A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
926 vulnerabilities with CWE-266
CVE-2024-7480
MEDIUM
Avaya Aura System Manager 10.1.x.x and 10.2.x.x - Authenticated Arbitrary File Read via CLI
CVSS 4.2
CVE-2024-41139
HIGH
SKYSEA Client View 6.010.06-19.210.04e - Privilege Escalation via DLL Placement
CVSS 7.8
CVE-2024-40433
HIGH
Tencent WeChat <8.0.37 - Privilege Escalation
CVSS 8.8
CVE-2024-36534
HIGH
hwameistor <0.14.3 - Privilege Escalation
CVSS 8.4
CVE-2024-23794
MEDIUM
OTRS 8.0.X, 2023.X, 2024.X-2024.4.x - Privilege Escalation via Inline Editing Functionality
CVSS 5.2
CVE-2024-37927
CRITICAL
NooTheme Jobmonster <4.7.0 - Privilege Escalation
CVSS 9.8
CVE-2024-31315
HIGH
Android - Local Privilege Escalation via Notification Access Settings
CVSS 7.8
CVE-2024-38278
MEDIUM
RUGGEDCOM Various - Info Disclosure
CVSS 6.6
CVE-2024-37134
MEDIUM
Dell PowerScale OneFS 8.2.2-9.8.0.0 - Privilege Escalation to Root
CVSS 6.7
CVE-2024-37132
MEDIUM
Dell PowerScale OneFS 8.2.2-9.8.0.0 - Denial of Service and Privilege Escalation
CVSS 6.7
CVE-2024-31912
HIGH
IBM MQ 9.3 LTS and 9.3 CD - Authenticated Privilege Escalation via Incorrect Privilege Assignment
CVSS 7.5
CVE-2024-27275
HIGH
IBM i 7.2-7.5 - Incorrect Privilege Assignment in Physical File Trigger Configuration
CVSS 7.4
CVE-2024-0085
MEDIUM
NVIDIA vGPU < 13.11 and Cloud Gaming < 555.52.04 - Privilege Escalation
CVSS 6.3
CVE-2024-36587
HIGH
DNSCrypt-proxy <2.1.5 - Privilege Escalation
CVSS 7.8
CVE-2024-37293
HIGH
AWS Deployment Framework < 4.0.0 - Privilege Escalation via Bootstrap CodeBuild Role
CVSS 7.5
CVE-2024-35700
CRITICAL
Userpro <= 5.1.8 - Unauthenticated Account Takeover via Incorrect Privilege Assignment
CVSS 9.8
CVE-2024-4870
HIGH
Frontend Registration - Contact Form 7 <5.1 - Privilege Escalation
CVSS 7.2
CVE-2024-32959
HIGH
Sirv <= 7.2.2 - Incorrect Privilege Assignment via Arbitrary Option Update
CVSS 8.8
CVE-2024-32507
HIGH
Hamid Alinia - idehweb <1.7.16 - Privilege Escalation
CVSS 8.8
CVE-2024-24882
CRITICAL
Masteriyo LMS <= 1.7.2 - Unauthenticated Privilege Escalation
CVSS 9.8
CVE-2024-22145
HIGH
InstaWP Connect <0.1.0.8 - Privilege Escalation
CVSS 8.8
CVE-2024-20389
HIGH
Cisco ConfD/Crosswork - Privilege Escalation
CVSS 7.8
CVE-2024-31771
HIGH
TotalAV <6.0.740 - Privilege Escalation
CVSS 7.8
CVE-2024-27460
MEDIUM
Plantronics Hub <3.25.1 - Privilege Escalation
CVSS 6.7
CVE-2024-27273
HIGH
IBM AIX 7.2-7.3 and VIOS 3.1-4.1 - Privilege Escalation via Unix Domain Datagram Socket SO_PEERID Operation
CVSS 8.1
Details
Vulnerabilities
926