CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

815 vulnerabilities with CWE-266
CVE-2025-11281 MEDIUM
Frappe LMS 2.35.0 - Info Disclosure
CVSS 5.0
CVE-2025-11272 MEDIUM
SeriaWei ZKEACMS <4.3 - Auth Bypass
CVSS 5.4
CVE-2025-10725 CRITICAL
Red Hat Openshift AI Service - Privilege Escalation
CVSS 9.9
CVE-2025-11080 MEDIUM
zhuimengshaonian wisdom-education <1.0.4 - Auth Bypass
CVSS 4.3
CVE-2025-11050 MEDIUM
Portabilis i-Educar <2.10 - Privilege Escalation
CVSS 6.3
CVE-2025-11049 MEDIUM
Portabilis i-Educar <2.10 - Auth Bypass
CVSS 6.3
CVE-2025-59945 HIGH
Syslifters Sysreptor < 2025.83 - Incorrect Privilege Assignment
CVSS 8.1
CVE-2025-11048 MEDIUM
Portabilis i-Educar <2.10 - Info Disclosure
CVSS 6.3
CVE-2025-11047 MEDIUM
Portabilis i-Educar <2.10 - Auth Bypass
CVSS 6.3
CVE-2025-11030 HIGH
Tutorials-Website Employee Management System <611887d8f8375271ce8ab...
CVSS 7.3
CVE-2025-10992 MEDIUM
roncoo-pay <9428382af21cd5568319eae7429b7e1d0332ff40 - Auth Bypass
CVSS 5.3
CVE-2025-10989 MEDIUM
RuoYi <4.8.1 - Auth Bypass
CVSS 6.3
CVE-2025-10988 MEDIUM
YunaiV ruoyi-vue-pro <2025.09 - Auth Bypass
CVSS 6.3
CVE-2025-10987 MEDIUM
YunaiV yudao-cloud <2025.09 - Auth Bypass
CVSS 6.3
CVE-2025-10981 MEDIUM
JeecgBoot <3.8.2 - Info Disclosure
CVSS 4.3
CVE-2025-10980 MEDIUM
JeecgBoot <3.8.2 - Info Disclosure
CVSS 4.3
CVE-2025-10979 MEDIUM
JeecgBoot <3.8.2 - Auth Bypass
CVSS 4.3
CVE-2025-10978 MEDIUM
JeecgBoot <3.8.2 - Auth Bypass
CVSS 4.3
CVE-2025-10977 LOW
Jeecg Boot < 3.8.2 - Improper Authorization
CVSS 3.1
CVE-2025-10976 LOW
Jeecg Boot < 3.8.2 - Improper Authorization
CVSS 3.1
CVE-2025-10941 HIGH
Topaz SERVCore Teller <2.14.1 - Privilege Escalation
CVSS 7.8
CVE-2025-10822 MEDIUM
Fuyang Lipengjun Platform - Improper Authorization
CVSS 4.3
CVE-2025-10821 MEDIUM
Fuyang Lipengjun Platform - Improper Authorization
CVSS 4.3
CVE-2025-10820 MEDIUM
Fuyang Lipengjun Platform - Improper Authorization
CVSS 4.3
CVE-2025-10819 MEDIUM
Fuyang Lipengjun Platform - Improper Authorization
CVSS 4.3
Details
Vulnerabilities 815