CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

926 vulnerabilities with CWE-266
CVE-2024-45331 HIGH
Fortinet FortiAnalyzer <7.4.3 - Privilege Escalation
CVSS 7.3
CVE-2024-33503 MEDIUM
FortiManager/FortiAnalyzer Privilege Escalation via Shell Command Injection
CVSS 6.7
CVE-2024-13251 HIGH
Drupal Registration <2.0.1 - Privilege Escalation
CVSS 8.8
CVE-2024-13248 MEDIUM
Drupal Private content <2.1.0 - Privilege Escalation
CVSS 5.5
CVE-2024-13211 MEDIUM
SingMR HouseRent 1.0 - Improper Access Controls
CVSS 6.3
CVE-2024-13206 HIGH
REVE Antivirus 1.0.0.0 - Info Disclosure
CVSS 7.8
CVE-2024-13200 HIGH
wander-chu SpringBoot-Blog 1.0 - Info Disclosure
CVSS 7.3
CVE-2024-13189 HIGH
ZeroWdd myblog 1.0 - Permission Issues
CVSS 7.3
CVE-2024-13188 MEDIUM
MicroWorld eScan Antivirus 7.0.32 - Info Disclosure
CVSS 5.3
CVE-2024-56280 HIGH
Amento Tech Pvt Ltd WPGuppy <1.1.0 - Privilege Escalation
CVSS 8.8
CVE-2024-49644 HIGH
AllAccessible Team Accessibility <1.3.4 - Privilege Escalation
CVSS 8.8
CVE-2024-12470 CRITICAL
SakolaWP <1.0.8 - Privilege Escalation
CVSS 9.8
CVE-2024-56513 HIGH
Karmada <1.12.0 - Privilege Escalation
CVE-2024-55542 MEDIUM
Acronis Cyber Protect <39169 & <35895 - Privilege Escalation
CVSS 4.4
CVE-2024-13109 MEDIUM
Yunfan Learning Examination System 1.9.2 - Improper Authorization in /doc.html
CVSS 5.3
CVE-2024-13108 MEDIUM
D-Link DIR-816 A2 1.10CNB05_R1B011D88210 - Improper Access Controls
CVSS 5.3
CVE-2024-13107 MEDIUM
D-Link DIR-816 A2 1.10CNB05_R1B011D88210 - Improper Access Controls
CVSS 5.3
CVE-2024-13106 MEDIUM
D-Link DIR-816 A2 1.10CNB05_R1B011D88210 - Improper Access Controls
CVSS 5.3
CVE-2024-13105 MEDIUM
D-Link DIR-816 A2 1.10CNB05_R1B011D88210 - Improper Access Controls
CVSS 5.3
CVE-2024-13104 MEDIUM
D-Link DIR-816 A2 1.10CNB05_R1B011D88210 - Improper Access Controls
CVSS 5.3
CVE-2024-13103 MEDIUM
D-Link DIR-816 A2 1.10CNB05_R1B011D88210 - Improper Access Controls
CVSS 5.3
CVE-2024-13102 MEDIUM
D-Link DIR-816 A2 1.10CNB05_R1B011D88210 - Improper Access Controls
CVSS 5.3
CVE-2024-52049 HIGH
Trend Micro Apex One - Privilege Escalation
CVSS 7.8
CVE-2024-52048 HIGH
Trend Micro Apex One - Privilege Escalation
CVSS 7.8
CVE-2024-56043 CRITICAL
VibeThemes WPLMS <= 1.9.9 - Unauthenticated Privilege Escalation
CVSS 9.8
Details
Vulnerabilities 926