CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

917 vulnerabilities with CWE-266
CVE-2025-3305 MEDIUM
IKUN_Library 1.0 - Improper Access Controls
CVSS 4.3
CVE-2025-3298 MEDIUM
SourceCodester Online Eyewear Shop 1.0 - Info Disclosure
CVSS 4.3
CVE-2025-3256 MEDIUM
xujiangfei admintwo 1.0 - Improper Access Controls
CVSS 6.3
CVE-2025-3255 MEDIUM
xujiangfei admintwo 1.0 - Improper Access Controls
CVSS 4.3
CVE-2025-31420 HIGH
Tomdever wpForo Forum <2.4.2 - Privilege Escalation
CVSS 7.6
CVE-2025-3237 MEDIUM
Tenda FH1202 1.2.0.14(408) - Info Disclosure
CVSS 5.3
CVE-2025-3236 MEDIUM
Tenda FH1202 1.2.0.14(408) - Info Disclosure
CVSS 5.3
CVE-2025-3202 HIGH
ageerle ruoyi-ai < 2.0.1 - Improper Authorization in SysNoticeController
CVSS 7.3
CVE-2025-3199 HIGH
ruoyi-ai < 2.0.2 - Unauthenticated Improper Authorization in SysModelController
CVSS 7.3
CVE-2025-31560 HIGH
Salonbookingsystem Salon Booking System < 10.11 - Incorrect Privilege Assignment
CVSS 7.2
CVE-2025-29036 MEDIUM
hackathon-starter <8.1.0 - Privilege Escalation
CVSS 5.9
CVE-2025-27095 MEDIUM
JumpServer <4.8.0, 3.10.18 - Privilege Escalation
CVSS 4.3
CVE-2025-2996 MEDIUM
Tenda FH1202 1.2.0.14(408) - Info Disclosure
CVSS 5.3
CVE-2025-2995 MEDIUM
Tenda FH1202 1.2.0.14(408) - Info Disclosure
CVSS 5.3
CVE-2025-2994 MEDIUM
Tenda FH1202 1.2.0.14(408) - Info Disclosure
CVSS 5.3
CVE-2025-2993 MEDIUM
Tenda FH1202 1.2.0.14(408) - Info Disclosure
CVSS 5.3
CVE-2025-2992 MEDIUM
Tenda FH1202 1.2.0.14(408 - Improper Access Controls
CVSS 5.3
CVE-2025-2991 MEDIUM
Tenda FH1202 1.2.0.14(408) - Info Disclosure
CVSS 5.3
CVE-2025-2990 MEDIUM
Tenda FH1202 1.2.0.14(408) - Info Disclosure
CVSS 5.3
CVE-2025-2989 MEDIUM
Tenda FH1202 1.2.0.14(408) - Info Disclosure
CVSS 5.3
CVE-2025-2955 MEDIUM
TOTOLINK A3000RU <5.9c.5185 - Improper Access Controls
CVSS 5.3
CVE-2025-2954 LOW
mannaandpoem OpenManus <2025.3.13 - Improper Access Controls
CVSS 3.3
CVE-2025-2713 HIGH
gVisor < 20240325.0 - Local Privilege Escalation via File Access Permission Mishandling
CVSS 7.8
CVE-2025-26512 CRITICAL
SnapCenter < 6.0.1P1 and < 6.1P1 - Authenticated Privilege Escalation to Admin via Plug-in
CVSS 9.9
CVE-2025-2688 MEDIUM
TOTOLINK A3000RU <5.9c.5185 - Improper Access Controls
CVSS 4.3
Details
Vulnerabilities 917