Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2022-06-07 CVE-2022-30736 Improper Privilege Management vulnerability in Samsung Account
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.
network
low complexity
samsung CWE-269
5.3
2022-06-07 CVE-2022-30739 Improper Privilege Management vulnerability in Samsung Account
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get an user email or phone number with a normal level permission.
network
low complexity
samsung CWE-269
4.3
2022-06-07 CVE-2022-30743 Improper Privilege Management vulnerability in Samsung Account
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.
network
low complexity
samsung CWE-269
5.3
2022-06-07 CVE-2019-9971 Improper Privilege Management vulnerability in multiple products
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo with the tcpdump command, without a password.
network
low complexity
3cx debian CWE-269
8.8
2022-06-07 CVE-2020-36542 Improper Privilege Management vulnerability in Demokratian
A vulnerability classified as critical has been found in Demokratian.
network
low complexity
demokratian CWE-269
critical
9.8
2022-05-26 CVE-2022-21827 Improper Privilege Management vulnerability in Citrix Gateway Plug-In 12.158/12.158.15/13.061.48
An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as SYSTEM.
local
low complexity
citrix CWE-269
7.1
2022-05-24 CVE-2022-29333 Improper Privilege Management vulnerability in Cyberlink Powerdirector 14.0
A vulnerability in CyberLink Power Director v14 allows attackers to escalate privileges via a crafted .exe file.
local
low complexity
cyberlink CWE-269
7.8
2022-05-24 CVE-2014-125001 Improper Privilege Management vulnerability in Cardosystems Scala Rider Q3 Firmware
A vulnerability classified as critical has been found in Cardo Systems Scala Rider Q3.
low complexity
cardosystems CWE-269
8.8
2022-05-21 CVE-2022-31267 Improper Privilege Management vulnerability in Gitblit 1.9.2
Gitblit 1.9.2 allows privilege escalation via the Config User Service: a control character can be placed in a profile data field, such as an emailAddress%3Atext '[email protected]\n\trole = "#admin"' value.
network
low complexity
gitblit CWE-269
critical
9.8
2022-05-20 CVE-2022-29179 Improper Privilege Management vulnerability in Cilium
Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads.
local
low complexity
cilium CWE-269
8.2