CWE-269
3,315 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CVEs (3,315)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. When the attacker has access to a valid (but unprivileged) account, t...Show more |
The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality. |
The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality. |
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30430, Acronis Cyber Protect 15 (Windows) before build 30984. |
Data leakage in Adobe connector in Snow Software SPE 9.27.0 on Windows allows privileged user to observe other users data. |
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via a crafted payload. |
Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases. This issue may allow users to access content that they are no longer privileged to access. |
Insecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges via the cover_id parameter. |
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook may lead to the misconfiguration of the Webhook. This component enfor...Show more |
Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber...Show more |
1Lenovo 109Thinkagile Hx1021 Firmware Thinkagile Hx1320 FirmwareThinkagile Hx1321 Firmware+106 moreJun 17, 2026 Apr 28, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have t...Show more |
1Illumina 11Iscan Firmware Iseq 100 FirmwareMiniseq Firmware+8 moreJun 17, 2026 Apr 28, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability. An unauthenticated malicious actor could upload and execute code remotely at the operating system level, whi...Show more |
The MagicJack device, a VoIP solution for internet phone calls, contains a hidden NAND flash memory partition allowing unauthorized read/write access. Attackers can exploit this by replacing the original software with a...Show more |
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
1Hyundai 2Gen5w L Firmware Gen5w L In Vehicle Infotainment System FirmwareJun 17, 2026 Apr 27, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, which is used during the firmware installation process, can be modified by an att...Show more |
1Hyundai 2Gen5w L Firmware Gen5w L In Vehicle Infotainment System FirmwareJun 17, 2026 Apr 27, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, which is used during the firmware installation process, can be modified by an att...Show more |
1Hyundai 2Gen5w L Firmware Gen5w L In Vehicle Infotainment System FirmwareJun 17, 2026 Apr 27, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppDMClient binary file, which is used during the firmware installation process, can be modified by an at...Show more |
1Hyundai 2Gen5w L Firmware Gen5w L In Vehicle Infotainment System FirmwareJun 17, 2026 Apr 27, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decryption binary used to decrypt firmware files has an information leak that allows an attacker to read...Show more |
Clusternet is a general-purpose system for controlling Kubernetes clusters across different environments. An issue in clusternet prior to version 0.15.2 can be leveraged to lead to a cluster-level privilege escalation. T...Show more |