← Back
CWE-269

3,313 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (3,313)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Jan 12, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Windows CSC Service Elevation of Privilege Vulnerability
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Jan 12, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Windows CSC Service Elevation of Privilege Vulnerability
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Jan 12, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Windows CSC Service Elevation of Privilege Vulnerability
1Microsoft
6Visual Studio
Visual Studio 2017Visual Studio 2019+3 more
Jun 17, 2026
Jan 12, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
1Microsoft
6Windows 10
Windows 8.1Windows Rt 8.1+3 more
Jun 17, 2026
Jan 12, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Windows Runtime C++ Template Library Elevation of Privilege Vulnerability
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Jan 12, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Active Template Library Elevation of Privilege Vulnerability
1Microsoft
5Windows 10
Windows 8.1Windows Server 2012+2 more
Jun 17, 2026
Jan 12, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Microsoft splwow64 Elevation of Privilege Vulnerability
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Jun 17, 2026
Jan 12, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Windows WLAN Service Elevation of Privilege Vulnerability
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Jun 17, 2026
Jan 12, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows AppX Deployment Extensions Elevation of Privilege Vulnerability
1Google
1Android
Jun 17, 2026
Jan 11, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Android versions which allows an app to gain the android.permission.ACTIVITY_RECOGNITION permission witho...Show more
In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Android versions which allows an app to gain the android.permission.ACTIVITY_RECOGNITION permission without user confirmation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11, Android-8.0, Android-8.1, Android-9, Android-10; Android ID: A-154505240.Show less
1K7computing
4Antivrius
Enterprise SecurityTotal Security+1 more
Jul 9, 2026
Jan 11, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
K7Computing Pvt Ltd K7AntiVirus Premium 15.1.0.53 is affected by: Buffer Overflow. The impact is: execute arbitrary code (local). The component is: K7TSMngr.exe.
1K7computing
4Antivrius
Enterprise SecurityTotal Security+1 more
Jul 9, 2026
Jan 11, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
K7Computing Pvt Ltd K7AntiVirus Premium 15.01.00.53 is affected by: Incorrect Access Control. The impact is: gain privileges (local).
1K7computing
4Antivrius
Enterprise SecurityTotal Security+1 more
Jul 9, 2026
Jan 11, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
K7Computing Pvt Ltd K7AntiVirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: gain privileges (local). The component is: K7TSMngr.exe.
1K7computing
4Antivrius
Enterprise SecurityTotal Security+1 more
Jul 9, 2026
Jan 11, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
K7Computing Pvt Ltd K7Antivirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: Local Process Execution (local). The component is: K7Sentry.sys.
1K7computing
4Antivrius
Enterprise SecurityTotal Security+1 more
Nov 21, 2024
Jan 11, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
1K7computing
4Antivrius
Enterprise SecurityTotal Security+1 more
Nov 21, 2024
Jan 11, 2021
N/A· v4
5.5 MEDIUM· v3
8.8 HIGH· v2
An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
1Nvidia
1Gpu Driver
Jun 17, 2026
Jan 8, 2021
N/A· v4
8.4 HIGH· v3
6.6 MEDIUM· v2
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which a local user can get elevated privileges to modify display configuration data, whi...Show more
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which a local user can get elevated privileges to modify display configuration data, which may result in denial of service of the display.Show less
1Citrix
1Secure Mail
Jun 17, 2026
Jan 6, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicious app would need to...Show more
Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device.Show less
1Dell
2Emc Isilon Onefs
Emc Powerscale Onefs
Jun 17, 2026
Jan 5, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Dell EMC Isilon OneFS versions 8.1 and later and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability on a SmartLock Compliance mode cluster. The compadmin user connecting using ISI PRIV L...Show more
Dell EMC Isilon OneFS versions 8.1 and later and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability on a SmartLock Compliance mode cluster. The compadmin user connecting using ISI PRIV LOGIN SSH or ISI PRIV LOGIN CONSOLE can elevate privileges to the root user if they have ISI PRIV HARDENING privileges.Show less
1Ultimatemember
1Ultimate Member
Jun 17, 2026
Jan 4, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update. Any user with wp-admin access to the profile.php page could supply the paramet...Show more
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update. Any user with wp-admin access to the profile.php page could supply the parameter um-role with a value set to any role (e.g., Administrator) during a profile update, and effectively escalate their privileges.Show less