A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
917 vulnerabilities with CWE-266
CVE-2025-3305
MEDIUM
IKUN_Library 1.0 - Improper Access Controls
CVSS 4.3
CVE-2025-3298
MEDIUM
SourceCodester Online Eyewear Shop 1.0 - Info Disclosure
CVSS 4.3
CVE-2025-3256
MEDIUM
xujiangfei admintwo 1.0 - Improper Access Controls
CVSS 6.3
CVE-2025-3255
MEDIUM
xujiangfei admintwo 1.0 - Improper Access Controls
CVSS 4.3
CVE-2025-31420
HIGH
Tomdever wpForo Forum <2.4.2 - Privilege Escalation
CVSS 7.6
CVE-2025-3237
MEDIUM
Tenda FH1202 1.2.0.14(408) - Info Disclosure
CVSS 5.3
CVE-2025-3236
MEDIUM
Tenda FH1202 1.2.0.14(408) - Info Disclosure
CVSS 5.3
CVE-2025-3202
HIGH
ageerle ruoyi-ai < 2.0.1 - Improper Authorization in SysNoticeController
CVSS 7.3
CVE-2025-3199
HIGH
ruoyi-ai < 2.0.2 - Unauthenticated Improper Authorization in SysModelController
CVSS 7.3
CVE-2025-31560
HIGH
Salonbookingsystem Salon Booking System < 10.11 - Incorrect Privilege Assignment
CVSS 7.2
CVE-2025-29036
MEDIUM
hackathon-starter <8.1.0 - Privilege Escalation
CVSS 5.9
CVE-2025-27095
MEDIUM
JumpServer <4.8.0, 3.10.18 - Privilege Escalation
CVSS 4.3
CVE-2025-2996
MEDIUM
Tenda FH1202 1.2.0.14(408) - Info Disclosure
CVSS 5.3
CVE-2025-2995
MEDIUM
Tenda FH1202 1.2.0.14(408) - Info Disclosure
CVSS 5.3
CVE-2025-2994
MEDIUM
Tenda FH1202 1.2.0.14(408) - Info Disclosure
CVSS 5.3
CVE-2025-2993
MEDIUM
Tenda FH1202 1.2.0.14(408) - Info Disclosure
CVSS 5.3
CVE-2025-2992
MEDIUM
Tenda FH1202 1.2.0.14(408 - Improper Access Controls
CVSS 5.3
CVE-2025-2991
MEDIUM
Tenda FH1202 1.2.0.14(408) - Info Disclosure
CVSS 5.3
CVE-2025-2990
MEDIUM
Tenda FH1202 1.2.0.14(408) - Info Disclosure
CVSS 5.3
CVE-2025-2989
MEDIUM
Tenda FH1202 1.2.0.14(408) - Info Disclosure
CVSS 5.3
CVE-2025-2955
MEDIUM
TOTOLINK A3000RU <5.9c.5185 - Improper Access Controls
CVSS 5.3
CVE-2025-2954
LOW
mannaandpoem OpenManus <2025.3.13 - Improper Access Controls
CVSS 3.3
CVE-2025-2713
HIGH
gVisor < 20240325.0 - Local Privilege Escalation via File Access Permission Mishandling
CVSS 7.8
CVE-2025-26512
CRITICAL
SnapCenter < 6.0.1P1 and < 6.1P1 - Authenticated Privilege Escalation to Admin via Plug-in
CVSS 9.9
CVE-2025-2688
MEDIUM
TOTOLINK A3000RU <5.9c.5185 - Improper Access Controls
CVSS 4.3
Details
Vulnerabilities
917