A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
926 vulnerabilities with CWE-266
CVE-2022-4232
MEDIUM
SourceCodester Event Registration System 1.0 - Unrestricted File Upload via cmd Argument
CVSS 4.7
CVE-2022-3944
MEDIUM
ERP - Unrestricted File Upload in Commodity Management
CVSS 6.3
CVE-2022-3826
MEDIUM
Huaxia ERP - Information Disclosure via Retail Management Search Parameter
CVSS 4.3
CVE-2022-42825
MEDIUM
iPadOS < 16.0 - Unauthorized File System Modification via Entitlement Misconfiguration
CVSS 5.5
CVE-2022-3771
MEDIUM
easyiicms - Unrestricted File Upload in Upload.php File Helper
CVSS 6.3
CVE-2022-3770
MEDIUM
Yunjing CMS - Unrestricted File Upload via /index/user/upload_img.html
CVSS 6.3
CVE-2022-3735
MEDIUM
ehoney - Incorrect Privilege Assignment in /api/public/signup
CVSS 6.3
CVE-2022-3549
MEDIUM
SourceCodester Simple Cold Storage Management System 1.0 - Unrestri...
CVSS 4.7
CVE-2022-3496
MEDIUM
SourceCodester Human Resource Management System 1.0 - Incorrect Privilege Assignment in Admin Panel
CVSS 6.3
CVE-2022-3458
MEDIUM
SourceCodester Human Resource Management System 1.0 - Unrestricted File Upload in Image File Handler
CVSS 6.3
CVE-2022-3436
MEDIUM
Web-Based Student Clearance System 1.0 - Unrestricted File Upload in Photo Handler
CVSS 6.3
CVE-2022-2637
MEDIUM
Hitachi Storage Plug-in for VMware vCenter 04.8.0-04.8.9 - Authenticated Privilege Escalation
CVSS 5.4
CVE-2022-20855
HIGH
Cisco IOS XE for Embedded Wireless Controllers - Authenticated OS Command Injection via Self-Healing Functionality
CVSS 7.9
CVE-2022-2626
HIGH
GitHub hestiacp/hestiacp <1.6.6 - Privilege Escalation
CVSS 7.2
CVE-2022-1746
HIGH
Dominion Voting Systems ImageCast X - Incorrect Privilege Assignment
CVSS 7.6
CVE-2022-20819
MEDIUM
Cisco Identity Services Engine - Authenticated Sensitive Information Exposure via Web Management Interface
CVSS 6.5
CVE-2022-20759
HIGH
Cisco ASA/FTD - Privilege Escalation
CVSS 8.8
CVE-2022-20681
HIGH
Cisco IOS XE - Privilege Escalation
CVSS 7.8
CVE-2022-20782
MEDIUM
Cisco Identity Services Engine - Authenticated Sensitive Information Exposure via Web Interface
CVSS 6.5
CVE-2022-1225
MEDIUM
phpipam < 1.4.6 - Incorrect Privilege Assignment
CVSS 6.5
CVE-2021-47799
MEDIUM
Visual Tools DVR VX16 <4.2.28 - Privilege Escalation
CVSS 6.2
CVE-2021-47241
HIGH
Linux Kernel - Incorrect Privilege Assignment in Ethtool String Set Message Length Calculation
CVSS 7.5
CVE-2021-40124
MEDIUM
Cisco Anyconnect Secure Mobility Client < 4.10.03104 - Improper Privilege Management
CVSS 6.7
CVE-2021-40123
MEDIUM
Cisco Identity Services Engine - Authenticated Arbitrary File Download via Web Interface
CVSS 4.3
CVE-2021-36097
LOW
OTRS <8.0.16 - Privilege Escalation
CVSS 3.5
Details
Vulnerabilities
926