Vulnerabilities > Execution with Unnecessary Privileges

DATE CVE VULNERABILITY TITLE RISK
2023-09-27 CVE-2023-4003 Execution with Unnecessary Privileges vulnerability in Oneidentity Password Manager 5.10.1/5.12.0/5.9.7.1
One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method.
low complexity
oneidentity CWE-250
6.8
2023-07-26 CVE-2023-39261 Execution with Unnecessary Privileges vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissions
local
low complexity
jetbrains CWE-250
7.8
2022-11-28 CVE-2022-3088 Execution with Unnecessary Privileges vulnerability in Moxa products
UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Image: Versions v1.0 to v1.12, UC-2100-W System Image: Versions v1.0 to v 1.12, UC-3100 System Image: Versions v1.0 to v1.6, UC-5100 System Image: Versions v1.0 to v1.4, UC-8100 System Image: Versions v3.0 to v3.5, UC-8100-ME-T System Image: Versions v3.0 and v3.1, UC-8200 System Image: v1.0 to v1.5, AIG-300 System Image: v1.0 to v1.4, UC-8410A with Debian 9 System Image: Versions v4.0.2 and v4.1.2, UC-8580 with Debian 9 System Image: Versions v2.0 and v2.1, UC-8540 with Debian 9 System Image: Versions v2.0 and v2.1, and DA-662C-16-LX (GLB) System Image: Versions v1.0.2 to v1.1.2 of Moxa's ARM-based computers have an execution with unnecessary privileges vulnerability, which could allow an attacker with user-level privileges to gain root privileges.
local
low complexity
moxa CWE-250
7.8
2022-11-22 CVE-2022-41950 Execution with Unnecessary Privileges vulnerability in Super Xray Project Super Xray 0.2
super-xray is the GUI alternative for vulnerability scanning tool xray.
local
low complexity
super-xray-project CWE-250
7.8
2022-10-11 CVE-2022-40182 Execution with Unnecessary Privileges vulnerability in Siemens products
A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions < V02.20.126.11-41), Desigo PXM50.E (All versions < V02.20.126.11-41), PXG3.W100-1 (All versions < V02.20.126.11-37), PXG3.W100-2 (All versions < V02.20.126.11-41), PXG3.W200-1 (All versions < V02.20.126.11-37), PXG3.W200-2 (All versions < V02.20.126.11-41).
network
low complexity
siemens CWE-250
8.8
2022-06-24 CVE-2022-1744 Execution with Unnecessary Privileges vulnerability in Dominionvoting Imagecast X 5.5.10.30/5.5.10.32
Applications on the tested version of Dominion Voting Systems ImageCast X can execute code with elevated privileges by exploiting a system level service.
local
low complexity
dominionvoting CWE-250
7.2
2022-04-27 CVE-2021-34591 Execution with Unnecessary Privileges vulnerability in Bender Cc612 Firmware and Icc15Xx Firmware
In Bender/ebee Charge Controllers in multiple versions are prone to Local privilege Escalation.
local
low complexity
bender CWE-250
7.2
2021-09-14 CVE-2021-37174 Execution with Unnecessary Privileges vulnerability in Siemens products
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM ROX RX1400 (All versions < V2.14.1), RUGGEDCOM ROX RX1500 (All versions < V2.14.1), RUGGEDCOM ROX RX1501 (All versions < V2.14.1), RUGGEDCOM ROX RX1510 (All versions < V2.14.1), RUGGEDCOM ROX RX1511 (All versions < V2.14.1), RUGGEDCOM ROX RX1512 (All versions < V2.14.1), RUGGEDCOM ROX RX1524 (All versions < V2.14.1), RUGGEDCOM ROX RX1536 (All versions < V2.14.1), RUGGEDCOM ROX RX5000 (All versions < V2.14.1).
network
low complexity
siemens CWE-250
critical
9.0
2021-06-04 CVE-2021-1528 Execution with Unnecessary Privileges vulnerability in Cisco products
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges on an affected system.
local
low complexity
cisco CWE-250
7.8
2021-05-28 CVE-2020-27826 Execution with Unnecessary Privileges vulnerability in Redhat Keycloak
A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API.
network
redhat CWE-250
4.9