WAFPlanet

CVE Database - Privilege Escalation

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

2537
Matching CVEs
15562
Critical
25943
High
66770
High WAF Coverage

CVE-2025-55187

UNKNOWN
0.00 CVSS none

In DriveLock 24.1.4 before 24.1.5, 24.2.5 before 24.2.6, and 25.1.2 before 25.1.4, attackers can gain elevated privileges.

Improper Privilege Management
WAF: Low

CVE-2025-5494

HIGH
7.80 CVSS 3.1

ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13.

Improper Privilege Management
WAF: Low

CVE-2025-9966

UNKNOWN
0.00 CVSS none

Improper privilege management vulnerability in Novakon P series allows attackers to gain root privileges if one service is compromized.This issue affects P series: P – V2001.A.C518o2.

Improper Privilege Management
WAF: Low

CVE-2025-9038

UNKNOWN
0.00 CVSS none

Improper Privilege Management vulnerability in GE Vernova S1 Agile Configuration Software on Windows allows Privilege Escalation.This issue affects S1 Agile Configuration Software: 3.1 and previous version.

Improper Privilege Management
WAF: Low

CVE-2025-57396

UNKNOWN
0.00 CVSS none

Tandoor Recipes 2.0.0-alpha-1, fixed in 2.0.0-alpha-2, is vulnerable to privilege escalation. This is due to the rework of the API, which resulted in the User Profile API Endpoint containing two boolean values indicating whether a user is staff or administrative. Consequently, any user can escalate their privileges to the highest level.

Improper Privilege Management
WAF: Low

CVE-2025-54761

UNKNOWN
0.00 CVSS none

An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.

Improper Privilege Management Improper Authentication
WAF: Low

CVE-2025-34204

CRITICAL
9.80 CVSS 3.1

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) contains multiple Docker containers that run primary application processes (for example PHP workers, Node.js servers and custom binaries) as the root user. This increases the blast radius of a container compromise and enables lateral movement and host compromise when a container is breached.

Improper Privilege Management
WAF: Low

CVE-2025-10650

UNKNOWN
0.00 CVSS none

SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys under certain conditions, allowing unauthorized privilege escalation to admin via SSH. Affects non-production debug and internal development builds created between versions 2.5.0 and 2.6.3.  No generally available (GA) or customer-released production builds were affected.  There is no evidence that this issue was exposed in customer environments or production deployments.

Improper Privilege Management
WAF: Low

CVE-2025-58432

HIGH
7.80 CVSS 3.1

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and all prior versions, the /v2_1/files/file/uploadV2 endpoint allows file upload from ANY USER who has access to localhost. File uploads are performed AS ROOT.

Improper Privilege Management
WAF: Low

CVE-2025-37123

UNKNOWN
0.00 CVSS none

A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.

Improper Privilege Management
WAF: Low

CVE-2025-34187

HIGH
8.80 CVSS 3.1

Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash scripts. If these scripts are writable by web-facing users or accessible via command injection, attackers can replace them with malicious payloads. Execution with sudo grants full root access, resulting in remote privilege escalation and potential system compromise.

OS Command Injection Improper Privilege Management
WAF: High

CVE-2025-43333

UNKNOWN
0.00 CVSS none

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to gain root privileges.

Improper Privilege Management
WAF: Low

CVE-2025-57118

UNKNOWN
0.00 CVSS none

An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php

Improper Privilege Management
WAF: Low

CVE-2025-9059

UNKNOWN
0.00 CVSS none

The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hijacking.

Improper Privilege Management
WAF: Low

CVE-2025-50892

UNKNOWN
0.00 CVSS none

The eudskacs.sys driver version 20250328 shipped with EaseUs Todo Backup 1.2.0.1 fails to properly validate privileges for I/O requests (IRP_MJ_READ/IRP_MJ_WRITE) sent to its device object. This allows a local, low-privileged attacker to perform arbitrary raw disk reads and writes, leading to sensitive information disclosure, denial of service, or local privilege escalation.

Improper Privilege Management
WAF: Low

CVE-2025-53914

UNKNOWN
0.00 CVSS none

Excessive Privileges vulnerability in Calix GigaCenter ONT (Broadcom SoC modules) allows Privilege Abuse.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE, 812G, 813G, 818G.

Improper Privilege Management
WAF: Low

CVE-2025-53913

UNKNOWN
0.00 CVSS none

Excessive Privileges vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows Privilege Abuse.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE, 812G, 813G, 818G.

Improper Privilege Management
WAF: Low

CVE-2025-52915

UNKNOWN
0.00 CVSS none

K7RKScan.sys 23.0.0.10, part of the K7 Security Anti-Malware suite, allows an admin-privileged user to send crafted IOCTL requests to terminate processes that are protected through a third-party implementation. This is caused by insufficient caller validation in the driver's IOCTL handler, enabling unauthorized processes to perform those actions in kernel space. Successful exploitation can lead to denial of service by disrupting critical third-party services or applications.

Improper Privilege Management
WAF: Low

CVE-2025-40594

CRITICAL
9.80 CVSS 3.1

A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions < V6.4 HF7), SINAMICS S210 V6.4 (All versions < V6.4 HF2). The affected devices allow a factory reset to be executed without the required privileges due to improper privilege management as well as manipulation of configuration data because of leaked privileges of previous sessions. This could allow an unauthorized attacker to escalate their privileges.

Improper Privilege Management
WAF: Low

CVE-2025-43722

UNKNOWN
0.00 CVSS none

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper privilege management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.

Improper Privilege Management
WAF: Low

CVE-2025-32345

UNKNOWN
0.00 CVSS none

In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's deceptive app scanning setting due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Improper Privilege Management
WAF: Low

CVE-2025-26462

HIGH
7.80 CVSS 3.1

In AccessibilityServiceConnection.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Improper Privilege Management
WAF: Low

CVE-2025-26435

HIGH
7.80 CVSS 3.1

In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's deceptive app scanning setting due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Improper Privilege Management
WAF: Low

CVE-2025-36904

UNKNOWN
0.00 CVSS none

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396458384.

Improper Privilege Management
WAF: Low

CVE-2025-36901

UNKNOWN
0.00 CVSS none

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396462223.

Improper Privilege Management
WAF: Low

CVE-2025-36896

UNKNOWN
0.00 CVSS none

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-394765106.

Improper Privilege Management
WAF: Low

CVE-2025-36891

UNKNOWN
0.00 CVSS none

Elevation of privilege

Improper Privilege Management
WAF: Low

CVE-2025-36890

UNKNOWN
0.00 CVSS none

Elevation of Privilege

Improper Privilege Management
WAF: Low

CVE-2025-32098

UNKNOWN
0.00 CVSS none

An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve Elevation of Privileges to SYSTEM by exploiting insecure file delete operations during the update process.

Improper Privilege Management
WAF: Low

CVE-2024-46916

UNKNOWN
0.00 CVSS none

Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical system files before the filesystem is properly mounted (e.g., leveraging a delete call in /etc/rc.d/init.d/mountfs to remove the /etc/fstab file). This can allow code execution and, in some versions, enable recovery of TPM Disk Encryption keys and decryption of the Windows system partition.

Improper Privilege Management
WAF: Low

CVE-2025-57759

UNKNOWN
0.00 CVSS none

Contao is an Open Source CMS. In versions starting from 5.3.0 and prior to 5.3.38 and 5.6.1, under certain conditions, back end users may be able to edit fields of pages and articles without having the necessary permissions. This issue has been patched in versions 5.3.38 and 5.6.1. There are no workarounds.

Improper Privilege Management
WAF: Low

CVE-2025-55582

UNKNOWN
0.00 CVSS none

D-Link DCS-825L firmware v1.08.01 contains a vulnerability in the watchdog script `mydlink-watch-dog.sh`, which blindly respawns binaries such as `dcp` and `signalc` without verifying integrity, authenticity, or permissions. An attacker with local filesystem access (via physical access, firmware modification, or debug interfaces) can replace these binaries with malicious payloads. The script executes these binaries as root in an infinite loop, leading to persistent privilege escalation and arbitrary code execution. This issue is mitigated in v1.09.02, but the product is officially End-of-Life and unsupported.

Improper Privilege Management
WAF: Low

CVE-2025-53105

UNKNOWN
0.00 CVSS none

GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 10.0.0 to before 10.0.19, a connected user without administration rights can change the rules execution order. This issue has been patched in version 10.0.19.

Improper Privilege Management
WAF: Low

CVE-2025-36729

UNKNOWN
0.00 CVSS none

A non-primary administrator user with admin rights to the web interface but without shell access permissions can display configuration of the device including the master admin password. This vulnerability also allows the user to give themselves shell access with the root gid.

Improper Privilege Management
WAF: Low

CVE-2025-6366

UNKNOWN
0.00 CVSS none

The Event List plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0.4. This is due to the plugin not properly validating a user's capabilities prior to updating their profile in the el_update_profile() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change their capabilities to those of an administrator.

Improper Privilege Management
WAF: Low

CVE-2024-47853

HIGH
8.80 CVSS 3.1

An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases when logging into Mahara with Learning Tools Interoperability (LTI).

Improper Privilege Management
WAF: Low

CVE-2025-5931

UNKNOWN
0.00 CVSS none

The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.5. This is due to the plugin not properly validating a user's identity prior to updating their password during a staff password reset. This makes it possible for authenticated attackers, with vendor-level access and above, to elevate their privilege to the level of a staff member and then change arbitrary user passwords, including those of administrators in order to gain access to their accounts. By default, the plugin allows customers to become vendors.

Improper Privilege Management
WAF: Low

CVE-2025-57760

UNKNOWN
0.00 CVSS none

Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exists in Langflow containers where an authenticated user with RCE access can invoke the internal CLI command langflow superuser to create a new administrative user. This results in full superuser access, even if the user initially registered through the UI as a regular (non-admin) account. A patched version has not been made public at this time.

Improper Privilege Management
WAF: Low

CVE-2025-55581

UNKNOWN
0.00 CVSS none

D-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-watch-dog.sh script. The script monitors and respawns the `dcp` and `signalc` binaries without validating their integrity, origin, or permissions. An attacker with filesystem access (e.g., via UART or firmware modification) may replace these binaries to achieve persistent arbitrary code execution with root privileges. The issue stems from improper handling of executable trust and absence of integrity checks in the watchdog logic.

Improper Privilege Management
WAF: Low

CVE-2025-55627

UNKNOWN
0.00 CVSS none

Insufficient privilege verification in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allows authenticated attackers to create accounts with elevated privileges.

Improper Privilege Management
WAF: Low

CVE-2025-50674

UNKNOWN
0.00 CVSS none

An issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user.inc in OpenMediaVault 7.4.17 allowing local authenticated attackers to escalate privileges to root.

Improper Input Validation Improper Privilege Management
WAF: Medium

CVE-2025-8309

UNKNOWN
0.00 CVSS none

There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus products by Zohocorp. This vulnerability impacts Asset Explorer versions before 7710, ServiceDesk Plus versions before 15110, ServiceDesk Plus MSP versions before 14940, and SupportCenter Plus versions before 14940.

Improper Privilege Management
WAF: Low

CVE-2025-6182

UNKNOWN
0.00 CVSS none

The StrongDM Windows service incorrectly handled communication related to system certificate management. Attackers could exploit this behavior to install untrusted root certificates or remove trusted ones.

Improper Privilege Management
WAF: Low

CVE-2025-8453

UNKNOWN
0.00 CVSS none

CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation and arbitrary code execution when a privileged engineer user with console access modifies a configuration file used by a root-level daemon to execute custom scripts.

Improper Privilege Management
WAF: Low

CVE-2025-8218

UNKNOWN
0.00 CVSS none

The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'change_role_member' parameter in all versions up to, and including, 3.5. This is due to a lack of restriction in the profile update role. This makes it possible for unauthenticated attackers to arbitrarily choose their role, including the Administrator role, during a profile update.

Improper Privilege Management
WAF: Low

CVE-2025-6758

UNKNOWN
0.00 CVSS none

The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' function in all versions up to, and including, 3.6. This is due to a lack of restriction in the registration role. This makes it possible for unauthenticated attackers to arbitrarily choose their role, including the Administrator role, during user registration.

Improper Privilege Management
WAF: Low

CVE-2025-6080

UNKNOWN
0.00 CVSS none

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized admin account creation in all versions up to, and including, 67.7.0. This is due to the plugin not properly validating a user's capabilities prior to adding users. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new users, including admins.

Improper Privilege Management
WAF: Low

CVE-2025-27847

UNKNOWN
0.00 CVSS none

In ESPEC North America Web Controller 3 before 3.3.8, /api/v4/auth/ users session privileges are not revoked on logout.

Improper Privilege Management
WAF: Low

CVE-2025-27846

UNKNOWN
0.00 CVSS none

In ESPEC North America Web Controller 3 before 3.3.8, an attacker with physical access can gain elevated privileges because GRUB and the BIOS are unprotected.

Improper Privilege Management
WAF: Low

CVE-2025-49758

UNKNOWN
0.00 CVSS none

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Improper Privilege Management
WAF: Low
Page 5 of 51 (2537 CVEs)