CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

917 vulnerabilities with CWE-266
CVE-2025-39542 HIGH
Jauhari Xelion Xelion Webchat <9.1.0 - Privilege Escalation
CVSS 8.8
CVE-2025-32648 CRITICAL
Projectopia <5.1.16 - Privilege Escalation
CVSS 9.8
CVE-2025-3675 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setL2tpServerCfg
CVSS 5.3
CVE-2025-3674 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setUrlFilterRules Function
CVSS 5.3
CVE-2025-3668 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setScheduleCfg Function
CVSS 5.3
CVE-2025-3667 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setUPnPCfg Function
CVSS 5.3
CVE-2025-3666 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setDdnsCfg Function
CVSS 5.3
CVE-2025-3665 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setSmartQosCfg
CVSS 5.3
CVE-2025-3664 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setWiFiEasyGuestCfg
CVSS 5.3
CVE-2025-3663 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in Password Handler
CVSS 5.3
CVE-2025-3587 MEDIUM
ZeroWdd studentmanager 1.0 - Improper Authorization via /getTeacherList
CVSS 6.3
CVE-2025-3569 MEDIUM
JamesZBL db-hospital-drug 1.0 - Improper Authorization in ShiroConfig.java
CVSS 6.3
CVE-2025-3567 MEDIUM
Echo 4.2 - Incorrect Privilege Assignment in LoginTicketInterceptor
CVSS 4.3
CVE-2025-3564 MEDIUM
huanfenz StudentManager <= 1.0 - Improper Authorization in Teacher String Handler
CVSS 4.3
CVE-2025-3550 MEDIUM
wowjoy Internet Doctor Workstation System 1.0 - Info Disclosure
CVSS 4.3
CVE-2025-3537 MEDIUM
Tutorials-Website Employee Management System 1.0 - Improper Authorization via ID Parameter in /admin/update-user.php
CVSS 5.3
CVE-2025-3536 MEDIUM
Tutorials-Website Employee Management System 1.0 - Improper Authorization in Delete User Function
CVSS 6.5
CVE-2025-23391 CRITICAL
Rancher 2.8.0-2.8.13, 2.9.0-2.9.7, 2.10.0-2.10.3 - Authenticated Privilege Escalation via Administrator Password Change
CVSS 9.1
CVE-2025-32491 CRITICAL
Rankology SEO <2.2.3 - Privilege Escalation
CVSS 9.8
CVE-2025-31524 HIGH
NotFound WP User Profiles <2.6.2 - Privilege Escalation
CVSS 8.8
CVE-2025-32695 CRITICAL
Mestres do WP Checkout Mestres WP <8.7.5 - Privilege Escalation
CVSS 9.8
CVE-2025-25023 MEDIUM
IBM Security Guardium <12.1 - Info Disclosure
CVSS 4.9
CVE-2025-23407 MEDIUM
Wi-Fi AP UNIT AC-WPS-11ac - Privilege Escalation
CVSS 4.3
CVE-2025-3398 MEDIUM
Lenve VBlog <1.0.0 - Improper Access Controls
CVSS 6.3
CVE-2025-3325 MEDIUM
iteaj iboot 1.1.3 - Improper Access Control in Admin Password Handler
CVSS 4.3
Details
Vulnerabilities 917