Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2020-02-07 CVE-2020-8655 Improper Privilege Management vulnerability in Eyesofnetwork 5.30
An issue was discovered in EyesOfNetwork 5.3.
local
low complexity
eyesofnetwork CWE-269
7.8
2020-02-06 CVE-2015-2909 Improper Privilege Management vulnerability in Netvu products
Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices rely on a GUI warning to help ensure that the administrator configures login credentials, which makes it easier for remote attackers to obtain access by leveraging situations in which this warning was not heeded.
network
low complexity
netvu CWE-269
critical
9.8
2020-02-06 CVE-2016-9928 Improper Privilege Management vulnerability in multiple products
MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.
network
high complexity
mcabber canonical debian CWE-269
7.4
2020-02-04 CVE-2015-3613 Improper Privilege Management vulnerability in Fortinet Fortimanager
A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page
network
low complexity
fortinet CWE-269
critical
9.8
2020-02-03 CVE-2020-5182 Improper Privilege Management vulnerability in Cmsjunkie J-Businessdirectory
The J-BusinessDirectory extension before 5.2.9 for Joomla! allows Reverse Tabnabbing.
network
low complexity
cmsjunkie CWE-269
6.5
2020-01-30 CVE-2015-0949 Improper Privilege Management vulnerability in multiple products
The System Management Mode (SMM) implementation in Dell Latitude E6430 BIOS Revision A09, HP EliteBook 850 G1 BIOS revision L71 Ver.
local
low complexity
dell hp CWE-269
7.8
2020-01-30 CVE-2020-8092 Improper Privilege Management vulnerability in Bitdefender Antivirus
A privilege escalation vulnerability in BDLDaemon as used in Bitdefender Antivirus for Mac allows a local attacker to obtain authentication tokens for requests submitted to the Bitdefender Cloud.
local
low complexity
bitdefender CWE-269
5.5
2020-01-30 CVE-2020-7908 Improper Privilege Management vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages.
network
low complexity
jetbrains CWE-269
4.3
2020-01-28 CVE-2013-4583 Improper Privilege Management vulnerability in Gitlab and Gitlab-Shell
The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to gain privileges and clone arbitrary repositories.
network
low complexity
gitlab CWE-269
8.8
2020-01-28 CVE-2019-5472 Improper Privilege Management vulnerability in Gitlab
An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments.
network
low complexity
gitlab CWE-269
7.5