Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2023-03-29 CVE-2017-6894 Improper Privilege Management vulnerability in Flexera Flexnet Manager and Flexnet Manager Suite 2015
A vulnerability exists in FlexNet Manager Suite releases 2015 R2 SP3 and earlier (including FlexNet Manager Platform 9.2 and earlier) that affects the inventory gathering components and can be exploited by local users to perform certain actions with elevated privileges on the local system.
local
low complexity
flexera CWE-269
7.8
2023-03-29 CVE-2023-0664 Improper Privilege Management vulnerability in multiple products
A flaw was found in the QEMU Guest Agent service for Windows.
local
low complexity
qemu redhat fedoraproject CWE-269
7.8
2023-03-22 CVE-2022-43863 Improper Privilege Management vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain additional admin capabilities.
network
low complexity
ibm CWE-269
7.2
2023-03-22 CVE-2023-25590 Improper Privilege Management vulnerability in Arubanetworks Clearpass Policy Manager
A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges to those of a higher role.
local
low complexity
arubanetworks CWE-269
7.8
2023-03-16 CVE-2023-21458 Improper Privilege Management vulnerability in Samsung Android 11.0/12.0/13.0
Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent.
local
low complexity
samsung CWE-269
3.3
2023-03-16 CVE-2023-24760 Improper Privilege Management vulnerability in Ofcms Project Ofcms 1.1.4
An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController.
network
low complexity
ofcms-project CWE-269
8.8
2023-03-12 CVE-2022-48365 Improper Privilege Management vulnerability in Ibexa Digital Experience Platform and EZ Platform Kernel
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.26.
network
low complexity
ibexa CWE-269
7.2
2023-03-07 CVE-2022-39953 Improper Privilege Management vulnerability in Fortinet Fortinac
A improper privilege management in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.6, FortiNAC version 9.1.0 through 9.1.8, FortiNAC all versions 8.8, FortiNAC all versions 8.7, FortiNAC all versions 8.6, FortiNAC all versions 8.5, FortiNAC version 8.3.7 allows attacker to escalation of privilege via specially crafted commands.
local
low complexity
fortinet CWE-269
7.8
2023-03-03 CVE-2022-45988 Improper Privilege Management vulnerability in Starsoftcomm Coocare 5.304
starsoftcomm CooCare 5.304 allows local attackers to escalate privileges and execute arbitrary commands via a crafted file upload.
local
low complexity
starsoftcomm CWE-269
7.8
2023-03-02 CVE-2023-26475 Improper Privilege Management vulnerability in Xwiki
XWiki Platform is a generic wiki platform.
network
low complexity
xwiki CWE-269
8.8