Vulnerabilities (CVE)

Filtered by CWE-269
Total 2612 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-25362 1 Google 1 Android 2026-06-17 3.6 LOW 6.8 MEDIUM
An improper permission management in CertInstaller prior to SMR APR-2021 Release 1 allows untrusted applications to delete certain local files.
CVE-2021-24289 1 De-baat 1 Store Locator Plus 2026-06-17 6.5 MEDIUM 8.8 HIGH
There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their user meta data to become an administrator on any site using the plugin.
CVE-2021-24207 1 Themeum 1 Wp Page Builder 2026-06-17 4.0 MEDIUM 4.3 MEDIUM
By default, the WP Page Builder WordPress plugin before 1.2.4 allows subscriber-level users to edit and make changes to any and all posts pages - user roles must be specifically blocked from editing posts and pages.
CVE-2021-24102 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2026-06-17 4.6 MEDIUM 7.8 HIGH
Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-24096 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2026-06-17 4.6 MEDIUM 7.8 HIGH
Windows Kernel Elevation of Privilege Vulnerability
CVE-2021-24095 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2026-06-17 4.6 MEDIUM 7.0 HIGH
DirectX Elevation of Privilege Vulnerability
CVE-2021-24092 1 Microsoft 12 Endpoint Protection, Security Essentials, System Center Endpoint Protection and 9 more 2026-06-17 4.6 MEDIUM 7.8 HIGH
Microsoft Defender Elevation of Privilege Vulnerability
CVE-2021-24090 1 Microsoft 2 Windows 10, Windows Server 2016 2026-06-17 9.3 HIGH 7.8 HIGH
Windows Error Reporting Elevation of Privilege Vulnerability
CVE-2021-24087 1 Azure-iot-cli-extension 1 - 2026-06-17 4.6 MEDIUM 7.0 HIGH
Azure IoT CLI extension Elevation of Privilege Vulnerability
CVE-2021-24038 1 Oculus 1 Desktop 2026-06-17 4.6 MEDIUM 7.8 HIGH
Due to a bug with management of handles in OVRServiceLauncher.exe, an attacker could expose a privileged process handle to an unprivileged process, leading to local privilege escalation. This issue affects Oculus Desktop versions after 1.39 and prior to 31.1.0.67.507.
CVE-2021-23999 1 Mozilla 3 Firefox, Firefox Esr, Thunderbird 2026-06-17 6.8 MEDIUM 8.8 HIGH
If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
CVE-2021-23893 1 Mcafee 1 Drive Encryption 2026-06-17 4.6 MEDIUM 8.8 HIGH
Privilege Escalation vulnerability in a Windows system driver of McAfee Drive Encryption (DE) prior to 7.3.0 could allow a local non-admin user to gain elevated system privileges via exploiting an unutilized memory buffer.
CVE-2021-23891 1 Mcafee 1 Total Protection 2026-06-17 4.6 MEDIUM 7.8 HIGH
Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated privileges by impersonating a client token which could lead to the bypassing of MTP self-defense.
CVE-2021-23877 1 Mcafee 1 Total Protection 2026-06-17 7.2 HIGH 6.7 MEDIUM
Privilege escalation vulnerability in the Windows trial installer of McAfee Total Protection (MTP) prior to 16.0.34_x may allow a local user to run arbitrary code as the admin user by replacing a specific temporary file created during the installation of the trial version of MTP.
CVE-2021-23193 1 Gallagher 1 Command Centre 2026-06-17 4.0 MEDIUM 8.1 HIGH
Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unprivileged operators to retrieve sensitive information from the Command Centre Server. This issue affects: Gallagher Command Centre 8.50 versions prior to 8.50.2048 (MR3) ; 8.40 versions prior to 8.40.2063 (MR4); 8.30 versions prior to 8.30.1454 (MR4) ; 8.20 versions prior to 8.20.1291 (MR6); version 8.10 and prior versions.
CVE-2021-22801 1 Schneider-electric 1 Connexium Network Manager 2026-06-17 7.5 HIGH 9.8 CRITICAL
A CWE-269: Improper Privilege Management vulnerability exists that could cause an arbitrary command execution when the software is configured with specially crafted event actions. Affected Product: ConneXium Network Manager Software (All Versions)
CVE-2021-22733 1 Schneider-electric 4 Homelynk, Homelynk Firmware, Spacelynk and 1 more 2026-06-17 4.6 MEDIUM 7.8 HIGH
Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause shell access when unauthorized code is loaded into the system folder.
CVE-2021-22732 1 Schneider-electric 4 Homelynk, Homelynk Firmware, Spacelynk and 1 more 2026-06-17 4.6 MEDIUM 7.8 HIGH
Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a code execution issue when an attacker loads unauthorized code on the web server.
CVE-2021-22421 1 Huawei 1 Harmonyos 2026-06-17 7.2 HIGH 7.8 HIGH
A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to cause further Elevation of Privileges.
CVE-2021-22396 1 Huawei 4 Ecns280 Td, Ecns280 Td Firmware, Ese620x Vess and 1 more 2026-06-17 4.6 MEDIUM 7.8 HIGH
There is a privilege escalation vulnerability in some Huawei products. Due to improper privilege management, a local attacker with common privilege may access some specific files in the affected products. Successful exploit will cause privilege escalation.Affected product versions include:eCNS280_TD V100R005C00,V100R005C10;eSE620X vESS V100R001C10SPC200,V100R001C20SPC200.