Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-269

MITRE ↗

Improper Privilege Management

401
CRITICAL
1,938
HIGH
752
MEDIUM
71
LOW
3,229 CVEs · Page 46/65
9.3
CVE-2021-21428

Openapi generator is a java tool which allows generation of API client libraries (SDK generation), server stubs, documen

9.1
CVE-2020-9141

There is a improper privilege management vulnerability in some Huawei smartphone. Successful exploitation of this vulner

9.0
CVE-2021-23885

Privilege escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.8 allows an authenticated user to gain eleva

8.8
CVE-2021-26594

In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any contr

8.8
CVE-2021-1728

System Center Operations Manager Elevation of Privilege Vulnerability

8.8
CVE-2021-26758

Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root term

8.8
CVE-2021-27394

A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.19), Mendix Applications

8.8
CVE-2021-1400

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series

8.8
CVE-2021-1401

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series

8.8
CVE-2021-24289

There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authentic

8.8
CVE-2021-27657

Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to

8.8
CVE-2021-33356

Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inj

8.8
CVE-2021-28814

An improper access control vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows r

8.8
CVE-2021-23999

If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and gr

8.8
CVE-2021-33538

In Weidmueller Industrial WLAN devices in multiple versions an exploitable improper access control vulnerability exists

8.8
CVE-2021-27661

Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Contr

8.8
CVE-2021-32739

Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generat

8.8
CVE-2021-34481

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file

8.8
CVE-2020-18171

TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed cr

8.8
CVE-2021-34802

A failure in resetting the security context in some transaction actions in Neo4j Graph Database 4.2 and 4.3 could allow

8.8
CVE-2019-14453

An issue was discovered in Comelit "App lejos de casa (web)" 2.8.0. It allows privilege escalation via modified domus an

8.8
CVE-2020-24576

Netskope Client through 77 allows low-privileged users to elevate their privileges to NT AUTHORITY\SYSTEM.

8.8
CVE-2021-24602

The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set

8.8
CVE-2021-37911

The management interface of BenQ smart wireless conference projector does not properly control user's privilege. Attacke

8.8
CVE-2021-1851

A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Se

8.8
CVE-2021-37173

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM ROX RX1400 (All versions

8.8
CVE-2021-36954

Windows Bind Filter Driver Elevation of Privilege Vulnerability

8.8
CVE-2021-23893

Privilege Escalation vulnerability in a Windows system driver of McAfee Drive Encryption (DE) prior to 7.3.0 could allow

8.8
CVE-2021-42283

NTFS Elevation of Privilege Vulnerability

8.8
CVE-2021-36307

Networking OS10, versions prior to October 2021 with RESTCONF API enabled, contains a privilege escalation vulnerability

8.8
CVE-2021-28710

certain VT-d IOMMUs may not work in shared page table mode For efficiency reasons, address translation control structure

8.8
CVE-2021-43858

MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious

8.6
CVE-2021-30355

Amazon Kindle e-reader prior to and including version 5.13.4 improperly manages privileges, allowing the framework user

8.4
CVE-2021-1051

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkD

8.4
CVE-2021-22376

A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnera

8.2
CVE-2020-35517

A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a

8.2
CVE-2021-23882

Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update

8.2
CVE-2021-23874 KEV

Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain

8.2
CVE-2021-31847

Improper access control vulnerability in the repair process for McAfee Agent for Windows prior to 5.7.4 could allow a lo

8.1
CVE-2021-29452

a12n-server is an npm package which aims to provide a simple authentication system. A new HAL-Form was added to allow ed

8.1
CVE-2021-1579

A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Applicat

8.1
CVE-2021-42135

HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policie

8.1
CVE-2021-23193

Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unp

8.0
CVE-2021-1712

Microsoft SharePoint Elevation of Privilege Vulnerability

8.0
CVE-2021-1719

Microsoft SharePoint Elevation of Privilege Vulnerability

8.0
CVE-2021-25651

A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local us

8.0
CVE-2021-37627

Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is

8.0
CVE-2021-36967

Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability

8.0
CVE-2021-40464

Windows Nearby Sharing Elevation of Privilege Vulnerability

8.0
CVE-2021-41348

Microsoft Exchange Server Elevation of Privilege Vulnerability

Frequently Asked Questions

What is CWE-269?

CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-269?

There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.

How can I protect against CWE-269 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.

Detect CWE-269 Vulnerabilities

CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.

Get Started