CWE-269
2,910 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CVEs (2,910)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Cloudfoundry Pivotal Software3Cf Release Cloud Foundry UaaCloud Foundry Uaa BoshMay 13, 2026 Jun 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v261; UAA release 2.x versions prior to v2.7.4.17, 3.6.x versions prior to v3.6.11, 3.9.x versions prior to v3.9.13, and other versions pri...Show more |
2Cloudfoundry Pivotal Software3Cf Release Cloud Foundry UaaCloud Foundry Uaa BoshMay 13, 2026 Jun 13, 2017 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v260; UAA release 2.x versions prior to v2.7.4.16, 3.6.x versions prior to v3.6.10, 3.9.x versions prior to v3.9.12, and other versions pri...Show more |
2Cloudfoundry Pivotal Software3Cloud Foundry Cf Cloud Foundry UaaCloud Foundry Uaa BoshMay 13, 2026 Jun 13, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x versions prior to v3.6.8, 3.9.x versions prior to v3.9.10, and other versions prio...Show more |
1Cloudfoundry 2Capi Release Cf ReleaseMay 13, 2026 Jun 13, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Cloud Foundry Foundation cf-release versions prior to 250 and CAPI-release versions prior to 1.12.0. A user with the SpaceAuditor role is over-privileged with the ability to restage application...Show more |
In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is capable of opening a specific URL in a browser to gain administrative privileges...Show more |
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account or read existing vendor account data (including usernames and passwords). |
PostgreSQL PL/Java before 1.5.0 allows remote authenticated users to alter type mappings for types they do not own. |
PostgreSQL PL/Java before 1.5.0 allows remote authenticated users with USAGE permission on the public schema to alter the public schema classpath. |
Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality. This bug prevents transitioning into the specified user specified in a run_as request. If a role has been cr...Show more |
Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions o...Show more |
A vulnerability in a script file that is installed as part of the Cisco Policy Suite (CPS) Software distribution for the CPS appliance could allow an authenticated, local attacker to escalate their privilege level to roo...Show more |
In Moodle 2.x and 3.x, remote authenticated users can take ownership of arbitrary blogs by editing an external blog link. |
1Emc 1Mainframe Enablers Resourcepak Base May 13, 2026 May 8, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 EMC Mainframe Enablers ResourcePak Base versions 7.6.0, 8.0.0, and 8.1.0 contains a fix for a privilege management vulnerability that could potentially be exploited by malicious users to compromise the affected system. |
3Hpe IntelSiemens36Active Management Technology Firmware Proliant Ml10 Gen9 Server FirmwareSimatic Field Pg M3 Firmware+33 moreApr 22, 2026 May 2, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could...Show more |
Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in t...Show more |
Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Workflow and the "MultiReport" function to alter or delete information via unspecified vectors. |
In Avast Antivirus before v17, an unprivileged user (and thus malware or a virus) can mark an arbitrary process as Trusted from the perspective of the Avast product. This bypasses the Self-Defense feature of the product,...Show more |
1Trendmicro 1Interscan Web Security Virtual Appliance May 13, 2026 Apr 5, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate data. Per IWSVA documentation, by default, IWSVA acts as a private Certificate Authority (CA) and dyn...Show more |
file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "same root name but with a suffix" attack. NOTE: This vulnerability exists because of...Show more |
1Honeywell 7Intermec Pc23 Firmware Intermec Pc42 FirmwareIntermec Pc43 Firmware+4 moreMay 13, 2026 Mar 29, 2017 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers before 10.11.013310 and 10.12.x before 10.12.013309 have /usr/bin/lua installed setuid to the itadmin account, which allows local users...Show more |