Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2022-01-11 CVE-2022-21902 Improper Privilege Management vulnerability in Microsoft products
Windows DWM Core Library Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-269
7.8
2022-01-11 CVE-2022-21970 Improper Privilege Management vulnerability in Microsoft Edge Chromium
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-269
6.1
2022-01-11 CVE-2022-0144 Improper Privilege Management vulnerability in Shelljs Project Shelljs
shelljs is vulnerable to Improper Privilege Management
local
low complexity
shelljs-project CWE-269
3.6
2022-01-10 CVE-2022-22263 Improper Privilege Management vulnerability in Google Android 11.0
Unprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbitrary activity.
local
low complexity
google CWE-269
2.1
2022-01-10 CVE-2022-22266 Improper Privilege Management vulnerability in Google Android 10.0/11.0/9.0
(Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity application prior to SMR Jan-2022 Release 1 allows untrusted applications to get WiFi information without proper permission.
local
low complexity
google CWE-269
2.1
2022-01-10 CVE-2021-45440 Improper Privilege Management vulnerability in Trendmicro products
A unnecessary privilege vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security 10.0 SP1 (on-prem versions only) could allow a local attacker to abuse an impersonation privilege and elevate to a higher level of privileges.
local
low complexity
trendmicro CWE-269
7.2
2022-01-04 CVE-2021-41388 Improper Privilege Management vulnerability in Netskope
Netskope client prior to 89.x on macOS is impacted by a local privilege escalation vulnerability.
local
low complexity
netskope CWE-269
7.2
2022-01-03 CVE-2021-39982 Improper Privilege Management vulnerability in Huawei Harmonyos 2.0
Phone Manager application has a Improper Privilege Management vulnerability.Successful exploitation of this vulnerability may read and write arbitrary files by tampering with Phone Manager notifications.
network
low complexity
huawei CWE-269
6.4
2021-12-27 CVE-2021-21750 Improper Privilege Management vulnerability in ZTE Zxin10 CMS
ZTE BigVideo Analysis product has a privilege escalation vulnerability.
local
low complexity
zte CWE-269
4.6
2021-12-23 CVE-2018-4478 Improper Privilege Management vulnerability in Apple mac OS X
A validation issue was addressed with improved logic.
local
low complexity
apple CWE-269
7.2