Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2021-05-12 CVE-2021-23891 Improper Privilege Management vulnerability in Mcafee Total Protection
Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated privileges by impersonating a client token which could lead to the bypassing of MTP self-defense.
local
low complexity
mcafee CWE-269
7.8
2021-05-11 CVE-2021-31169 Improper Privilege Management vulnerability in Microsoft Windows 10 and Windows Server 2016
Windows Container Manager Service Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-269
7.8
2021-05-06 CVE-2020-23128 Improper Privilege Management vulnerability in Chamilo LMS 1.11.10
Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege to create a new user then use the edit user function to change this new user to administrator privilege.
network
low complexity
chamilo CWE-269
4.9
2021-05-06 CVE-2020-28008 Improper Privilege Management vulnerability in Exim
Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges.
local
low complexity
exim CWE-269
7.8
2021-05-06 CVE-2020-28014 Improper Privilege Management vulnerability in Exim
Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges.
local
low complexity
exim CWE-269
6.1
2021-05-06 CVE-2021-1400 Improper Privilege Management vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to obtain sensitive information from or inject arbitrary commands on an affected device.
network
low complexity
cisco CWE-269
8.8
2021-05-06 CVE-2021-1447 Improper Privilege Management vulnerability in Cisco Content Security Management Appliance
A vulnerability in the user account management system of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an authenticated, local attacker to elevate their privileges to root.
local
low complexity
cisco CWE-269
6.7
2021-05-04 CVE-2020-27518 Improper Privilege Management vulnerability in Windscribe
All versions of Windscribe VPN for Mac and Windows <= v2.02.10 contain a local privilege escalation vulnerability in the WindscribeService component.
local
low complexity
windscribe CWE-269
7.8
2021-04-30 CVE-2020-27519 Improper Privilege Management vulnerability in Pritunl Pritunl-Client-Electron 1.2.2550.20
Pritunl Client v1.2.2550.20 contains a local privilege escalation vulnerability in the pritunl-service component.
local
low complexity
pritunl CWE-269
7.8
2021-04-22 CVE-2021-0256 Improper Privilege Management vulnerability in Juniper Junos
A sensitive information disclosure vulnerability in the mosquitto message broker of Juniper Networks Junos OS may allow a locally authenticated user with shell access the ability to read portions of sensitive files, such as the master.passwd file.
local
low complexity
juniper CWE-269
5.5