Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2022-06-07 CVE-2022-30739 Improper Privilege Management vulnerability in Samsung Account
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get an user email or phone number with a normal level permission.
network
low complexity
samsung CWE-269
4.0
2022-06-07 CVE-2022-30743 Improper Privilege Management vulnerability in Samsung Account
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.
network
low complexity
samsung CWE-269
5.0
2022-06-07 CVE-2019-9971 Improper Privilege Management vulnerability in multiple products
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo with the tcpdump command, without a password.
network
low complexity
3cx debian CWE-269
critical
9.0
2022-06-07 CVE-2020-36542 Improper Privilege Management vulnerability in Demokratian
A vulnerability classified as critical has been found in Demokratian.
network
low complexity
demokratian CWE-269
7.5
2022-05-26 CVE-2022-21827 Improper Privilege Management vulnerability in Citrix Gateway Plug-In 12.158/12.158.15/13.061.48
An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as SYSTEM.
local
low complexity
citrix CWE-269
6.6
2022-05-24 CVE-2022-29333 Improper Privilege Management vulnerability in Cyberlink Powerdirector 14.0
A vulnerability in CyberLink Power Director v14 allows attackers to escalate privileges via a crafted .exe file.
network
cyberlink CWE-269
6.8
2022-05-24 CVE-2014-125001 Improper Privilege Management vulnerability in Cardosystems Scala Rider Q3 Firmware
A vulnerability classified as critical has been found in Cardo Systems Scala Rider Q3.
low complexity
cardosystems CWE-269
8.3
2022-05-21 CVE-2022-31267 Improper Privilege Management vulnerability in Gitblit 1.9.2
Gitblit 1.9.2 allows privilege escalation via the Config User Service: a control character can be placed in a profile data field, such as an emailAddress%3Atext '[email protected]\n\trole = "#admin"' value.
network
low complexity
gitblit CWE-269
7.5
2022-05-20 CVE-2022-29179 Improper Privilege Management vulnerability in Cilium
Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads.
local
low complexity
cilium CWE-269
7.2
2022-05-20 CVE-2022-1770 Improper Privilege Management vulnerability in Trudesk Project Trudesk
Improper Privilege Management in GitHub repository polonel/trudesk prior to 1.2.2.
network
low complexity
trudesk-project CWE-269
6.5