A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
1,014 vulnerabilities with CWE-266
CVE-2026-12780
HIGH
AOMEI Backupper Kernel Driver amwrtdrv.sys access control
CVSS 7.8
CVE-2026-12779
HIGH
AOMEI Dynamic Disk Manager Kernel Driver ddmdrv.sys access control
CVSS 7.8
CVE-2026-12778
HIGH
AOMEI Partition Assistant Kernel Driver ampa10.sys access control
CVSS 7.8
CVE-2026-12771
MEDIUM
BerriAI litellm M2M JWT user_api_key_auth.py improper authorization
CVSS 5.0
CVE-2026-12770
MEDIUM
BerriAI litellm Admin Key key_management_endpoints.py improper authorization
CVSS 5.4
CVE-2026-12529
HIGH
SourceCodester CET Automated Grading System with AI Predictive Analytics Student Self-Registration Endpoint index.php access control
CVSS 7.3
CVE-2026-54807
CRITICAL
WordPress Registration Form for WooCommerce plugin <= 1.0.9 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-54805
HIGH
WordPress Falang multilanguage plugin <= 1.4.2 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-54196
MEDIUM
WordPress JetFormBuilder plugin <= 3.6.1 - Privilege Escalation vulnerability
CVSS 6.8
CVE-2026-49058
CRITICAL
WordPress LoginPress Pro plugin <= 6.2.2 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-39546
HIGH
WordPress MultiLoca plugin <= 4.2.15 - Privilege Escalation vulnerability
CVSS 7.6
CVE-2026-27395
CRITICAL
WordPress Support Board plugin < 3.8.9 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-53862
MEDIUM
OpenClaw < 2026.5.12 - Bootstrap Token Replay via Pending Pairing Scope Widening
CVSS 4.2
CVE-2026-53847
MEDIUM
OpenClaw < 2026.5.6 - Privilege Escalation via Active Memory Write Scope
CVSS 5.4
CVE-2026-12294
CRITICAL
Sandbox escape in the DOM: Workers component
CVSS 9.6
CVE-2026-12289
HIGH
Privilege escalation in the Graphics: WebRender component
CVSS 8.8
CVE-2026-49780
HIGH
WordPress Dokan plugin <= 5.0.2 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-49083
HIGH
WordPress LatePoint plugin <= 5.5.1 - Privilege Escalation vulnerability
CVSS 7.5
CVE-2026-49063
HIGH
WordPress Listdom plugin <= 5.5.0 - Privilege Escalation vulnerability
CVSS 7.3
CVE-2026-48889
HIGH
WordPress Amelia plugin <= 2.3 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-39587
HIGH
WordPress WP BASE Booking plugin <= 5.9.0 - Privilege Escalation vulnerability
CVSS 8.1
CVE-2026-39583
CRITICAL
WordPress Datalogics Ecommerce Delivery plugin <= 2.6.62 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-39579
HIGH
WordPress B Blocks plugin <= 2.0.31 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-39470
HIGH
WordPress WooCommerce Cart Abandonment Recovery plugin < 2.1.0 - Privilege Escalation vulnerability
CVSS 7.2
CVE-2026-34901
CRITICAL
WordPress iControlWP plugin <= 5.5.3 - Privilege Escalation vulnerability
CVSS 9.8
Details
Vulnerabilities
1,014