Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2022-03-18 CVE-2022-24637 Improper Privilege Management vulnerability in Openwebanalytics Open web Analytics
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes.
network
low complexity
openwebanalytics CWE-269
critical
9.8
2022-03-11 CVE-2022-22141 Improper Privilege Management vulnerability in Yokogawa products
'Long-term Data Archive Package' service implemented in the following Yokogawa Electric products creates some named pipe with imporper ACL configuration.
local
low complexity
yokogawa CWE-269
7.8
2022-03-10 CVE-2022-20051 Improper Privilege Management vulnerability in Google Android 11.0/12.0
In ims service, there is a possible unexpected application behavior due to incorrect privilege assignment.
local
low complexity
google CWE-269
5.5
2022-03-08 CVE-2022-24408 Improper Privilege Management vulnerability in Siemens Sinumerik MC Firmware and Sinumerik ONE Firmware
A vulnerability has been identified in SINUMERIK MC (All versions < V1.15 SP1), SINUMERIK ONE (All versions < V6.15 SP1).
local
low complexity
siemens CWE-269
7.8
2022-03-03 CVE-2022-25089 Improper Privilege Management vulnerability in Kofax Printix 1.3.1106.0
Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via UITasks.PersistentRegistryData.
network
low complexity
kofax CWE-269
critical
9.8
2022-02-25 CVE-2022-23921 Improper Privilege Management vulnerability in GE Proficy Cimplicitiy 11.1
Exploitation of this vulnerability may result in local privilege escalation and code execution.
local
low complexity
ge CWE-269
7.8
2022-02-24 CVE-2022-25636 Improper Privilege Management vulnerability in multiple products
net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write.
local
low complexity
linux debian netapp oracle CWE-269
7.8
2022-02-20 CVE-2022-25372 Improper Privilege Management vulnerability in Pritunl Pritunl-Client-Electron
Pritunl Client through 1.2.3019.52 on Windows allows local privilege escalation, related to an ACL entry for CREATOR OWNER in platform_windows.go.
local
low complexity
pritunl CWE-269
7.8
2022-02-14 CVE-2022-25150 Improper Privilege Management vulnerability in Malwarebytes Binisoft Windows Firewall Control
In Malwarebytes Binisoft Windows Firewall Control before 6.8.1.0, programs executed from the Tools tab can be used to escalate privileges.
local
low complexity
malwarebytes CWE-269
7.8
2022-02-11 CVE-2022-24927 Improper Privilege Management vulnerability in Samsung Video Player
Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files without permission.
network
low complexity
samsung CWE-269
critical
9.8