Vulnerabilities > Execution with Unnecessary Privileges

DATE CVE VULNERABILITY TITLE RISK
2023-09-27 CVE-2023-4003 Execution with Unnecessary Privileges vulnerability in Oneidentity Password Manager 5.10.1/5.12.0/5.9.7.1
One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method.
low complexity
oneidentity CWE-250
6.8
2023-07-26 CVE-2023-39261 Execution with Unnecessary Privileges vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissions
local
low complexity
jetbrains CWE-250
7.8
2022-11-28 CVE-2022-3088 Execution with Unnecessary Privileges vulnerability in Moxa products
UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Image: Versions v1.0 to v1.12, UC-2100-W System Image: Versions v1.0 to v 1.12, UC-3100 System Image: Versions v1.0 to v1.6, UC-5100 System Image: Versions v1.0 to v1.4, UC-8100 System Image: Versions v3.0 to v3.5, UC-8100-ME-T System Image: Versions v3.0 and v3.1, UC-8200 System Image: v1.0 to v1.5, AIG-300 System Image: v1.0 to v1.4, UC-8410A with Debian 9 System Image: Versions v4.0.2 and v4.1.2, UC-8580 with Debian 9 System Image: Versions v2.0 and v2.1, UC-8540 with Debian 9 System Image: Versions v2.0 and v2.1, and DA-662C-16-LX (GLB) System Image: Versions v1.0.2 to v1.1.2 of Moxa's ARM-based computers have an execution with unnecessary privileges vulnerability, which could allow an attacker with user-level privileges to gain root privileges.
local
low complexity
moxa CWE-250
7.8
2022-11-22 CVE-2022-41950 Execution with Unnecessary Privileges vulnerability in Super Xray Project Super Xray 0.2
super-xray is the GUI alternative for vulnerability scanning tool xray.
local
low complexity
super-xray-project CWE-250
7.8
2022-10-11 CVE-2022-40182 Execution with Unnecessary Privileges vulnerability in Siemens products
A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions < V02.20.126.11-41), Desigo PXM50.E (All versions < V02.20.126.11-41), PXG3.W100-1 (All versions < V02.20.126.11-37), PXG3.W100-2 (All versions < V02.20.126.11-41), PXG3.W200-1 (All versions < V02.20.126.11-37), PXG3.W200-2 (All versions < V02.20.126.11-41).
network
low complexity
siemens CWE-250
8.8
2022-08-10 CVE-2022-2634 Execution with Unnecessary Privileges vulnerability in Digi Connectport X2D Firmware
An attacker may be able to execute malicious actions due to the lack of device access protections and device permissions when using the web application.
network
low complexity
digi CWE-250
critical
9.8
2022-06-24 CVE-2022-1744 Execution with Unnecessary Privileges vulnerability in Dominionvoting Imagecast X 5.5.10.30/5.5.10.32
Applications on the tested version of Dominion Voting Systems ImageCast X can execute code with elevated privileges by exploiting a system level service.
low complexity
dominionvoting CWE-250
6.8
2022-04-27 CVE-2021-34591 Execution with Unnecessary Privileges vulnerability in Bender Cc612 Firmware and Icc15Xx Firmware
In Bender/ebee Charge Controllers in multiple versions are prone to Local privilege Escalation.
local
low complexity
bender CWE-250
7.8
2021-09-14 CVE-2021-37174 Execution with Unnecessary Privileges vulnerability in Siemens products
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM ROX RX1400 (All versions < V2.14.1), RUGGEDCOM ROX RX1500 (All versions < V2.14.1), RUGGEDCOM ROX RX1501 (All versions < V2.14.1), RUGGEDCOM ROX RX1510 (All versions < V2.14.1), RUGGEDCOM ROX RX1511 (All versions < V2.14.1), RUGGEDCOM ROX RX1512 (All versions < V2.14.1), RUGGEDCOM ROX RX1524 (All versions < V2.14.1), RUGGEDCOM ROX RX1536 (All versions < V2.14.1), RUGGEDCOM ROX RX5000 (All versions < V2.14.1).
network
low complexity
siemens CWE-250
8.8
2021-06-04 CVE-2021-1528 Execution with Unnecessary Privileges vulnerability in Cisco products
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges on an affected system.
local
low complexity
cisco CWE-250
7.8