← Back
CWE-269

3,315 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (3,315)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Anydesk
1Anydesk
Jun 17, 2026
Oct 14, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain administrator privileges by using the Open Chat Log feature to launch a privileged Notepad process that can launch other applications.
1Microsoft
1Exchange Server
Jun 17, 2026
Oct 13, 2021
N/A· v4
8.0 HIGH· v3
5.2 MEDIUM· v2
Microsoft Exchange Server Elevation of Privilege Vulnerability
1Microsoft
5Windows 10
Windows 11Windows Server 2016+2 more
Jun 17, 2026
Oct 13, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows AppX Deployment Service Elevation of Privilege Vulnerability
1Microsoft
8Windows 10
Windows 11Windows 8.1+5 more
Jun 17, 2026
Oct 13, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Storage Spaces Controller Elevation of Privilege Vulnerability
1Microsoft
4Windows 10
Windows 11Windows Server 2016+1 more
Jun 17, 2026
Oct 13, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Microsoft DWM Core Library Elevation of Privilege Vulnerability
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Oct 13, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Windows Kernel Elevation of Privilege Vulnerability
1Microsoft
4Windows 10
Windows 11Windows Server 2016+1 more
Jun 17, 2026
Oct 13, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Desktop Bridge Elevation of Privilege Vulnerability
1Microsoft
10Windows 10
Windows 11Windows 7+7 more
Jun 17, 2026
Oct 13, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Storage Spaces Controller Elevation of Privilege Vulnerability
1Microsoft
8Windows 10
Windows 11Windows 8.1+5 more
Jun 17, 2026
Oct 13, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Storage Spaces Controller Elevation of Privilege Vulnerability
1Microsoft
8Windows 10
Windows 11Windows 8.1+5 more
Jun 17, 2026
Oct 13, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Storage Spaces Controller Elevation of Privilege Vulnerability
1Microsoft
8Windows 10
Windows 11Windows 8.1+5 more
Jun 17, 2026
Oct 13, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Event Tracing Elevation of Privilege Vulnerability
1Microsoft
5Windows 10
Windows 11Windows Server 2016+2 more
Jun 17, 2026
Oct 13, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
DirectX Graphics Kernel Elevation of Privilege Vulnerability
1Microsoft
10Windows 10
Windows 11Windows 7+7 more
Jun 17, 2026
Oct 13, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Common Log File System Driver Elevation of Privilege Vulnerability
1Microsoft
10Windows 10
Windows 11Windows 7+7 more
Jun 17, 2026
Oct 13, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Common Log File System Driver Elevation of Privilege Vulnerability
1Microsoft
6Windows 10
Windows 11Windows Server+3 more
Jun 17, 2026
Oct 13, 2021
N/A· v4
8.0 HIGH· v3
5.2 MEDIUM· v2
Windows Nearby Sharing Elevation of Privilege Vulnerability
1Microsoft
10Windows 10
Windows 11Windows 7+7 more
Jun 17, 2026
Oct 13, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows Common Log File System Driver Elevation of Privilege Vulnerability
1Microsoft
9Windows 10
Windows 11Windows 8.1+6 more
Jun 17, 2026
Oct 13, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Storage Spaces Controller Elevation of Privilege Vulnerability
1Gitlab
1Gitlab
Jun 17, 2026
Oct 11, 2021
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external'...Show more
An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.Show less
1Johnsoncontrols
1Exacqvision Web Service
Jun 17, 2026
Oct 11, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server.
1Hashicorp
1Vault
Jun 17, 2026
Oct 11, 2021
N/A· v4
8.1 HIGH· v3
4.9 MEDIUM· v2
HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than inte...Show more
HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the /gcp/roleset/* path may be able to issue Google Cloud service account credentials.Show less