← Back
CWE-269

3,308 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (3,308)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zenphoto
1Zenphoto
Nov 21, 2024
Jun 26, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Local file inclusion vulnerability in Zenphoto 1.4.14 and earlier allows a remote attacker with an administrative privilege to execute arbitrary code or obtain sensitive information.
1Basercms
1Basercms
Nov 21, 2024
Jun 26, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction for a content to view a file which is uploaded by a site user via unspecified ve...Show more
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction for a content to view a file which is uploaded by a site user via unspecified vectors.Show less
1Cybozu
1Office
Nov 21, 2024
Jun 26, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Cybozu Office 10.0.0 to 10.8.0 allows authenticated attackers to bypass authentication to obtain the schedules without access privilege via unspecified vectors.
1Octopus
1Octopus Deploy
Nov 21, 2024
Jun 26, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Octopus Deploy 3.0 onwards (before 2018.6.7), an authenticated user with incorrect permissions may be able to create Accounts under the Infrastructure menu.
2Redhat
Theforeman
2Foreman
Satellite
Nov 21, 2024
Jun 21, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, al...Show more
A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to access those systems.Show less
1Broadcom
1Privileged Access Manager
Jun 17, 2026
Jun 18, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands by poisoning a configuration file.
1Broadcom
1Privileged Access Manager
Jun 17, 2026
Jun 18, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with specially crafted requests.
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Jun 16, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 does not properly check for folder-to-object association, which allo...Show more
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 does not properly check for folder-to-object association, which allows remote authenticated users to delete arbitrary tasks via the task id in a delete action to api/tasks.Show less
1Ibm
1Puredata System For Analytics
Nov 21, 2024
Jun 15, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
IBM Netezza Platform Software (IBM PureData System for Analytics 1.0.0) could allow a local user to modify a world writable file, which could be used to execute commands as root. IBM X-Force ID: 140211.
1Apollotechnologiesinc
1Momentum Axel 720p Firmware
Nov 21, 2024
Jun 12, 2018
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
An issue was discovered on Momentum Axel 720P 5.1.8 devices. All processes run as root.
2Canonical
Mozilla
2Firefox
Ubuntu Linux
Nov 21, 2024
Jun 11, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have explicit user permission...Show more
WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have explicit user permission. This vulnerability affects Firefox < 60.Show less
3Debian
MozillaRedhat
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+5 more
Nov 25, 2025
Jun 11, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorrect enforcement of CSP. This vulnerability affects Thunderbird < 52.3, Firefox ES...Show more
When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorrect enforcement of CSP. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.Show less
1Mozilla
2Firefox
Thunderbird
Nov 25, 2025
Jun 11, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. Note: This attack only affects Windows operating systems. Other operating...Show more
An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.Show less
1Mozilla
1Firefox
Nov 25, 2025
Jun 11, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using the Mozilla Windows Updater, which runs with the Maintenance Service's privileged access. Note: Thi...Show more
The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using the Mozilla Windows Updater, which runs with the Maintenance Service's privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.Show less
1Mozilla
1Firefox
Nov 25, 2025
Jun 11, 2018
N/A· v4
5.5 MEDIUM· v3
3.6 LOW· v2
The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parameter through the Mozilla Maintenance Service, which has privileged acces...Show more
The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parameter through the Mozilla Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 45.8 and Firefox < 52.Show less
1Quest
1Disk Backup
Nov 21, 2024
Jun 2, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 2 of 6).
1Ibm
2Flashsystem 840 Firmware
Flashsystem 900 Firmware
Nov 21, 2024
May 29, 2018
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
IBM FlashSystem V840 and V900 products could allow an authenticated attacker with specialized access to overwrite arbitrary files which could cause a denial of service. IBM X-Force ID: 141148.
1Mcafee
1Virusscan Enterprise
Jun 17, 2026
May 25, 2018
N/A· v4
3.9 LOW· v3
2.1 LOW· v2
Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 13 allows local users to spawn unrelated processes with elevated privileges via the syst...Show more
Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 13 allows local users to spawn unrelated processes with elevated privileges via the system administrator granting McTray.exe elevated privileges (by default it runs with the current user's privileges).Show less
1Moodle
1Moodle
Nov 21, 2024
May 25, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Moodle 3.x. Students who submitted assignments and exported them to portfolios can download any stored Moodle file by changing the download URL.
1Fortinet
1Fortios
Nov 21, 2024
May 24, 2018
N/A· v4
6.2 MEDIUM· v3
7.2 HIGH· v2
A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, and 5.2 and below versions allows attacker to execute unauthorized binary program contained on an US...Show more
A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, and 5.2 and below versions allows attacker to execute unauthorized binary program contained on an USB drive plugged into a FortiGate via linking the aforementioned binary program to a command that is allowed to be run by the fnsysctl CLI command.Show less