Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2020-08-11 CVE-2020-14979 Improper Privilege Management vulnerability in multiple products
The WinRing0.sys and WinRing0x64.sys drivers 1.2.0 in EVGA Precision X1 through 1.0.6 allow local users, including low integrity processes, to read and write to arbitrary memory locations.
local
low complexity
evga winring0-project CWE-269
7.2
2020-08-11 CVE-2020-11552 Improper Privilege Management vulnerability in Zohocorp Manageengine Adselfservice Plus
An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not properly enforce user privileges associated with a Certificate dialog.
network
low complexity
zohocorp CWE-269
critical
10.0
2020-08-10 CVE-2020-9078 Improper Privilege Management vulnerability in Huawei Fusioncompute 8.0.0
FusionCompute 8.0.0 have local privilege escalation vulnerability.
local
low complexity
huawei CWE-269
4.6
2020-08-10 CVE-2020-9529 Improper Privilege Management vulnerability in Hichip Shenzhen Hichip Vision Technology Firmware
Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions of Internet of Things devices, suffers from a privilege escalation vulnerability that allows attackers on the local network to reset the device's administrator password.
network
low complexity
hichip CWE-269
7.5
2020-08-08 CVE-2020-15825 Improper Privilege Management vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2020.1, users with the Modify Group permission can elevate other users' privileges.
network
low complexity
jetbrains CWE-269
6.5
2020-08-08 CVE-2020-15824 Improper Privilege Management vulnerability in multiple products
In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue.
network
low complexity
jetbrains oracle CWE-269
8.8
2020-08-04 CVE-2019-20001 Improper Privilege Management vulnerability in Ricoh Streamline NX Client Tool and Streamline NX PC Client
An issue was discovered in RICOH Streamline NX Client Tool and RICOH Streamline NX PC Client that allows attackers to escalate local privileges.
local
low complexity
ricoh CWE-269
4.6
2020-08-04 CVE-2020-5617 Improper Privilege Management vulnerability in Skygroup Skysea Client View 12.200.12N/15.210.05F
Privilege escalation vulnerability in SKYSEA Client View Ver.12.200.12n to 15.210.05f allows an attacker to obtain unauthorized privileges and modify/obtain sensitive information or perform unintended operations via unspecified vectors.
local
low complexity
skygroup CWE-269
4.6
2020-08-03 CVE-2020-5773 Improper Privilege Management vulnerability in Teltonika-Networks Trb245 Firmware 00.02.04.01
Improper Access Control in Teltonika firmware TRB2_R_00.02.04.01 allows a low privileged user to perform unauthorized write operations.
network
low complexity
teltonika-networks CWE-269
6.5
2020-08-03 CVE-2020-4534 Improper Privilege Management vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper handling of UNC paths.
local
low complexity
ibm CWE-269
7.2