Vulnerabilities (CVE)

Filtered by CWE-269
Total 1970 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-25513 1 Google 1 Android 2024-11-21 2.1 LOW 2.4 LOW
An improper privilege management vulnerability in Apps Edge application prior to SMR Dec-2021 Release 1 allows unauthorized access to some device data on the lockscreen.
CVE-2021-25508 1 Samsung 1 Smartthings 2024-11-21 7.5 HIGH 5.3 MEDIUM
Improper privilege management vulnerability in API Key used in SmartThings prior to 1.7.73.22 allows an attacker to abuse the API key without limitation.
CVE-2021-25429 1 Google 1 Android 2024-11-21 3.3 LOW 4.3 MEDIUM
Improper privilege management vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application.
CVE-2021-25428 1 Google 1 Android 2024-11-21 4.6 MEDIUM 7.8 HIGH
Improper validation check vulnerability in PackageManager prior to SMR July-2021 Release 1 allows untrusted applications to get dangerous level permission without user confirmation in limited circumstances.
CVE-2021-25377 2 Google, Samsung 2 Android, Experience Service 2024-11-21 4.6 MEDIUM 3.3 LOW
Intent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10.0) above allows attacker to execute privileged action.
CVE-2021-25363 1 Google 1 Android 2024-11-21 3.6 LOW 6.8 MEDIUM
An improper access control in ActivityManagerService prior to SMR APR-2021 Release 1 allows untrusted applications to access running processesdelete some local files.
CVE-2021-25362 1 Google 1 Android 2024-11-21 3.6 LOW 6.8 MEDIUM
An improper permission management in CertInstaller prior to SMR APR-2021 Release 1 allows untrusted applications to delete certain local files.
CVE-2021-24289 1 De-baat 1 Store Locator Plus 2024-11-21 6.5 MEDIUM 8.8 HIGH
There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their user meta data to become an administrator on any site using the plugin.
CVE-2021-24207 1 Themeum 1 Wp Page Builder 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
By default, the WP Page Builder WordPress plugin before 1.2.4 allows subscriber-level users to edit and make changes to any and all posts pages - user roles must be specifically blocked from editing posts and pages.
CVE-2021-24102 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2024-11-21 4.6 MEDIUM 7.8 HIGH
Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-24096 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2024-11-21 4.6 MEDIUM 7.8 HIGH
Windows Kernel Elevation of Privilege Vulnerability
CVE-2021-24095 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2024-11-21 4.6 MEDIUM 7.0 HIGH
DirectX Elevation of Privilege Vulnerability
CVE-2021-24092 1 Microsoft 12 Endpoint Protection, Security Essentials, System Center Endpoint Protection and 9 more 2024-11-21 4.6 MEDIUM 7.8 HIGH
Microsoft Defender Elevation of Privilege Vulnerability
CVE-2021-24090 1 Microsoft 2 Windows 10, Windows Server 2016 2024-11-21 9.3 HIGH 7.8 HIGH
Windows Error Reporting Elevation of Privilege Vulnerability
CVE-2021-24087 1 Azure-iot-cli-extension 1 - 2024-11-21 4.6 MEDIUM 7.0 HIGH
Azure IoT CLI extension Elevation of Privilege Vulnerability
CVE-2021-24038 1 Oculus 1 Desktop 2024-11-21 4.6 MEDIUM 7.8 HIGH
Due to a bug with management of handles in OVRServiceLauncher.exe, an attacker could expose a privileged process handle to an unprivileged process, leading to local privilege escalation. This issue affects Oculus Desktop versions after 1.39 and prior to 31.1.0.67.507.
CVE-2021-23999 1 Mozilla 3 Firefox, Firefox Esr, Thunderbird 2024-11-21 6.8 MEDIUM 8.8 HIGH
If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
CVE-2021-23893 1 Mcafee 1 Drive Encryption 2024-11-21 4.6 MEDIUM 8.8 HIGH
Privilege Escalation vulnerability in a Windows system driver of McAfee Drive Encryption (DE) prior to 7.3.0 could allow a local non-admin user to gain elevated system privileges via exploiting an unutilized memory buffer.
CVE-2021-23891 1 Mcafee 1 Total Protection 2024-11-21 4.6 MEDIUM 7.8 HIGH
Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated privileges by impersonating a client token which could lead to the bypassing of MTP self-defense.
CVE-2021-23877 1 Mcafee 1 Total Protection 2024-11-21 7.2 HIGH 6.7 MEDIUM
Privilege escalation vulnerability in the Windows trial installer of McAfee Total Protection (MTP) prior to 16.0.34_x may allow a local user to run arbitrary code as the admin user by replacing a specific temporary file created during the installation of the trial version of MTP.