Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-269

MITRE ↗

Improper Privilege Management

401
CRITICAL
1,938
HIGH
752
MEDIUM
71
LOW
3,229 CVEs · Page 44/65
6.5
CVE-2020-36603

The HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unpri

6.5
CVE-2022-3419

The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allo

6.5
CVE-2022-23737

An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improp

6.5
CVE-2022-4264

Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to chan

6.4
CVE-2021-36290

Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin

6.4
CVE-2021-36293

Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin

6.4
CVE-2022-2498

An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4,

6.4
CVE-2022-23485

Sentry is an error tracking and performance monitoring platform. In versions of the sentry python library prior to 22.11

6.4
CVE-2022-46172

authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, an

6.3
CVE-2019-25066

A vulnerability has been found in ajenti 2.1.31 and classified as critical. This vulnerability affects unknown code of t

6.3
CVE-2019-25068

A vulnerability classified as critical was found in Axios Italia Axios RE 1.7.0/7.0.0. This vulnerability affects unknow

6.3
CVE-2017-20023

A vulnerability was found in Solare Solar-Log 2.8.4-56/3.5.2-85 and classified as critical. This issue affects some unkn

6.3
CVE-2017-20037

A vulnerability has been found in SICUNET Access Controller 0.32-05z and classified as critical. Affected by this vulner

6.3
CVE-2017-20038

A vulnerability was found in SICUNET Access Controller 0.32-05z and classified as critical. Affected by this issue is so

6.3
CVE-2018-25040

A vulnerability was found in uTorrent Web. It has been declared as critical. Affected by this vulnerability is an unknow

6.3
CVE-2018-25041

A vulnerability was found in uTorrent. It has been rated as critical. Affected by this issue is some unknown functionali

6.3
CVE-2018-25044

A vulnerability, which was classified as critical, has been found in uTorrent. This issue affects some unknown processin

6.3
CVE-2017-20063

A vulnerability was found in Elefant CMS 1.3.12-RC. It has been classified as critical. Affected is an unknown function

6.3
CVE-2017-20068

A vulnerability was found in Hindu Matrimonial Script. It has been rated as critical. Affected by this issue is some unk

6.3
CVE-2017-20069

A vulnerability classified as critical has been found in Hindu Matrimonial Script. This affects an unknown part of the f

6.3
CVE-2017-20070

A vulnerability classified as critical was found in Hindu Matrimonial Script. This vulnerability affects unknown code of

6.3
CVE-2017-20071

A vulnerability, which was classified as critical, has been found in Hindu Matrimonial Script. This issue affects some u

6.3
CVE-2017-20072

A vulnerability, which was classified as critical, was found in Hindu Matrimonial Script. Affected is an unknown functio

6.3
CVE-2017-20073

A vulnerability has been found in Hindu Matrimonial Script and classified as critical. Affected by this vulnerability is

6.3
CVE-2017-20074

A vulnerability was found in Hindu Matrimonial Script and classified as critical. Affected by this issue is some unknown

6.3
CVE-2017-20075

A vulnerability was found in Hindu Matrimonial Script. It has been classified as critical. This affects an unknown part

6.3
CVE-2017-20076

A vulnerability was found in Hindu Matrimonial Script. It has been declared as critical. This vulnerability affects unkn

6.3
CVE-2017-20077

A vulnerability was found in Hindu Matrimonial Script. It has been rated as critical. This issue affects some unknown pr

6.3
CVE-2017-20078

A vulnerability classified as critical has been found in Hindu Matrimonial Script. Affected is an unknown function of th

6.3
CVE-2017-20079

A vulnerability classified as critical was found in Hindu Matrimonial Script. Affected by this vulnerability is an unkno

6.3
CVE-2017-20080

A vulnerability, which was classified as critical, has been found in Hindu Matrimonial Script. Affected by this issue is

6.3
CVE-2017-20081

A vulnerability, which was classified as critical, was found in Hindu Matrimonial Script. This affects an unknown part o

6.3
CVE-2019-25071

A vulnerability was found in Apple iPhone up to 12.4.1. It has been declared as critical. Affected by this vulnerability

6.3
CVE-2021-43076

An improper privilege management vulnerability [CWE-269] in FortiADC versions 6.2.1 and below, 6.1.5 and below, 6.0.4 an

6.3
CVE-2022-4281

A vulnerability has been found in Facepay 1.0 and classified as critical. Affected by this vulnerability is an unknown f

6.1
CVE-2022-21970

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

6.1
CVE-2022-24072

The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into th

6.0
CVE-2022-20906

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on

6.0
CVE-2022-20907

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on

5.9
CVE-2022-30735

Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_tok

5.9
CVE-2022-36861

Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected

5.7
CVE-2022-38124

Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner.

5.6
CVE-2017-20028

A vulnerability was found in HumHub 0.20.1/1.0.0-beta.3. It has been classified as critical. This affects an unknown par

5.6
CVE-2022-3421

An attacker can pre-create the `/Applications/Google\ Drive.app/Contents/MacOS` directory which is expected to be owned

5.5
CVE-2022-20051

In ims service, there is a possible unexpected application behavior due to incorrect privilege assignment. This could le

5.5
CVE-2022-20112

In getAvailabilityStatus of PrivateDnsPreferenceController.java, there is a possible way for a guest user to change priv

5.4
CVE-2021-45729

The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authe

5.4
CVE-2022-23160

Dell PowerScale OneFS, versions 8.2.0-9.3.0, contains an Improper Handling of Insufficient Permissions vulnerability. An

5.4
CVE-2021-4200

A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for any user when restr

5.4
CVE-2022-25782

Improper Handling of Insufficient Privileges vulnerability in Web UI of Secomea GateManager allows logged in user to acc

Frequently Asked Questions

What is CWE-269?

CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-269?

There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.

How can I protect against CWE-269 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.

Detect CWE-269 Vulnerabilities

CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.

Get Started