VulnSea

CWE-1220

CVEs classified under CWE-1220, newest first.

38 CVEsRSS

CVE-2026-33825High· 7.8CISA KEVPoC
5mo ago

Microsoft Defender Elevation of Privilege Vulnerability

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

▾ AbyssalMicrosoft · Microsoft Defender Antimalware PlatformEPSS 0.40%via CVEORG
CVE-2026-39363High· 7.5PoC
5mo ago

Vite is a frontend tooling framework for JavaScript

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custo…

▾ Midnightvitejs · viteEPSS 2.6%via NVD
CVE-2025-20628None
5mo ago

An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) where administrators cannot properly configure access rules for Remote Connector Servers (RCS) running in client mode.…

An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) where administrators cannot properly configure access rules for Remote Connector Servers (RCS) running in client mode.…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-23466High· 7.8⚖ disputed
5mo ago

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Open-code GGTT MMIO access protection GGTT MMIO access is currently protected by hotplug (drm_dev_enter), which works correctly when the driver loads successfu…

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Open-code GGTT MMIO access protection GGTT MMIO access is currently protected by hotplug (drm_dev_enter), which works correctly when the driver loads successfu…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2025-69196Medium· 6.5
6mo ago

FastMCP is the standard framework for building MCP applications

FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the …

▾ Sunlitjlowin · fastmcpEPSS 0.36%via NVD
CVE-2025-35998High· 7.9
7mo ago

Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow an escalation of privilege

Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow an escalation of privilege. System software adversary with a privileged use…

▾ TwilightEPSS 0.16%via NVD
CVE-2025-4404Critical· 9.1PoC
1y ago

A privilege escalation from host to domain vulnerability was found in the FreeIPA project

A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services…

▾ AbyssalEPSS 2.0%via NVD
CVE-2024-13272Medium· 6.3
1y ago

Insufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows Content Spoofing.This issue affects Paragraphs table: from 0.0.0 before 1.23.0, from 2.0.0 before 2.0.2.

Insufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows Content Spoofing.This issue affects Paragraphs table: from 0.0.0 before 1.23.0, from 2.0.0 before 2.0.2.

▾ Sunlitparagraphs_table_project · paragraphs_tableEPSS 0.24%via NVD
CWE-1220 vulnerabilities (CVEs) — page 2 · VulnSea