VYPR

CWE-266

Incorrect Privilege Assignment

BaseDraft

Description

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

CVEs mapped to this weakness (1,068)

page 31 of 54
  • CVE-2025-2121MedMar 9, 2025
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in Thinkware Car Dashcam F800 Pro up to 20250226. Affected is an unknown function of the component File Storage. The manipulation leads to improper access controls. The attack can only be done within the local network. The…

  • CVE-2025-1847MedMar 3, 2025
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.…

  • CVE-2025-0849MedJan 30, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability classified as critical has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /edit-staff/ of the component Staff Handler. The manipulation leads to improper authorization. It is possible to launch the attack…

  • CVE-2025-0783MedJan 28, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability, which was classified as problematic, was found in pankajindevops scale up to 20241113. This affects an unknown part of the component API Endpoint. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. This product…

  • CVE-2024-13211MedJan 9, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in SingMR HouseRent 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file src/main/java/com/house/wym/controller/AdminController.java. The manipulation leads to improper access controls. The attack may be…

  • CVE-2024-12235MedDec 5, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 1.0.0. It has been declared as critical. Affected by this vulnerability is the function doFilter of the file \agile-bpm-basic-master\ab-auth\ab-auth-spring-security-oauth2\src\main\java\com…

  • CVE-2024-11485MedNov 20, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability, which was classified as critical, has been found in Code4Berry Decoration Management System 1.0. Affected by this issue is some unknown functionality of the file /decoration/admin/userregister.php of the component User Handler. The manipulation leads to…

  • CVE-2024-11484MedNov 20, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability classified as critical was found in Code4Berry Decoration Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /decoration/admin/update_image.php of the component User Image Handler. The manipulation of the argument…

  • CVE-2024-47595MedNov 12, 2024
    risk 0.41cvss 6.3epss 0.00

    An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation the attacker could cause high impact on confidentiality and integrity of the application.

  • CVE-2024-10766MedNov 4, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in Codezips Free Exam Hall Seating Management System 1.0. This issue affects some unknown processing of the file /pages/save_user.php. The manipulation of the argument image leads to unrestricted upload. The…

  • CVE-2024-10765MedNov 4, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical was found in Codezips Online Institute Management System up to 1.0. This vulnerability affects unknown code of the file /profile.php. The manipulation of the argument old_image leads to unrestricted upload. The attack can be initiated…

  • CVE-2024-10764MedNov 4, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in Codezips Online Institute Management System 1.0. This affects an unknown part of the file /pages/save_user.php. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack…

  • CVE-2024-46540MedSep 30, 2024
    risk 0.41cvss 6.3epss 0.01

    A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attackers to use remote file downloads and self-extract fucntions to upload webshells to the target server, thereby obtaining system privileges.

  • CVE-2024-9082MedSep 22, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=save of the component User Creation Handler. The manipulation of the argument Type with the…

  • CVE-2024-0085MedJun 13, 2024
    risk 0.41cvss 6.3epss 0.00

    NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged operations on the host. A successful exploit of this vulnerability might lead to data tampering, escalation of privileges, and denial of service.

  • CVE-2024-25083MedFeb 16, 2024
    risk 0.41cvss 6.3epss 0.00

    An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1. When an low-privileged user initiates a repair, there is an attack vector through which the user is able to execute any program with elevated privileges.

  • CVE-2022-4281MedDec 5, 2022
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in Facepay 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /face-recognition-php/facepay-master/camera.php. The manipulation of the argument userId leads to authorization bypass. The attack can…

  • CVE-2022-4276MedDec 3, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in House Rental System and classified as critical. Affected by this issue is some unknown functionality of the file tenant-engine.php of the component POST Request Handler. The manipulation of the argument id_photo leads to unrestricted upload. The…

  • CVE-2022-4272MedDec 3, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in FeMiner wms. Affected by this issue is some unknown functionality of the file /product/savenewproduct.php?flag=1. The manipulation of the argument upfile leads to unrestricted upload. The attack may be launched…

  • CVE-2022-3944MedNov 11, 2022
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in jerryhanjj ERP. It has been declared as critical. Affected by this vulnerability is the function uploadImages of the file application/controllers/basedata/inventory.php of the component Commodity Management. The manipulation leads to unrestricted…