CWE-269
3,313 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CVEs (3,313)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Teltonika Networks 1Trb245 Firmware Jun 17, 2026 Aug 3, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Improper Access Control in Teltonika firmware TRB2_R_00.02.04.01 allows a low privileged user to perform unauthorized write operations. |
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to privlege escalation where the "My schedules and subscriptions" page is visible and accessible to a less privileged user. IBM X-Force ID: 167449. |
An issue was discovered in Pi-Hole through 5.0. The local www-data user has sudo privileges to execute the pihole core script as root without a password, which could allow an attacker to obtain root access via shell meta...Show more |
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 Jul 29, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A low-privilege user may use SQL syntax to write arbitrary files to the OpenClinic GA 5.09.02 and 5.89.05b server, which may allow the execution of arbitrary commands. |
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a lack of exploit mitigations vulnerability. Successful exploitation could lead to privilege escalation. |
1Ufactory 3Xarm 5 Lite Firmware Xarm 6 FirmwareXarm 7 FirmwareJun 17, 2026 Jul 15, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible files, encryption, or is...Show more |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Jul 14, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated att...Show more |
1Microsoft 5Azure Storage Explorer TypescriptVisual Studio 2017+2 moreJun 17, 2026 Jul 14, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability'. |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Jul 14, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'. |
1Siemens 1Opcenter Execution Core Jun 17, 2026 Jul 14, 2020 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2). Authenticated users could have access to resources they normally would not have. This vuln...Show more |
1Rittal 5Cmc Iii Pu 7030.000 Firmware Cmciii Pu 9333e0fb FirmwareIot Interface 3124.300+2 moreJun 17, 2026 Jul 14, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is a least privilege violation. |
1Checkpoint 1Zonealarm Extreme Security Jun 17, 2026 Jul 6, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute code at elevated privileges through a combination of file permission manipulation...Show more |
Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to create and edit files via symbolic link manipulation in a location they would otherwise not have access to. This i...Show more |
Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee de...Show more |
Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks. |
AsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering a triple fault via a request to zero CR3. |
GNS3 ubridge through 0.9.18 on macOS, as used in GNS3 server before 2.1.17, allows a local attacker to read arbitrary files because it handles configuration-file errors by printing the configuration file while executing...Show more |
1Mattermost 1Mattermost Server Nov 21, 2024 Jun 19, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpoints on a user's behalf. |
1Mattermost 1Mattermost Server Nov 21, 2024 Jun 19, 2020 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by using a registered OAuth application with personal access tokens. |
1Mattermost 1Mattermost Server Jun 17, 2026 Jun 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently a system admin. |