Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2022-06-10 CVE-2022-30610 Improper Privilege Management vulnerability in IBM Spectrum Copy Data Management
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a page linked to from within IBM Spectrum Copy Data Management to rewrite it.
network
low complexity
ibm CWE-269
4.5
2022-06-09 CVE-2017-20028 Improper Privilege Management vulnerability in Humhub 0.20.1/1.0.0
A vulnerability was found in HumHub 0.20.1/1.0.0-beta.3.
network
low complexity
humhub CWE-269
critical
9.8
2022-06-09 CVE-2019-25068 Improper Privilege Management vulnerability in Axiositalia Registro Elettronico 1.7.0/7.0.0
A vulnerability classified as critical was found in Axios Italia Axios RE 1.7.0/7.0.0.
network
low complexity
axiositalia CWE-269
8.8
2022-06-09 CVE-2022-31214 Improper Privilege Management vulnerability in multiple products
A Privilege Context Switching issue was discovered in join.c in Firejail 0.9.68.
7.8
2022-06-09 CVE-2022-32272 Improper Privilege Management vulnerability in Opswat Metadefender
OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access control, resulting in privilege escalation.
network
low complexity
opswat CWE-269
critical
9.8
2022-06-07 CVE-2022-30735 Improper Privilege Management vulnerability in Samsung Account
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_token without permission.
network
low complexity
samsung CWE-269
7.5
2022-06-07 CVE-2022-30736 Improper Privilege Management vulnerability in Samsung Account
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.
network
low complexity
samsung CWE-269
5.3
2022-06-07 CVE-2022-30739 Improper Privilege Management vulnerability in Samsung Account
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get an user email or phone number with a normal level permission.
network
low complexity
samsung CWE-269
4.3
2022-06-07 CVE-2022-30743 Improper Privilege Management vulnerability in Samsung Account
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.
network
low complexity
samsung CWE-269
5.3
2022-06-07 CVE-2019-9971 Improper Privilege Management vulnerability in multiple products
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo with the tcpdump command, without a password.
network
low complexity
3cx debian CWE-269
8.8