
CVE-2025-26655 – Missing Authorization check in SAP JIT(Outbound)
https://notcve.org/view.php?id=CVE-2025-26655
11 Mar 2025 — SAP Just In Time(JIT) does not perform necessary authorization checks for an authenticated user, allowing attacker to escalate privileges that would otherwise be restricted, potentially causing a low impact on the integrity of the application.Confidentiality and Availability are not impacted. • https://me.sap.com/notes/3347991 • CWE-862: Missing Authorization •

CVE-2024-56192
https://notcve.org/view.php?id=CVE-2024-56192
10 Mar 2025 — This could lead to local escalation of privilege with no additional execution privileges needed. • https://source.android.com/docs/security/bulletin/pixel-watch/2025/2025-03-01 • CWE-281: Improper Preservation of Permissions •

CVE-2024-56191
https://notcve.org/view.php?id=CVE-2024-56191
10 Mar 2025 — This could lead to local escalation of privilege with no additional execution privileges needed. • https://source.android.com/docs/security/bulletin/pixel-watch/2025/2025-03-01 • CWE-281: Improper Preservation of Permissions •

CVE-2025-27255
https://notcve.org/view.php?id=CVE-2025-27255
10 Mar 2025 — Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encrypted using an hardcoded password retrievable by an attacker analyzing the application code. • https://www.gevernova.com/grid-solutions/app/DownloadFile.aspx?prod=urfamily&type=21&file=76 • CWE-798: Use of Hard-coded Credentials •

CVE-2025-25871 – OpenPanel 0.3.4 Directory Traversal / Arbitrary File Read
https://notcve.org/view.php?id=CVE-2025-25871
07 Mar 2025 — An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function OpenPanel version 0.3.4 suffers from a directory traversal vulnerability in the fix permission functionality. • https://packetstorm.news/files/id/189621 • CWE-281: Improper Preservation of Permissions •

CVE-2025-25451
https://notcve.org/view.php?id=CVE-2025-25451
06 Mar 2025 — An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a physically proximate attacker to escalate privileges via the "2fa_authorized" Local Storage key Un problema en TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 y anteriores permite que un atacante físicamente próximo escale privilegios a través de la clave de almacenamiento local "2fa_authorized" • https://piuswalter.de/blog/2fa-bypass-and-deactivation-attack-in-mytaag • CWE-287: Improper Authentication •

CVE-2025-25452
https://notcve.org/view.php?id=CVE-2025-25452
06 Mar 2025 — An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to escalate privileges via the "/user" endpoint Un problema en TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 y anteriores permite que un atacante remoto escale privilegios a través del endpoint "/user" • https://piuswalter.de/blog/2fa-bypass-and-deactivation-attack-in-mytaag • CWE-287: Improper Authentication •

CVE-2025-25450
https://notcve.org/view.php?id=CVE-2025-25450
06 Mar 2025 — An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to escalate privileges via the deactivation of the activated second factor to the /session endpoint Un problema en TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 y anteriores permite que un atacante remoto escale privilegios a través de la desactivación del segundo factor activado al punto final /session • https://piuswalter.de/blog/2fa-bypass-and-deactivation-attack-in-mytaag • CWE-287: Improper Authentication •

CVE-2025-25873 – OpenAdmin 0.3.4 Cross Site Request Forgery
https://notcve.org/view.php?id=CVE-2025-25873
06 Mar 2025 — Cross Site Request Forgery vulnerability in Open Panel OpenAdmin v.0.3.4 allows a remote attacker to escalate privileges via the Change Root Password function Cross site request forgery in the Users and Change Root Password functions in OpenAdmin version 0.3.4 allows remote attackers to perform attacks enabling unauthorized actions that could lead to privilege escalation. • https://packetstorm.news/files/id/189597 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2025-27644
https://notcve.org/view.php?id=CVE-2025-27644
05 Mar 2025 — Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Local Privilege Escalation V-2024-007. • https://help.printerlogic.com/saas/Print/Security/Security-Bulletins.htm • CWE-269: Improper Privilege Management •