Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2022-06-15 CVE-2022-20819 Improper Privilege Management vulnerability in Cisco Identity Services Engine
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device.
network
low complexity
cisco CWE-269
6.5
2022-06-14 CVE-2022-29614 Improper Privilege Management vulnerability in SAP Host Agent and Netweaver Abap
SAP startservice - of SAP NetWeaver Application Server ABAP, Application Server Java, ABAP Platform and HANA Database - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, SAPHOSTAGENT 7.22, - on Unix systems, s-bit helper program sapuxuserchk, can be abused physically resulting in a privilege escalation of an attacker leading to low impact on confidentiality and integrity, but a profound impact on availability.
low complexity
sap CWE-269
5.0
2022-06-13 CVE-2022-2063 Improper Privilege Management vulnerability in Xgenecloud Nocodb
Improper Privilege Management in GitHub repository nocodb/nocodb prior to 0.91.7+.
network
low complexity
xgenecloud CWE-269
8.8
2022-06-10 CVE-2022-30610 Improper Privilege Management vulnerability in IBM Spectrum Copy Data Management
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a page linked to from within IBM Spectrum Copy Data Management to rewrite it.
network
low complexity
ibm CWE-269
4.5
2022-06-09 CVE-2017-20028 Improper Privilege Management vulnerability in Humhub 0.20.1/1.0.0
A vulnerability was found in HumHub 0.20.1/1.0.0-beta.3.
network
low complexity
humhub CWE-269
critical
9.8
2022-06-09 CVE-2019-25068 Improper Privilege Management vulnerability in Axiositalia Registro Elettronico 1.7.0/7.0.0
A vulnerability classified as critical was found in Axios Italia Axios RE 1.7.0/7.0.0.
network
low complexity
axiositalia CWE-269
8.8
2022-06-09 CVE-2022-31214 Improper Privilege Management vulnerability in multiple products
A Privilege Context Switching issue was discovered in join.c in Firejail 0.9.68.
7.8
2022-06-09 CVE-2022-32272 Improper Privilege Management vulnerability in Opswat Metadefender
OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access control, resulting in privilege escalation.
network
low complexity
opswat CWE-269
critical
9.8
2022-06-07 CVE-2022-30735 Improper Privilege Management vulnerability in Samsung Account
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_token without permission.
network
low complexity
samsung CWE-269
7.5
2022-06-07 CVE-2022-30736 Improper Privilege Management vulnerability in Samsung Account
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.
network
low complexity
samsung CWE-269
5.3