025
CVE-2025-54654
6.2

A permission control vulnerability in Huawei Gallery module allows unauthorized access to protected content. This affects Huawei smartphone users who ...

Oct 11, 2025
CVE-2025-46587
6.2

A permission control vulnerability in Huawei's media library module allows unauthorized access to protected media files. This affects Huawei devices a...

May 6, 2025
CVE-2024-56440
6.2

A permission control vulnerability in Huawei's Connectivity module allows unauthorized access to restricted functionality. This affects Huawei devices...

Jan 8, 2025
CVE-2024-32996
6.2

This CVE-2024-32996 is a privilege escalation vulnerability in Huawei/HarmonyOS account modules that allows attackers to gain elevated privileges. Suc...

May 14, 2024
CVE-2023-52721
6.2

This vulnerability in the WindowManager module allows unauthorized access to sensitive information due to improper permission control. It affects Huaw...

May 14, 2024
CVE-2026-24924
6.1

This vulnerability involves improper permission control in the print module, allowing unauthorized access to sensitive information. It affects systems...

Feb 6, 2026
CVE-2024-54103
6.1

This vulnerability allows unauthorized access to album content due to improper access control in Huawei devices. It affects users of specific Huawei s...

Dec 12, 2024
CVE-2024-20370
6.0

This vulnerability allows authenticated local attackers with administrative credentials on Cisco ASA/FTD devices to escalate privileges to root by exp...

Oct 23, 2024
CVE-2026-24931
5.9

This vulnerability involves an improper security check in the card module, potentially allowing unauthorized access to sensitive information. It affec...

Feb 6, 2026
CVE-2025-58284
5.9

A permission control vulnerability in Huawei network modules allows unauthorized access to sensitive information. This affects Huawei devices and serv...

Oct 11, 2025
CVE-2025-53186
5.9

This vulnerability allows third-party calling applications to send unverified broadcasts to the audio framework module on affected Huawei devices. Thi...

Jul 7, 2025
CVE-2025-20145
5.8

This vulnerability allows unauthenticated remote attackers to bypass egress ACLs on Cisco IOS XR devices when traffic flows between different line car...

Mar 12, 2025
CVE-2025-68967
5.7

This vulnerability involves improper permission control in the print module, allowing unauthorized access to sensitive information. It affects Huawei ...

Jan 14, 2026
CVE-2025-58315
5.5

A permission control vulnerability in the Wi-Fi module could allow unauthorized access to sensitive service information. This affects Huawei devices w...

Nov 28, 2025
CVE-2025-58293
5.5

This vulnerability involves improper exception handling in the print module of Huawei products, which could allow attackers to cause denial of service...

Oct 11, 2025
CVE-2025-58283
5.5

A permission control vulnerability in Huawei Wi-Fi modules could allow unauthorized access to sensitive information. This affects Huawei consumer devi...

Oct 11, 2025
CVE-2025-58285
5.3

This CVE describes a permission control vulnerability in Huawei's media module that could allow unauthorized access to sensitive media content. Succes...

Oct 11, 2025
CVE-2024-20371
5.3

A vulnerability in Cisco Nexus 3550-F Switches allows unauthenticated remote attackers to bypass ACL deny rules during device reboot, sending traffic ...

Nov 6, 2024
CVE-2025-58312
5.1

A permission control vulnerability in Huawei's App Lock module could allow attackers to bypass application locking mechanisms. This affects availabili...

Nov 28, 2025
CVE-2024-45442
5.1

This vulnerability allows attackers to bypass permission verification in Huawei's DownloadProviderMain module APIs, potentially disrupting download se...

Sep 4, 2024
CVE-2025-53178
4.8

A permission bypass vulnerability in the calendar storage module allows unauthorized access to calendar data. This affects Huawei head units where att...

Jul 7, 2025
CVE-2025-64315
4.4

A configuration defect in the file management module could allow unauthorized access to application data. This vulnerability affects Huawei laptop use...

Nov 28, 2025
CVE-2026-28541
4.0

A permission control vulnerability in the cellular_data module could allow unauthorized access to cellular data functionality. This affects Huawei con...

Mar 5, 2026

About CWE-264 (CWE-264)

Our database tracks 52 CVEs classified as CWE-264, with 3 rated critical and 17 rated high severity. The average CVSS score for CWE-264 vulnerabilities is 6.5.

External reference: View CWE-264 on MITRE CWE →

Monitor CWE-264 Vulnerabilities

Get alerted when new CWE-264 CVEs affect your infrastructure.

Start Monitoring Free