A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
917 vulnerabilities with CWE-266
CVE-2025-39542
HIGH
Jauhari Xelion Xelion Webchat <9.1.0 - Privilege Escalation
CVSS 8.8
CVE-2025-32648
CRITICAL
Projectopia <5.1.16 - Privilege Escalation
CVSS 9.8
CVE-2025-3675
MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setL2tpServerCfg
CVSS 5.3
CVE-2025-3674
MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setUrlFilterRules Function
CVSS 5.3
CVE-2025-3668
MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setScheduleCfg Function
CVSS 5.3
CVE-2025-3667
MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setUPnPCfg Function
CVSS 5.3
CVE-2025-3666
MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setDdnsCfg Function
CVSS 5.3
CVE-2025-3665
MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setSmartQosCfg
CVSS 5.3
CVE-2025-3664
MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setWiFiEasyGuestCfg
CVSS 5.3
CVE-2025-3663
MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in Password Handler
CVSS 5.3
CVE-2025-3587
MEDIUM
ZeroWdd studentmanager 1.0 - Improper Authorization via /getTeacherList
CVSS 6.3
CVE-2025-3569
MEDIUM
JamesZBL db-hospital-drug 1.0 - Improper Authorization in ShiroConfig.java
CVSS 6.3
CVE-2025-3567
MEDIUM
Echo 4.2 - Incorrect Privilege Assignment in LoginTicketInterceptor
CVSS 4.3
CVE-2025-3564
MEDIUM
huanfenz StudentManager <= 1.0 - Improper Authorization in Teacher String Handler
CVSS 4.3
CVE-2025-3550
MEDIUM
wowjoy Internet Doctor Workstation System 1.0 - Info Disclosure
CVSS 4.3
CVE-2025-3537
MEDIUM
Tutorials-Website Employee Management System 1.0 - Improper Authorization via ID Parameter in /admin/update-user.php
CVSS 5.3
CVE-2025-3536
MEDIUM
Tutorials-Website Employee Management System 1.0 - Improper Authorization in Delete User Function
CVSS 6.5
CVE-2025-23391
CRITICAL
Rancher 2.8.0-2.8.13, 2.9.0-2.9.7, 2.10.0-2.10.3 - Authenticated Privilege Escalation via Administrator Password Change
CVSS 9.1
CVE-2025-32491
CRITICAL
Rankology SEO <2.2.3 - Privilege Escalation
CVSS 9.8
CVE-2025-31524
HIGH
NotFound WP User Profiles <2.6.2 - Privilege Escalation
CVSS 8.8
CVE-2025-32695
CRITICAL
Mestres do WP Checkout Mestres WP <8.7.5 - Privilege Escalation
CVSS 9.8
CVE-2025-25023
MEDIUM
IBM Security Guardium <12.1 - Info Disclosure
CVSS 4.9
CVE-2025-23407
MEDIUM
Wi-Fi AP UNIT AC-WPS-11ac - Privilege Escalation
CVSS 4.3
CVE-2025-3398
MEDIUM
Lenve VBlog <1.0.0 - Improper Access Controls
CVSS 6.3
CVE-2025-3325
MEDIUM
iteaj iboot 1.1.3 - Improper Access Control in Admin Password Handler
CVSS 4.3
Details
Vulnerabilities
917