Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2021-01-11 CVE-2018-9333 Improper Privilege Management vulnerability in K7Computing products
K7Computing Pvt Ltd K7AntiVirus Premium 15.1.0.53 is affected by: Buffer Overflow.
local
low complexity
k7computing CWE-269
7.8
2021-01-11 CVE-2018-9332 Improper Privilege Management vulnerability in K7Computing products
K7Computing Pvt Ltd K7AntiVirus Premium 15.01.00.53 is affected by: Incorrect Access Control.
local
low complexity
k7computing CWE-269
7.8
2021-01-11 CVE-2018-11008 Improper Privilege Management vulnerability in K7Computing products
An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
local
low complexity
k7computing CWE-269
5.5
2021-01-11 CVE-2018-11006 Improper Privilege Management vulnerability in K7Computing products
An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
local
low complexity
k7computing CWE-269
5.5
2021-01-08 CVE-2021-1051 Improper Privilege Management vulnerability in Nvidia GPU Driver
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which a local user can get elevated privileges to modify display configuration data, which may result in denial of service of the display.
local
low complexity
nvidia CWE-269
8.4
2021-01-06 CVE-2020-8275 Improper Privilege Management vulnerability in Citrix Secure Mail
Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail.
network
low complexity
citrix CWE-269
4.3
2021-01-04 CVE-2020-36156 Improper Privilege Management vulnerability in Ultimatemember Ultimate Member
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update.
network
low complexity
ultimatemember CWE-269
8.8
2021-01-04 CVE-2020-36155 Improper Privilege Management vulnerability in Ultimatemember Ultimate Member
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta.
network
low complexity
ultimatemember CWE-269
critical
9.8
2020-12-27 CVE-2020-8290 Improper Privilege Management vulnerability in Backblaze
Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation before creation of client update directories allowing for local escalation of privilege via rogue client update binary.
local
low complexity
backblaze CWE-269
7.8
2020-12-23 CVE-2020-25194 Improper Privilege Management vulnerability in Moxa Nport Iaw5000A-I/O Firmware
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has improper privilege management, which may allow an attacker with user privileges to perform requests with administrative privileges.
network
low complexity
moxa CWE-269
8.8