Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-269 · Improper privilege managementDefinition on MITRE ↗Clear

17 results

CVE-2026-46817
2026-07-15
Oracle E-Business Suite Improper Privilege Management Vulnerability
Oracle

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.

CWE-269 · Improper privilege managementCWE-287 · Improper authenticationCWE-306 · Missing authentication
Refsoracle.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-07-18
CVE-2026-21533
2026-02-10
Microsoft Windows Improper Privilege Management Vulnerability
Microsoft

Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally.

CWE-269 · Improper privilege management
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2026-03-03
CVE-2024-8068
2025-08-25
Citrix Session Recording Improper Privilege Management Vulnerability
Citrix

Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an authenticated user in the same Windows Active Directory domain as the session recording server domain.

CWE-269 · Improper privilege management
Refssupport.citrix.comnvd.nist.gov
Federal remediation due 2025-09-15
CVE-2024-49035
2025-02-25
Microsoft Partner Center Improper Access Control Vulnerability
Microsoft

Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges.

CWE-269 · Improper privilege management
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-03-18
CVE-2024-38014
2024-09-10
Microsoft Windows Installer Improper Privilege Management Vulnerability
Microsoft

Microsoft Windows Installer contains an improper privilege management vulnerability that could allow an attacker to gain SYSTEM privileges.

CWE-269 · Improper privilege management
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-10-01
CVE-2024-26169
2024-06-13
Microsoft Windows Error Reporting Service Improper Privilege Management VulnerabilityRansomware
Microsoft

Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges.

CWE-269 · Improper privilege management
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-07-04
CVE-2023-28434
2023-09-19
MinIO Security Feature Bypass Vulnerability
MinIO

MinIO contains a security feature bypass vulnerability that allows an attacker to use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket` to conduct privilege escalation. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access.

CWE-269 · Improper privilege management
Refsgithub.comnvd.nist.gov
Federal remediation due 2023-10-10
CVE-2019-1388
2023-04-07
Microsoft Windows Certificate Dialog Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context.

CWE-269 · Improper privilege management
Refsportal.msrc.microsoft.comnvd.nist.gov
Federal remediation due 2023-04-28
CVE-2021-25337
2022-11-08
Samsung Mobile Devices Improper Access Control Vulnerability
Samsung

Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with CVE-2021-25369 and CVE-2021-25370.

CWE-269 · Improper privilege management
Refssecurity.samsungmobile.comnvd.nist.gov
Federal remediation due 2022-11-29
CVE-2014-3153
2022-05-25
Linux Kernel Privilege Escalation Vulnerability
Linux

The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges.

CWE-269 · Improper privilege management
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2021-42287
2022-04-11
Microsoft Active Directory Domain Services Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.

CWE-269 · Improper privilege management
Refsnvd.nist.gov
Federal remediation due 2022-05-02
CVE-2021-34484
2022-03-31
Microsoft Windows User Profile Service Privilege Escalation Vulnerability
Microsoft

Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.

CWE-269 · Improper privilege management
Refsnvd.nist.gov
Federal remediation due 2022-04-21
CVE-2020-0787
2022-01-28
Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management VulnerabilityRansomware
Microsoft

Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.

CWE-269 · Improper privilege managementCWE-59 · Link following
Refsnvd.nist.gov
Federal remediation due 2022-07-28
CVE-2019-13272
2021-12-10
Linux Kernel Improper Privilege Management Vulnerability
Linux

Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root access.

CWE-269 · Improper privilege management
Refsnvd.nist.gov
Federal remediation due 2022-06-10
CVE-2021-34527
2021-11-03
Microsoft Windows Print Spooler Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.

CWE-269 · Improper privilege management
RefsReference CISA's ED 21-04 (
Federal remediation due 2022-05-03
CVE-2020-8655
2021-11-03
EyesOfNetwork Improper Privilege Management Vulnerability
EyesOfNetwork

EyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scripting Engine (NSE) script to nmap7.

CWE-269 · Improper privilege management
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-3950
2021-11-03
VMware Multiple Products Privilege Escalation Vulnerability
VMware

VMware Fusion, Remote Console (VMRC) for Mac, and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries that allows attackers to escalate privileges to root.

CWE-269 · Improper privilege management
Refsnvd.nist.gov
Federal remediation due 2022-05-03