Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2022-05-10 CVE-2022-1397 Improper Privilege Management vulnerability in Easyappointments
API Privilege Escalation in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
network
low complexity
easyappointments CWE-269
8.8
2022-05-06 CVE-2021-27765 Improper Privilege Management vulnerability in Hcltech Bigfix Platform
The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation.
local
low complexity
hcltech CWE-269
7.8
2022-05-06 CVE-2021-27766 Improper Privilege Management vulnerability in Hcltech Bigfix Platform
The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation.
local
low complexity
hcltech CWE-269
7.8
2022-05-06 CVE-2021-27767 Improper Privilege Management vulnerability in Hcltech Bigfix Platform
The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation.
local
low complexity
hcltech CWE-269
7.8
2022-05-04 CVE-2022-25782 Improper Privilege Management vulnerability in Secomea products
Improper Handling of Insufficient Privileges vulnerability in Web UI of Secomea GateManager allows logged in user to access and update privileged information.
network
low complexity
secomea CWE-269
5.4
2022-05-03 CVE-2022-20759 Improper Privilege Management vulnerability in Cisco Firepower Threat Defense
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, but unprivileged, remote attacker to elevate privileges to level 15.
network
low complexity
cisco CWE-269
8.8
2022-05-02 CVE-2021-36784 Improper Privilege Management vulnerability in Suse Rancher
A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin role to escalate to full admin.
network
low complexity
suse CWE-269
7.2
2022-04-29 CVE-2021-36207 Improper Privilege Management vulnerability in Johnsoncontrols products
Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow an authenticated user to elevate their privileges to administrator.
network
low complexity
johnsoncontrols CWE-269
8.8
2022-04-29 CVE-2022-1227 Improper Privilege Management vulnerability in multiple products
A privilege escalation flaw was found in Podman.
8.8
2022-04-22 CVE-2022-1107 Improper Privilege Management vulnerability in Lenovo products
During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.
local
low complexity
lenovo CWE-269
6.7