CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 73 of 99
- CVE-2024-30542CRITICALCVSS 9.8EG 9.82024-05-17
Improper Privilege Management vulnerability in Wholesale WholesaleX allows Privilege Escalation.This issue affects WholesaleX: from n/a through 1.3.2.
- CVE-2024-3057CRITICALCVSS 9.8EG 9.82024-10-08
A flaw exists whereby a user can make a specific call to a FlashArray endpoint allowing privilege escalation.
- CVE-2024-31141MEDIUMCVSS 6.5EG 6.52024-11-19
Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accept configuration data for customizing behavior, and includes ConfigProvider plugins in orde…
- CVE-2024-31237HIGHCVSS 7.5EG 7.52024-05-17
Improper Privilege Management vulnerability in WP Sharks s2Member Pro allows Privilege Escalation.This issue affects s2Member Pro: from n/a through 240315.
- CVE-2024-31290CRITICALCVSS 9.8EG 9.82024-05-17
Improper Privilege Management vulnerability in CodeRevolution Demo My WordPress allows Privilege Escalation.This issue affects Demo My WordPress: from n/a through 1.0.9.1.
- CVE-2024-31311HIGHCVSS 7.8EG 7.82024-07-09
In increment_annotation_count of stats_event.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…
- CVE-2024-31313HIGHCVSS 7.8EG 7.82024-07-09
In availableToWriteBytes of MessageQueueBase.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is …
- CVE-2024-31318HIGHCVSS 7.8EG 7.82024-07-09
In CompanionDeviceManagerService.java, there is a possible way to pair a companion device without user acceptance due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges n…
- CVE-2024-31320HIGHCVSS 7.8EG 7.82024-07-09
In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation due to CDM. This could lead to local escalation of privilege with no additional execution privileges…
- CVE-2024-31322HIGHCVSS 7.8EG 7.82024-07-09
In updateServicesLocked of AccessibilityManagerService.java, there is a possible way for an app to be hidden from the Setting while retaining Accessibility Service due to improper input validation. This could lead to local escalation of p…
- CVE-2024-31323HIGHCVSS 7.8EG 7.82024-07-09
In onCreate of multiple files, there is a possible way to trick the user into granting health permissions due to tapjacking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction …
- CVE-2024-31325HIGHCVSS 7.8EG 7.82024-07-09
In multiple locations, there is a possible way to reveal images across users data due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne…
- CVE-2024-31334HIGHCVSS 7.8EG 7.82024-07-09
In DevmemIntFreeDefBackingPage of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges nee…
- CVE-2024-3137HIGHCVSS 7.1EG 7.12024-04-02
Improper Privilege Management in uvdesk/community-skeleton
- CVE-2024-31498HIGHCVSS 8.8EG 8.82024-04-04
Yubico ykman-gui (aka YubiKey Manager GUI) before 1.2.6 on Windows, when Edge is not used, allows privilege escalation because browser windows can open as Administrator.
- CVE-2024-31502HIGHCVSS 8.1EG 8.12024-04-26
An issue in Insurance Management System v.1.0.0 and before allows a remote attacker to escalate privileges via a crafted POST request to /admin/core/new_staff.
- CVE-2024-31556HIGHCVSS 7.8EG 7.82024-05-14
An issue in Reportico Web before v.8.1.0 allows a local attacker to execute arbitrary code and obtain sensitive information via the sessionid function.
- CVE-2024-31756HIGHCVSS 7.8EG 7.82024-05-21
An issue in MarvinTest Solutions Hardware Access Driver v.5.0.3.0 and before and fixed in v.5.0.4.0 allows a local attacker to escalate privileges via the Hw65.sys component.
- CVE-2024-31757HIGHCVSS 7.8EG 7.82024-05-21
An issue in TeraByte Unlimited Image for Windows v.3.64.0.0 and before and fixed in v.4.0.0.0 allows a local attacker to escalate privileges via the TBOFLHelper64.sys and TBOFLHelper.sys component.
- CVE-2024-31953MEDIUMCVSS 6.7EG 6.72024-05-14
An issue was discovered in Samsung Magician 8.0.0 on macOS. Because it is possible to tamper with the directory and executable files used during the installation process, an attacker can escalate privileges through arbitrary code execution…
- CVE-2024-32003HIGHCVSS 8.8EG 8.82024-04-12
wn-dusk-plugin (Dusk plugin) is a plugin which integrates Laravel Dusk browser testing into Winter CMS. The Dusk plugin provides some special routes as part of its testing framework to allow a browser environment (such as headless Chrome) …
- CVE-2024-32418CRITICALCVSS 9.8EG 9.82024-04-22
An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component.
- CVE-2024-32511CRITICALCVSS 9.8EG 9.82024-05-17
Improper Privilege Management vulnerability in Astoundify Simple Registration for WooCommerce allows Privilege Escalation.This issue affects Simple Registration for WooCommerce: from n/a through 1.5.6.
- CVE-2024-32849HIGHCVSS 7.8EG 7.82024-06-10
Trend Micro Security 17.x (Consumer) is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own.
- CVE-2024-32854MEDIUMCVSS 6.7EG 6.72024-07-02
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privilege attacker could potentially exploit this vulnerability, leading to privilege escalation.
- CVE-2024-32899HIGHCVSS 7.0EG 7.02024-06-13
In gpu_pm_power_off_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a race condition. This could lead to local escalation of privilege to TEE with no additional execution privileges needed. User i…
- CVE-2024-32906HIGHCVSS 7.8EG 7.82024-06-13
In AcvpOnMessage of avcp.cpp, there is a possible EOP due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2024-32918MEDIUMCVSS 6.1EG 6.12024-06-13
Permission Bypass allowing attackers to disable HDCP 2.2 encryption by not completing the HDCP Key Exchange initialization steps
- CVE-2024-32960HIGHCVSS 8.8EG 8.82024-05-17
Improper Privilege Management vulnerability in Booking Ultra Pro allows Privilege Escalation.This issue affects Booking Ultra Pro: from n/a through 1.1.12.
- CVE-2024-33223HIGHCVSS 8.8EG 8.82024-05-22
An issue in the component IOMap64.sys of ASUSTeK Computer Inc ASUS GPU TweakII v1.4.5.2 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
- CVE-2024-33224HIGHCVSS 8.4EG 8.42024-05-22
An issue in the component rtkio64.sys of Realtek Semiconductor Corp Realtek lO Driver v1.008.0823.2017 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
- CVE-2024-33226CRITICALCVSS 9.9EG 9.92024-05-22
An issue in the component Access64.sys of Wistron Corporation TBT Force Power Control v1.0.0.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
- CVE-2024-3325HIGHCVSS 7.2EG 7.22024-07-10
Vulnerability in Jaspersoft JasperReport Servers.This issue affects JasperReport Servers: from 8.0.4 through 9.0.0.
- CVE-2024-33308CRITICALCVSS 9.1EG 9.12024-04-30
An issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to escalate privileges via the Emergency Contact Feature. NOTE: this is disputed as discussed in the msn-official/CVE-Evidence reposi…
- CVE-2024-33374CRITICALCVSS 9.8EG 9.82024-06-14
Incorrect access control in the UART/Serial interface on the LB-LINK BL-W1210M v2.0 router allows attackers to access the root terminal without authentication.
- CVE-2024-33393MEDIUMCVSS 6.2EG 6.22024-05-01
An issue in spidernet-io spiderpool v.0.9.3 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.
- CVE-2024-33398HIGHCVSS 7.5EG 7.52024-05-03
There is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allows an attacker to impersonate the service account bound to this ClusterRole and use its high-risk privileges to list co…
- CVE-2024-33500MEDIUMCVSS 5.9EG 5.92024-06-11
A vulnerability has been identified in Mendix Applications using Mendix 10 (All versions < V10.11.0), Mendix Applications using Mendix 10 (V10.6) (All versions < V10.6.9), Mendix Applications using Mendix 9 (All versions >= V9.3.0 < V9.24.…
- CVE-2024-33522MEDIUMCVSS 6.7EG 6.72024-04-29
In vulnerable versions of Calico (v3.27.2 and below), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 and below), and Calico Cloud (v19.2.0 and below), an attacker who has local access to the Kubernetes node, can escalate their privileges b…
- CVE-2024-33549HIGHCVSS 8.8EG 8.82024-05-17
Improper Privilege Management vulnerability in AA-Team WZone allows Privilege Escalation.This issue affects WZone: from n/a through 14.0.10.
- CVE-2024-33550HIGHCVSS 8.8EG 8.82024-05-17
Improper Privilege Management vulnerability in JR King/Eran Schoellhorn WP Masquerade allows Privilege Escalation.This issue affects WP Masquerade: from n/a through 1.1.0.
- CVE-2024-33552CRITICALCVSS 9.8EG 9.82024-05-17
Improper Privilege Management vulnerability in 8theme XStore Core allows Privilege Escalation.This issue affects XStore Core: from n/a through 5.3.8.
- CVE-2024-33567CRITICALCVSS 9.8EG 9.82024-05-17
Improper Privilege Management vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Privilege Escalation.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3.
- CVE-2024-33569HIGHCVSS 7.2EG 7.22024-05-17
Improper Privilege Management vulnerability in Darren Cooney Instant Images allows Privilege Escalation.This issue affects Instant Images: from n/a through 6.1.0.
- CVE-2024-33656HIGHCVSS 7.8EG 7.82024-08-21
The DXE module SmmComputrace contains a vulnerability that allows local attackers to leak stack or global memory. This could lead to privilege escalation, arbitrary code execution, and bypassing OS security mechanisms
- CVE-2024-33775CRITICALCVSS 9.8EG 9.82024-05-01
An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.
- CVE-2024-33872CRITICALCVSS 9.8EG 9.82024-08-20
Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code execution and escalation of privileges.
- CVE-2024-3388MEDIUMCVSS 4.1EG 4.12024-04-10
A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability does not allow the at…
- CVE-2024-33894HIGHCVSS 8.8EG 8.82024-08-02
Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are executing several processes with elevated privileges.
- CVE-2024-34082HIGHCVSS 8.5EG 8.52024-05-15
Grav is a file-based Web platform. Prior to version 1.7.46, a low privilege user account with page edit privilege can read any server files using Twig Syntax. This includes Grav user account files - `/grav/user/accounts/*.yaml`. This file …
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →