A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
914 vulnerabilities with CWE-266
CVE-2025-36007
HIGH
IBM QRadar SIEM 7.5-7.5.0 Update Pack 13 Independent Fix 02 - Privilege Escalation via Update Script
CVSS 7.8
CVE-2025-12304
MEDIUM
TIME-SEA-PLUS <fb299162f18498dd9cf17da906886d80a077d53b - Auth Bypass
CVSS 4.3
CVE-2025-62007
HIGH
bPlugins Voice Feedback <=1.0.3 - Privilege Escalation
CVSS 8.8
CVE-2025-60222
HIGH
SUMO Memberships for WooCommerce <= 7.6.0 - Privilege Escalation
CVSS 8.8
CVE-2025-60220
CRITICAL
CouponXxL <3.0.0 - Privilege Escalation
CVSS 9.8
CVE-2025-60211
HIGH
extendons WooCommerce Registration Fields Plugin - Custom Signup Fi...
CVSS 8.8
CVE-2025-59580
HIGH
Goodlayers Core < 2.1.7 - Privilege Escalation
CVSS 8.8
CVE-2025-53428
HIGH
N-Media Simple User Registration <6.4 - Privilege Escalation
CVSS 8.8
CVE-2025-53425
HIGH
Dokan <4.1.2 - Privilege Escalation
CVSS 7.2
CVE-2025-49924
HIGH
Wholesale Suite <2.2.4.2 - Privilege Escalation
CVSS 7.2
CVE-2025-48082
HIGH
Progress Planner <= 1.8.0 - Privilege Escalation
CVSS 8.8
CVE-2025-62645
CRITICAL
Restaurant Brands International Assistant < 2025-09-06 Privilege Escalation via GraphQL
CVSS 9.9
CVE-2025-11853
MEDIUM
Sismics Teedy < 1.11 - Improper Access Control in API Endpoint
CVSS 6.3
CVE-2025-10577
HIGH
HP Sound Research SECOMN64 Driver - Incorrect Privilege Assignment
CVE-2025-10576
HIGH
HP Sound Research SECOMN64 Driver - Incorrect Privilege Assignment
CVE-2025-10038
MEDIUM
Binary MLM Plan <3.0 - Privilege Escalation
CVSS 6.5
CVE-2025-11646
MEDIUM
Furbo 360 Dog Camera Firmware < 036 and Furbo Mini Firmware < 074 - Improper Access Controls in GATT Service
CVSS 6.3
CVE-2025-11641
LOW
Furbo 360 Dog Camera Firmware < 036 and Furbo Mini Firmware < 074 - Improper Access Control in Trial Restriction Handler
CVSS 3.9
CVE-2025-11554
MEDIUM
Portabilis i-Educar <2.9.10 - Privilege Escalation
CVSS 6.3
CVE-2025-11440
MEDIUM
JhumanJ OpnForm <1.9.3 - Improper Access Controls
CVSS 4.3
CVE-2025-61785
LOW
Deno < 2.2.15 and 2.3.0-2.5.2 - Incorrect Privilege Assignment via FsFile utime Methods
CVSS 3.3
CVE-2025-43914
HIGH
Dell PowerProtect Data Domain BoostFS Incorrect Privilege Assignment
CVSS 7.5
CVE-2025-11281
MEDIUM
Frappe LMS 2.35.0 - Info Disclosure
CVSS 5.0
CVE-2025-11272
MEDIUM
SeriaWei ZKEACMS <4.3 - Auth Bypass
CVSS 5.4
CVE-2025-10725
CRITICAL
Red Hat Openshift AI Service - Privilege Escalation
CVSS 9.9
Details
Vulnerabilities
914