Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-269
Total 1509 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-37968 1 Microsoft 2 Azure Arc-enabled Kubernetes, Azure Stack Edge 2022-10-12 N/A 10.0 CRITICAL
Azure Arc-enabled Kubernetes cluster Connect Elevation of Privilege Vulnerability.
CVE-2022-42238 1 Merchandise Online Store Project 1 Merchandise Online Store 2022-10-11 N/A 8.8 HIGH
A Vertical Privilege Escalation issue in Merchandise Online Store v.1.0 allows an attacker to get access to the admin dashboard.
CVE-2022-36772 3 Ibm, Linux, Microsoft 4 Aix, Infosphere Information Server, Linux Kernel and 1 more 2022-10-08 N/A 6.5 MEDIUM
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that should only be available to a privileged user.
CVE-2022-39877 2 Google, Samsung 2 Android, Group Sharing 2022-10-08 N/A 5.3 MEDIUM
Improper access control vulnerability in ProfileSharingAccount in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.
CVE-2022-3422 1 Tooljet 1 Tooljet 2022-10-07 N/A 7.5 HIGH
Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when see the info i can see the forgot_password_token the hacker can send the request and changed the pass
CVE-2021-3100 2 Amazon, Linux 2 Log4jhotpatch, Linux Kernel 2022-10-06 7.2 HIGH 8.8 HIGH
The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges.
CVE-2022-22665 1 Apple 2 Mac Os X, Macos 2022-10-06 9.3 HIGH 7.8 HIGH
A logic issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.3. A malicious application may be able to gain root privileges.
CVE-2022-41975 2 Microsoft, Realvnc 3 Windows, Vnc Server, Vnc Viewer 2022-10-04 N/A 7.8 HIGH
RealVNC VNC Server before 6.11.0 and VNC Viewer before 6.22.826 on Windows allow local privilege escalation via MSI installer Repair mode.
CVE-2022-41604 1 Checkpoint 1 Zonealarm 2022-09-30 N/A 8.8 HIGH
Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges. This occurs because of weak permissions for the %PROGRAMDATA%\CheckPoint\ZoneAlarm\Data\Updates directory, and a self-protection driver bypass that allows creation of a junction directory. This can be leveraged to perform an arbitrary file move as NT AUTHORITY\SYSTEM.
CVE-2022-0070 2 Amazon, Linux 2 Log4jhotpatch, Linux Kernel 2022-09-30 7.2 HIGH 8.8 HIGH
Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the Linux capabilities and cgroups of the target Java process that the hotpatch is applied to.
CVE-2022-39032 1 Lcnet 1 Smart Evision 2022-09-28 N/A 8.8 HIGH
Smart eVision has an improper privilege management vulnerability. A remote attacker with general user privilege can exploit this vulnerability to escalate to administrator privilege, and then perform arbitrary system command or disrupt service.
CVE-2017-8114 1 Roundcube 1 Webmail 2022-09-27 6.5 MEDIUM 8.8 HIGH
Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.
CVE-2022-38512 1 Liferay 2 Dxp, Liferay Portal 2022-09-26 N/A 6.5 MEDIUM
The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page's XLIFF translation file via crafted URL.
CVE-2022-30150 1 Microsoft 5 Windows 10, Windows 11, Windows Server 2016 and 2 more 2022-09-22 6.0 MEDIUM 7.5 HIGH
Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability.
CVE-2022-22041 1 Microsoft 8 Windows 10, Windows 11, Windows 8.1 and 5 more 2022-09-22 8.5 HIGH 6.8 MEDIUM
Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-22022, CVE-2022-30206, CVE-2022-30226.
CVE-2022-3068 1 Octoprint 1 Octoprint 2022-09-22 N/A 8.8 HIGH
Improper Privilege Management in GitHub repository octoprint/octoprint prior to 1.8.3.
CVE-2022-38351 1 Supremainc 1 Biostar 2 2022-09-21 N/A 8.8 HIGH
A vulnerability in Suprema BioStar (aka Bio Star) 2 v2.8.16 allows attackers to escalate privileges to System Administrator via a crafted PUT request to the update profile page.
CVE-2022-3079 1 Festo 4 Cpx-cec-c1, Cpx-cec-c1 Firmware, Cpx-cmxx and 1 more 2022-09-21 N/A 7.5 HIGH
Festo control block CPX-CEC-C1 and CPX-CMXX in multiple versions allow unauthenticated, remote access to critical webpage functions which may cause a denial of service.
CVE-2022-29908 1 Fabasoft 1 Fabasoft Cloud Enterprise Client 2022-09-21 N/A 7.8 HIGH
The folioupdate service in Fabasoft Cloud Enterprise Client 22.4.0043 allows Local Privilege Escalation.
CVE-2022-40142 2 Microsoft, Trendmicro 2 Windows, Apex One 2022-09-21 N/A 7.8 HIGH
A security link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service agents could allow a local attacker to create a writable folder in an arbitrary location and escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.