VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 99 of 164
  • CVE-2024-14009HigOct 30, 2025
    risk 0.47cvss 7.2epss 0.01

    Nagios XI versions prior to 2024R1.0.1 contain a privilege escalation vulnerability in the System Profile component. The System Profile feature is an administrative diagnostic/configuration capability. Due to improper access controls and unsafe handling of exported/imported…

  • CVE-2025-6042HigOct 15, 2025
    risk 0.47cvss 7.3epss 0.00

    The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.4.0. This is due to the plugin assigning the editor role by default. While limitations with…

  • CVE-2025-9966HigSep 23, 2025
    risk 0.47cvss epss 0.00

    Improper privilege management vulnerability in Novakon P series allows attackers to gain root privileges if one service is compromized.This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97fd9).

  • CVE-2025-52915HigSep 9, 2025
    risk 0.47cvss 7.2epss 0.01

    K7RKScan.sys 23.0.0.10, part of the K7 Security Anti-Malware suite, allows an admin-privileged user to send crafted IOCTL requests to terminate processes that are protected through a third-party implementation. This is caused by insufficient caller validation in the driver's…

  • CVE-2025-36729HigAug 26, 2025
    risk 0.47cvss 7.2epss 0.00

    A non-primary administrator user with admin rights to the web interface but without shell access permissions can display configuration of the device including the master admin password. This vulnerability also allows the user to give themselves shell access with the root gid.

  • CVE-2025-55581HigAug 22, 2025
    risk 0.47cvss 7.3epss 0.00

    D-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-watch-dog.sh script. The script monitors and respawns the `dcp` and `signalc` binaries without validating their integrity, origin, or permissions. An attacker…

  • CVE-2025-22165HigJul 24, 2025
    risk 0.47cvss 7.3epss 0.00

    This Medium severity ACE (Arbitrary Code Execution) vulnerability was introduced in version 4.2.8 of Sourcetree for Mac. This ACE (Arbitrary Code Execution) vulnerability, with a CVSS Score of 5.9, allows a locally authenticated attacker to execute arbitrary code which has high…

  • CVE-2025-50124HigJul 11, 2025
    risk 0.47cvss epss 0.00

    A CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation when the server is accessed by a privileged account via a console and through exploitation of a setup script.

  • CVE-2025-39202HigJun 24, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with low privileges can see and overwrite files causing information leak and data corruption.

  • CVE-2024-41199HigMay 22, 2025
    risk 0.47cvss 7.2epss 0.01

    An issue in Ocuco Innovation - JOBMANAGER.EXE v2.10.24.16 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.

  • CVE-2025-44040HigMay 21, 2025
    risk 0.47cvss 7.2epss 0.00

    An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash function. Authentication decisions may be made via PHP loose-equality comparisons if a specific MD5 value is present in the credential store. NOTE: this is disputed…

  • CVE-2023-41076HigApr 11, 2025
    risk 0.47cvss 7.3epss 0.00

    An app may be able to elevate privileges. This issue is fixed in macOS 14. This issue was addressed by removing the vulnerable code.

  • CVE-2025-29033HigApr 1, 2025
    risk 0.47cvss 7.3epss 0.01

    An issue in BambooHR Build v.25.0210.170831-83b08dd allows a remote attacker to escalate privileges via the /saml/index.php?r=" HTTP GET parameter.

  • CVE-2024-58104HigMar 25, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute…

  • CVE-2024-21966HigFeb 11, 2025
    risk 0.47cvss 7.3epss 0.00

    A DLL hijacking vulnerability in the AMD Ryzen™ Master Utility could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2024-46999HigSep 20, 2024
    risk 0.47cvss 7.3epss 0.00

    Zitadel is an open source identity management platform. ZITADEL's user grants deactivation mechanism did not work correctly. Deactivated user grants were still provided in token, which could lead to unauthorized access to applications and resources. Additionally, the management…

  • CVE-2024-7890HigSep 11, 2024
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

  • CVE-2024-45041HigSep 9, 2024
    risk 0.47cvss 8.3epss 0.01

    External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secrets has a deployment called default-external-secrets-cert-controller, which is bound with a same-name ClusterRole. This ClusterRole has "get/list" verbs of…

  • CVE-2024-7291HigAug 3, 2024
    risk 0.47cvss 7.2epss 0.01

    The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.4.1. This is due to improper restriction on user meta fields. This makes it possible for authenticated attackers, with administrator-level and above…

  • CVE-2024-38775HigAug 1, 2024
    risk 0.47cvss 7.2epss 0.01

    Improper Privilege Management vulnerability in WebAppick CTX Feed allows Privilege Escalation.This issue affects CTX Feed: from n/a through 6.5.6.