A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
917 vulnerabilities with CWE-266
CVE-2025-8261
HIGH
Vaelsys VaelsysV4 4.1.0 - Unauthenticated User Creation via vgrid_server.php
CVSS 7.3
CVE-2025-8181
HIGH
TOTOLINK N600R/X2000R 1.0.0.1 - Privilege Escalation
CVSS 7.2
CVE-2025-31513
MEDIUM
AlertEnterprise Guardian <4.1.14.2.2.1 - Privilege Escalation
CVSS 6.5
CVE-2025-7947
MEDIUM
jshERP < 3.5 - Improper Authorization via Account Handler ID Parameter
CVSS 5.4
CVE-2025-44655
CRITICAL
TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9 - Privilege Escalation via vsftpd chroot_local_user Misconfiguration
CVSS 9.8
CVE-2025-52836
CRITICAL
Unity Business Technology Pty Ltd The E-Commerce ERP <2.1.1.3 - Pri...
CVSS 9.8
CVE-2025-34112
CRITICAL
Riverbed SteelCentral NetProfiler & NetExpress <10.8.7 - RCE
CVE-2025-7576
HIGH
Teledyne FLIR FB- and FH-Series 1.3.2.16 - Improper Access Controls
CVSS 7.3
CVE-2025-7552
MEDIUM
Dromara Northstar <7.3.5 - Improper Access Controls
CVSS 6.3
CVE-2025-0140
MEDIUM
Palo Alto Networks GlobalProtect App - Privilege Escalation
CVE-2025-0139
MEDIUM
Palo Alto Networks Autonomous Digital Experience Manager - Privileg...
CVE-2025-27028
MEDIUM
Radiflow iSAP Smart Collector <1.20 - Info Disclosure
CVSS 6.8
CVE-2025-47422
HIGH
Advanced Installer <22.6 - Privilege Escalation
CVSS 7.5
CVE-2025-43001
MEDIUM
SAPCAR >= 7.53 < 7.53, >= 7.22EXT < 7.22EXT - Privilege Escalation via Archive Extraction
CVSS 6.9
CVE-2025-42992
MEDIUM
SAPCAR 7.22EXT-7.53 - Privilege Escalation via Malicious SAR Archive
CVSS 6.9
CVE-2025-7076
MEDIUM
BlackVue Dashcam 590X < 2025-06-24 - Unauthenticated Improper Access Control in Configuration Handler
CVSS 5.4
CVE-2025-49867
CRITICAL
RealHomes <= 4.4.0 - Privilege Escalation via Incorrect Privilege Assignment
CVSS 9.8
CVE-2025-23970
CRITICAL
aonetheme Service Finder Booking <6.0 - Privilege Escalation
CVSS 9.8
CVE-2025-27021
HIGH
Infinera G42 R6.1.3 - Privilege Escalation
CVSS 7.0
CVE-2025-45006
CRITICAL
Open-Source RISC-V Processor <f517abb - Memory Corruption
CVSS 9.1
CVE-2025-6765
MEDIUM
Intelbras InControl 2.21.60.9 - Incorrect Privilege Assignment via /v1/operador/ HTTP PUT Request
CVSS 6.3
CVE-2025-52726
HIGH
Pebas CouponXxL Custom Post Types <3.0 - Privilege Escalation
CVSS 8.6
CVE-2025-6736
MEDIUM
juzaweb CMS 3.4.2 - Incorrect Privilege Assignment in Add New Themes Page
CVSS 6.3
CVE-2025-6735
MEDIUM
juzaweb CMS 3.4.2 - Improper Authorization in Import Page
CVSS 6.3
CVE-2025-6702
MEDIUM
linlinjava litemall 1.8.0 - Incorrect Privilege Assignment via wx/comment/post adminComment Parameter
CVSS 4.3
Details
Vulnerabilities
917