Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2024-12-14 CVE-2024-11721 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.24.5.
network
high complexity
CWE-269
8.1
2024-08-28 CVE-2024-4555 Improper Privilege Management vulnerability in Microfocus Netiq Access Manager 5.0.2
Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specific scenario. This issue affects NetIQ Access Manager before 5.0.4.1 and before 5.1
network
low complexity
microfocus CWE-269
7.5
2024-06-13 CVE-2024-32918 Improper Privilege Management vulnerability in Google Android
Permission Bypass allowing attackers to disable HDCP 2.2 encryption by not completing the HDCP Key Exchange initialization steps
low complexity
google CWE-269
6.1
2024-06-12 CVE-2024-5909 Improper Privilege Management vulnerability in Paloaltonetworks Cortex XDR Agent
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent.
local
low complexity
paloaltonetworks CWE-269
5.5
2024-06-12 CVE-2024-5759 Improper Privilege Management vulnerability in Tenable Security Center 6.3.0
An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the required privileges
network
low complexity
tenable CWE-269
6.3
2024-05-17 CVE-2024-22145 Improper Privilege Management vulnerability in Instawp Connect
Improper Privilege Management vulnerability in InstaWP Team InstaWP Connect allows Privilege Escalation.This issue affects InstaWP Connect: from n/a through 0.1.0.8.
network
low complexity
instawp CWE-269
8.8
2024-05-17 CVE-2024-33552 Improper Privilege Management vulnerability in 8Theme Xstore Core
Improper Privilege Management vulnerability in 8theme XStore Core allows Privilege Escalation.This issue affects XStore Core: from n/a through 5.3.8.
network
low complexity
8theme CWE-269
critical
9.8
2024-05-17 CVE-2023-41243 Improper Privilege Management vulnerability in Wpvivid Migration, Backup, Staging
Improper Privilege Management vulnerability in WPvivid Team WPvivid Backup and Migration allows Privilege Escalation.This issue affects WPvivid Backup and Migration: from n/a through 0.9.90.
network
low complexity
wpvivid CWE-269
8.8
2024-04-25 CVE-2024-28241 Improper Privilege Management vulnerability in Glpi-Project Glpi Agent
The GLPI Agent is a generic management agent.
local
low complexity
glpi-project CWE-269
7.8
2024-03-06 CVE-2023-38944 Improper Privilege Management vulnerability in Multilaser Re160V Firmware and Re163V Firmware
An issue in Multilaser RE160V firmware v12.03.01.09_pt and Multilaser RE163V firmware v12.03.01.10_pt allows attackers to bypass the access control and gain complete access to the application via modifying a HTTP header.
network
low complexity
multilaser CWE-269
critical
9.8