A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
926 vulnerabilities with CWE-266
CVE-2024-9180
HIGH
OpenBao < 2.0.3 and Vault 1.17.7-1.17.6, 1.18.0-1.17.9, <1.18.0 - Privilege Escalation via Identity Endpoint
CVSS 7.2
CVE-2024-9519
HIGH
UserPlus < 2.0 - Authenticated Privilege Escalation via Registration Form Role Update
CVSS 7.2
CVE-2024-48941
MEDIUM
Syracom Secure Login < 3.1.4.5 - Two-Factor Authentication Bypass via /rest Endpoint
CVSS 5.4
CVE-2024-47653
MEDIUM
Shilpi Client Dashboard - Privilege Escalation
CVSS 6.5
CVE-2024-25660
CRITICAL
Nokia Transcend Network Management Sy... - Incorrect Privilege Assignment
CVSS 9.0
CVE-2024-25632
HIGH
eLabFTW <5.0.0 - Privilege Escalation
CVSS 8.6
CVE-2024-46511
HIGH
LoadZilla LLC LoadLogic <1.4.3 - RCE
CVSS 7.5
CVE-2024-46540
MEDIUM
emlog < 2.3.15 - Remote Code Execution via /admin/store.php File Download
CVSS 6.3
CVE-2024-9082
MEDIUM
SourceCodester Online Eyewear Shop 1.0 - Incorrect Privilege Assignment in User Creation Handler
CVSS 6.3
CVE-2024-22303
HIGH
Houzez <3.2.4 - Privilege Escalation
CVSS 8.8
CVE-2024-21743
HIGH
Houzez Login Register <3.2.5 - Privilege Escalation
CVSS 8.8
CVE-2024-8253
HIGH
Post Grid and Gutenberg Blocks <2.2.90 - Privilege Escalation
CVSS 8.8
CVE-2024-40681
HIGH
IBM MQ 9.1-9.4 - Authenticated Privilege Escalation via Queue Manager Security Bypass
CVSS 7.5
CVE-2024-39579
MEDIUM
Dell PowerScale OneFS 8.2.2.x-9.8.0.0 - Privilege Escalation to Root
CVSS 6.7
CVE-2024-4555
HIGH
OpenText NetIQ Access Manager < 5.0.4.1 and < 5.1 - User Account Impersonation
CVSS 7.7
CVE-2024-45187
HIGH
Mage AI - Unauthenticated Remote Code Execution via Deleted User Privilege Escalation
CVSS 7.1
CVE-2024-39576
HIGH
Dell Power Manager < 3.16.0 - Incorrect Privilege Assignment
CVSS 8.8
CVE-2024-20466
MEDIUM
Cisco Identity Services Engine - Authenticated Sensitive Information Exposure via Web Management Interface
CVSS 6.5
CVE-2024-28000
CRITICAL
WordPress LiteSpeed Cache - Unauthenticated Privilege Escalation to Admin
CVSS 9.8
CVE-2024-6322
MEDIUM
Grafana 11.1.0-11.1.1 and 11.1.2-11.1.3 - Incorrect Privilege Assignment via ReqActions Bypass
CVSS 5.4
CVE-2024-34738
HIGH
Android - Incorrect Privilege Assignment in AppOpsService
CVSS 7.8
CVE-2024-25633
MEDIUM
elabftw 4.4.0-4.9.9 - Unauthenticated Privilege Escalation via User Account Creation
CVSS 5.4
CVE-2024-42441
MEDIUM
Zoom Workplace Desktop App <6.1.5 - Privilege Escalation
CVSS 6.2
CVE-2024-43153
CRITICAL
Woffice <5.4.10 - Privilege Escalation
CVSS 9.8
CVE-2024-6758
MEDIUM
Sprecher Automation SPRECON-E <8.71j - Privilege Escalation
CVSS 6.5
Details
Vulnerabilities
926