Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2023-01-10 CVE-2023-21772 Improper Privilege Management vulnerability in Microsoft products
Windows Kernel Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-269
7.8
2023-01-10 CVE-2023-21773 Improper Privilege Management vulnerability in Microsoft products
Windows Kernel Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-269
7.8
2023-01-10 CVE-2023-21774 Improper Privilege Management vulnerability in Microsoft products
Windows Kernel Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-269
7.8
2023-01-08 CVE-2022-0668 Improper Privilege Management vulnerability in Jfrog Artifactory
JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated user.
network
low complexity
jfrog CWE-269
critical
9.8
2022-12-28 CVE-2022-46172 Improper Privilege Management vulnerability in Goauthentik Authentik
authentik is an open-source Identity provider focused on flexibility and versatility.
network
low complexity
goauthentik CWE-269
6.4
2022-12-25 CVE-2022-37706 Improper Privilege Management vulnerability in Enlightenment
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and the system library function mishandles pathnames that begin with a /dev/..
local
low complexity
enlightenment CWE-269
7.8
2022-12-23 CVE-2022-41290 Improper Privilege Management vulnerability in IBM AIX and Vios
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the rm_rlcache_file command to obtain root privileges.
local
low complexity
ibm CWE-269
8.4
2022-12-23 CVE-2022-38757 Improper Privilege Management vulnerability in Microfocus Zenworks 2020
A vulnerability has been identified in Micro Focus ZENworks 2020 Update 3a and prior versions.
network
low complexity
microfocus CWE-269
7.2
2022-12-23 CVE-2022-4687 Improper Privilege Management vulnerability in Usememos Memos
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0.
network
low complexity
usememos CWE-269
8.1
2022-12-21 CVE-2022-46334 Improper Privilege Management vulnerability in Proofpoint Enterprise Protection
Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privileges due to unnecessary permissions.
local
low complexity
proofpoint CWE-269
7.8