Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2021-01-11 CVE-2018-9332 Improper Privilege Management vulnerability in K7Computing products
K7Computing Pvt Ltd K7AntiVirus Premium 15.01.00.53 is affected by: Incorrect Access Control.
local
low complexity
k7computing CWE-269
4.6
2021-01-11 CVE-2018-11008 Improper Privilege Management vulnerability in K7Computing products
An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
4.3
2021-01-11 CVE-2018-11006 Improper Privilege Management vulnerability in K7Computing products
An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
8.8
2021-01-08 CVE-2021-1051 Improper Privilege Management vulnerability in Nvidia GPU Driver
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which a local user can get elevated privileges to modify display configuration data, which may result in denial of service of the display.
local
low complexity
nvidia CWE-269
6.6
2021-01-06 CVE-2020-8275 Improper Privilege Management vulnerability in Citrix Secure Mail
Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail.
network
citrix CWE-269
4.3
2021-01-04 CVE-2020-36157 Improper Privilege Management vulnerability in Ultimatemember Ultimate Member
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Roles.
network
low complexity
ultimatemember CWE-269
7.5
2021-01-04 CVE-2020-36156 Improper Privilege Management vulnerability in Ultimatemember Ultimate Member
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update.
network
low complexity
ultimatemember CWE-269
6.5
2021-01-04 CVE-2020-36155 Improper Privilege Management vulnerability in Ultimatemember Ultimate Member
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta.
network
low complexity
ultimatemember CWE-269
7.5
2021-01-04 CVE-2020-4919 Improper Privilege Management vulnerability in IBM Cloud PAK System
IBM Cloud Pak System 2.3 has insufficient logout controls which could allow an authenticated privileged user to impersonate another user on the system.
network
low complexity
ibm CWE-269
5.5
2021-01-04 CVE-2020-4912 Improper Privilege Management vulnerability in IBM Cloud PAK System
IBM Cloud Pak System 2.3 Self Service Console could allow a privilege escalation by capturing the user request URL when logged in as a privileged user.
network
low complexity
ibm CWE-269
6.5