CWE-269
3,313 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CVEs (3,313)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Jan 12, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Windows CSC Service Elevation of Privilege Vulnerability |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Jan 12, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Windows CSC Service Elevation of Privilege Vulnerability |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Jan 12, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Windows CSC Service Elevation of Privilege Vulnerability |
1Microsoft 6Visual Studio Visual Studio 2017Visual Studio 2019+3 moreJun 17, 2026 Jan 12, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability |
1Microsoft 6Windows 10 Windows 8.1Windows Rt 8.1+3 moreJun 17, 2026 Jan 12, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Windows Runtime C++ Template Library Elevation of Privilege Vulnerability |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Jan 12, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Active Template Library Elevation of Privilege Vulnerability |
1Microsoft 5Windows 10 Windows 8.1Windows Server 2012+2 moreJun 17, 2026 Jan 12, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Microsoft splwow64 Elevation of Privilege Vulnerability |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Jan 12, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Windows WLAN Service Elevation of Privilege Vulnerability |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Jan 12, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Windows AppX Deployment Extensions Elevation of Privilege Vulnerability |
In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Android versions which allows an app to gain the android.permission.ACTIVITY_RECOGNITION permission witho...Show more |
1K7computing 4Antivrius Enterprise SecurityTotal Security+1 moreJul 9, 2026 Jan 11, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 K7Computing Pvt Ltd K7AntiVirus Premium 15.1.0.53 is affected by: Buffer Overflow. The impact is: execute arbitrary code (local). The component is: K7TSMngr.exe. |
1K7computing 4Antivrius Enterprise SecurityTotal Security+1 moreJul 9, 2026 Jan 11, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 K7Computing Pvt Ltd K7AntiVirus Premium 15.01.00.53 is affected by: Incorrect Access Control. The impact is: gain privileges (local). |
1K7computing 4Antivrius Enterprise SecurityTotal Security+1 moreJul 9, 2026 Jan 11, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 K7Computing Pvt Ltd K7AntiVirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: gain privileges (local). The component is: K7TSMngr.exe. |
1K7computing 4Antivrius Enterprise SecurityTotal Security+1 moreJul 9, 2026 Jan 11, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 K7Computing Pvt Ltd K7Antivirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: Local Process Execution (local). The component is: K7Sentry.sys. |
1K7computing 4Antivrius Enterprise SecurityTotal Security+1 moreNov 21, 2024 Jan 11, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53. |
1K7computing 4Antivrius Enterprise SecurityTotal Security+1 moreNov 21, 2024 Jan 11, 2021 N/A· v4 5.5 MEDIUM· v3 8.8 HIGH· v2 An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53. |
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which a local user can get elevated privileges to modify display configuration data, whi...Show more |
Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicious app would need to...Show more |
1Dell 2Emc Isilon Onefs Emc Powerscale OnefsJun 17, 2026 Jan 5, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Dell EMC Isilon OneFS versions 8.1 and later and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability on a SmartLock Compliance mode cluster. The compadmin user connecting using ISI PRIV L...Show more |
1Ultimatemember 1Ultimate Member Jun 17, 2026 Jan 4, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update. Any user with wp-admin access to the profile.php page could supply the paramet...Show more |