Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-269

MITRE ↗

Improper Privilege Management

401
CRITICAL
1,938
HIGH
752
MEDIUM
71
LOW
3,229 CVEs · Page 51/65
7.0
CVE-2021-1709

Windows Win32k Elevation of Privilege Vulnerability

7.0
CVE-2021-24087

Azure IoT CLI extension Elevation of Privilege Vulnerability

7.0
CVE-2021-24095

DirectX Elevation of Privilege Vulnerability

7.0
CVE-2021-26863

Windows Win32k Elevation of Privilege Vulnerability

7.0
CVE-2021-33751

Windows Storage Spaces Controller Elevation of Privilege Vulnerability

7.0
CVE-2021-34487

Windows Event Tracing Elevation of Privilege Vulnerability

7.0
CVE-2021-41334

Windows Desktop Bridge Elevation of Privilege Vulnerability

6.8
CVE-2021-25362

An improper permission management in CertInstaller prior to SMR APR-2021 Release 1 allows untrusted applications to dele

6.8
CVE-2021-25363

An improper access control in ActivityManagerService prior to SMR APR-2021 Release 1 allows untrusted applications to ac

6.8
CVE-2018-4478

A validation issue was addressed with improved logic. This issue is fixed in macOS High Sierra 10.13.5, Security Update

6.7
CVE-2021-23880

Improper Access Control in attribute in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update

6.7
CVE-2021-1447

A vulnerability in the user account management system of Cisco AsyncOS for Cisco Content Security Management Appliance (

6.7
CVE-2021-34493

Windows Partition Management Driver Elevation of Privilege Vulnerability

6.7
CVE-2021-0691

In the SELinux policy configured in system_app.te, there is a possible way for system_app to gain code execution in othe

6.7
CVE-2021-23877

Privilege escalation vulnerability in the Windows trial installer of McAfee Total Protection (MTP) prior to 16.0.34_x ma

6.7
CVE-2021-40124

A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could

6.7
CVE-2021-36316

Dell EMC Avamar Server versions 18.2, 19.1, 19.2, 19.3, and 19.4 contain an improper privilege management vulnerability

6.6
CVE-2021-1646

Windows WLAN Service Elevation of Privilege Vulnerability

6.6
CVE-2021-1371

A vulnerability in the role-based access control of Cisco IOS XE SD-WAN Software could allow an authenticated, local att

6.6
CVE-2021-42302

Azure RTOS Elevation of Privilege Vulnerability

6.6
CVE-2021-42303

Azure RTOS Elevation of Privilege Vulnerability

6.6
CVE-2021-42304

Azure RTOS Elevation of Privilege Vulnerability

6.5
CVE-2020-35557

An issue in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through

6.5
CVE-2021-1416

Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remot

6.5
CVE-2020-12527

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all ve

6.5
CVE-2020-12528

An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improp

6.5
CVE-2021-24158

Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders f

6.5
CVE-2021-29951

The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal

6.5
CVE-2021-39192

Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.

6.5
CVE-2021-43528

Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to thi

6.3
CVE-2021-29449

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation

6.2
CVE-2021-21430

OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configurat

6.1
CVE-2021-20208

A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a conta

6.1
CVE-2020-28014

Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. The -oP option is available to the exim user, and all

6.1
CVE-2021-31961

Windows InstallService Elevation of Privilege Vulnerability

6.1
CVE-2021-33697

Under certain conditions, SAP BusinessObjects Business Intelligence Platform (SAPUI5), versions - 420, 430, can allow an

5.9
CVE-2021-25365

An improper exception control in softsimd prior to SMR APR-2021 Release 1 allows unprivileged applications to access the

5.9
CVE-2021-39937

A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 b

5.6
CVE-2021-31836

Improper privilege management vulnerability in maconfig for McAfee Agent for Windows prior to 5.7.4 allows a local user

5.5
CVE-2018-11006

An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.

5.5
CVE-2018-11008

An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.

5.5
CVE-2021-1258

A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local

5.5
CVE-2021-0255

A local privilege escalation vulnerability in ethtraceroute of Juniper Networks Junos OS may allow a locally authenticat

5.5
CVE-2021-0256

A sensitive information disclosure vulnerability in the mosquitto message broker of Juniper Networks Junos OS may allow

5.5
CVE-2021-1836

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.5 and iPadOS 14.5, tvOS 14.5. A lo

5.5
CVE-2021-22263

An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting fr

5.5
CVE-2021-42277

Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability

5.5
CVE-2021-42280

Windows Feedback Hub Elevation of Privilege Vulnerability

5.5
CVE-2021-43211

Windows 10 Update Assistant Elevation of Privilege Vulnerability

5.4
CVE-2021-34766

A vulnerability in the web UI of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote

Frequently Asked Questions

What is CWE-269?

CWE-269 (Improper Privilege Management) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-269?

There are 3,542 CVE records associated with CWE-269 in our database. Of these, 401 are critical severity, 1938 are high severity, and 752 are medium severity.

How can I protect against CWE-269 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-269 using AI-powered security agents.

Detect CWE-269 Vulnerabilities

CyberStrike's AI agents automatically detect improper privilege management vulnerabilities across your infrastructure.

Get Started