Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-269
Total 1509 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-13695 1 Quickbox 1 Quickbox 2021-07-21 9.0 HIGH 7.2 HIGH
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as root without a password, which allows an attacker to obtain sensitive information via a grep of a /root/*.db or /etc/shadow file.
CVE-2020-5916 1 F5 13 Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, Big-ip Analytics and 10 more 2021-07-21 4.0 MEDIUM 6.8 MEDIUM
In BIG-IP versions 15.1.0-15.1.0.4 and 15.0.0-15.0.1.3 the Certificate Administrator user role and higher privileged roles can perform arbitrary file reads outside of the web root directory.
CVE-2020-1412 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2021-07-21 9.3 HIGH 8.8 HIGH
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
CVE-2019-19216 1 Bmcsoftware 1 Control-m\/agent 2021-07-21 8.5 HIGH 8.8 HIGH
BMC Control-M/Agent 7.0.00.000 has an Insecure File Copy.
CVE-2021-34511 1 Microsoft 6 Windows 10, Windows 7, Windows Server 2008 and 3 more 2021-07-20 4.6 MEDIUM 7.8 HIGH
Windows Installer Elevation of Privilege Vulnerability
CVE-2021-34514 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2021-07-20 7.2 HIGH 7.8 HIGH
Windows Kernel Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-31979, CVE-2021-33771.
CVE-2021-34477 1 Microsoft 2 .net Education Bundle Sdk Install Tool, .net Install Tool For Extension Authors 2021-07-19 4.6 MEDIUM 7.8 HIGH
Visual Studio Code .NET Runtime Elevation of Privilege Vulnerability
CVE-2021-34488 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2021-07-19 4.6 MEDIUM 7.8 HIGH
Windows Console Driver Elevation of Privilege Vulnerability
CVE-2021-34493 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2021-07-19 4.6 MEDIUM 6.7 MEDIUM
Windows Partition Management Driver Elevation of Privilege Vulnerability
CVE-2021-29792 1 Ibm 1 Event Streams 2021-07-14 6.5 MEDIUM 7.2 HIGH
IBM Event Streams 10.0, 10.1, 10.2, and 10.3 could allow a user the CA private key to create their own certificates and deploy them in the cluster and gain privileges of another user. IBM X-Force ID: 203450.
CVE-2021-25428 1 Google 1 Android 2021-07-14 4.6 MEDIUM 7.8 HIGH
Improper validation check vulnerability in PackageManager prior to SMR July-2021 Release 1 allows untrusted applications to get dangerous level permission without user confirmation in limited circumstances.
CVE-2021-25429 1 Google 1 Android 2021-07-14 3.3 LOW 4.3 MEDIUM
Improper privilege management vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application.
CVE-2021-28692 1 Xen 1 Xen 2021-07-12 5.6 MEDIUM 7.1 HIGH
inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands. In the current implementation in Xen, asynchronous notification of the completion of such commands is not used. Instead, the issuing CPU spin-waits for the completion of the most recently issued command(s). Some of these waiting loops try to apply a timeout to fail overly-slow commands. The course of action upon a perceived timeout actually being detected is inappropriate: - on Intel hardware guests which did not originally cause the timeout may be marked as crashed, - on AMD hardware higher layer callers would not be notified of the issue, making them continue as if the IOMMU operation succeeded.
CVE-2021-35523 1 Securepoint 1 Openvpn-client 2021-07-02 7.2 HIGH 7.8 HIGH
Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYSTEM. A non-privileged local user can modify the OpenVPN configuration stored under "%APPDATA%\Securepoint SSL VPN" and add a external script file that is executed as privileged user.
CVE-2021-25651 1 Avaya 1 Aura Utility Services 2021-06-29 4.6 MEDIUM 7.8 HIGH
** UNSUPPORTED WHEN ASSIGNED ** A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to escalate privileges. Affects all 7.x versions of Avaya Aura Utility Services.
CVE-2021-0052 1 Intel 1 Computing Improvement Program 2021-06-24 4.6 MEDIUM 7.8 HIGH
Incorrect default privileges in the Intel(R) Computing Improvement Program before version 2.4.6522 may allow an authenticated user to potentially enable an escalation of privilege via local access.
CVE-2021-34810 1 Synology 1 Download Station 2021-06-23 6.5 MEDIUM 8.8 HIGH
Improper privilege management vulnerability in cgi component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to execute arbitrary code via unspecified vectors.
CVE-2021-33356 1 Raspap 1 Raspap 2021-06-21 9.0 HIGH 8.8 HIGH
Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inject arbitrary commands to /installers/common.sh component that can result in remote command execution with root privileges.
CVE-2021-0487 1 Google 1 Android 2021-06-15 7.2 HIGH 7.8 HIGH
In onCreate of CalendarDebugActivity.java, there is a possible way to export calendar data to the sdcard without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174046397
CVE-2021-31954 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2021-06-15 7.2 HIGH 7.8 HIGH
Windows Common Log File System Driver Elevation of Privilege Vulnerability