VYPR

CWE-266

Incorrect Privilege Assignment

BaseDraft

Description

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

CVEs mapped to this weakness (1,068)

page 36 of 54
  • CVE-2025-2334MedMar 15, 2025
    risk 0.35cvss 5.4epss 0.01

    A vulnerability classified as problematic has been found in 274056675 springboot-openai-chatgpt e84f6f5. This affects the function deleteChat of the file /api/mjkj-chat/chat/ai/delete/chat of the component Chat History Handler. The manipulation of the argument chatListId leads…

  • CVE-2025-2218MedMar 12, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This vulnerability affects unknown code of the file /api/system/other of the component Setting Handler. The manipulation leads to improper access controls. The attack can be initiated…

  • CVE-2025-2089MedMar 7, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been found in StarSea99 starsea-mall 1.0/2.X and classified as critical. Affected by this vulnerability is the function updateUserInfo of the file /personal/updateInfo of the component com.siro.mall.controller.mall.UserController. The manipulation of the…

  • CVE-2024-55570MedMar 3, 2025
    risk 0.35cvss 5.4epss 0.00

    /api/user/users in the web GUI for the Cubro EXA48200 network packet broker (build 20231025055018) fixed in V5.0R14.5P4-V3.3R1 allows remote authenticated users of the application to increase their privileges by sending a single HTTP PUT request with rolename=Administrator, aka…

  • CVE-2025-1226MedFeb 12, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown code of the file /oa/setup/setup.jsp. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed…

  • CVE-2024-13108MedJan 2, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. It has been declared as critical. This vulnerability affects unknown code of the file /goform/form2NetSniper.cgi. The manipulation leads to improper access controls. The attack can be initiated remotely. The…

  • CVE-2024-13107MedJan 2, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. It has been classified as critical. This affects an unknown part of the file /goform/form2LocalAclEditcfg.cgi of the component ACL Handler. The manipulation leads to improper access controls. It is possible…

  • CVE-2024-13105MedJan 2, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/form2Dhcpd.cgi of the component DHCPD Setting Handler. The manipulation leads to improper access…

  • CVE-2024-13104MedJan 2, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability, which was classified as critical, was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. Affected is an unknown function of the file /goform/form2AdvanceSetup.cgi of the component WiFi Settings Handler. The manipulation leads to improper access controls. It is…

  • CVE-2024-13103MedJan 2, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability, which was classified as critical, has been found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. This issue affects some unknown processing of the file /goform/form2AddVrtsrv.cgi of the component Virtual Service Handler. The manipulation leads to improper access…

  • CVE-2024-13102MedJan 2, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability classified as critical was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. This vulnerability affects unknown code of the file /goform/DDNS of the component DDNS Service. The manipulation leads to improper access controls. The attack can be initiated remotely.…

  • CVE-2024-13067MedDec 31, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in CodeAstro Online Food Ordering System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/all_users.php of the component All Users Page. The manipulation leads to improper access controls. The attack may be…

  • CVE-2024-12678MedDec 20, 2024
    risk 0.35cvss 6.5epss 0.01

    Nomad Community and Nomad Enterprise ("Nomad") allocations are vulnerable to privilege escalation within a namespace through unredacted workload identity tokens. This vulnerability, identified as CVE-2024-12678, is fixed in Nomad Community Edition 1.9.4 and Nomad Enterprise…

  • CVE-2024-10654MedNov 1, 2024
    risk 0.35cvss 5.3epss 0.02

    A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /formLoginAuth.htm. The manipulation of the argument authCode with the input 1 leads to authorization bypass. The…

  • CVE-2024-48941MedOct 10, 2024
    risk 0.35cvss 5.4epss 0.00

    The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to bypass 2FA by interacting with the /rest endpoint of Jira, Confluence, or Bitbucket. In the default configuration, /rest is allowlisted.

  • CVE-2024-25633MedAug 15, 2024
    risk 0.35cvss 5.4epss 0.00

    eLabFTW is an open source electronic lab notebook for research labs. In an eLabFTW system, one can configure who is allowed to create new user accounts. A vulnerability has been found starting in version 4.4.0 and prior to version 5.0.0 that allows regular users to create new,…

  • CVE-2023-39173MedJul 25, 2023
    risk 0.35cvss 5.4epss 0.00

    In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full account access

  • CVE-2022-2637MedOct 6, 2022
    risk 0.35cvss 5.4epss 0.00

    Incorrect Privilege Assignment vulnerability in Hitachi Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation.This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.8.0 before 04.9.0.

  • CVE-2026-71468MedAug 11, 2026
    risk 0.34cvss 5.3epss 0.00

    A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access…

  • CVE-2026-18720MedAug 4, 2026
    risk 0.34cvss 5.3epss 0.00

    A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?plugin/msgWarning/action of the component msgWarning Plugin. Executing a manipulation can lead to improper authorization. It is possible to launch the attack…