VYPR

CWE-266

Incorrect Privilege Assignment

BaseDraft

Description

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

CVEs mapped to this weakness (1,190)

page 60 of 60
  • CVE-2025-3202HigApr 4, 2025
    risk 0.00cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in ageerle ruoyi-ai up to 2.0.0. Affected is an unknown function of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/controller/system/SysNoticeController.java. The manipulation leads to improper…

  • CVE-2025-3199HigApr 4, 2025
    risk 0.00cvss 7.3epss 0.01

    A vulnerability was found in ageerle ruoyi-ai up to 2.0.1 and classified as critical. Affected by this issue is some unknown functionality of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/controller/system/SysModelController.java of the component API…

  • CVE-2025-2713HigMar 28, 2025
    risk 0.00cvss 7.8epss 0.00

    Google gVisor's runsc component exhibited a local privilege escalation vulnerability due to incorrect handling of file access permissions, which allowed unprivileged users to access restricted files. This occurred because the process initially ran with root-like permissions…

  • CVE-2024-37293HigJun 11, 2024
    risk 0.00cvss 7.5epss 0.00

    The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and regions within an AWS Organization. ADF allows for staged, parallel, multi-account, cross-region deployments of applications or resources via the structure defined…

  • CVE-2022-2626HigAug 5, 2022
    risk 0.00cvss 7.2epss 0.01

    Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.

  • CVE-2022-1225MedApr 4, 2022
    risk 0.00cvss 6.5epss 0.01

    Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6.

  • CVE-2015-1814Oct 16, 2015
    risk 0.00cvss —epss 0.02

    The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a "forced API token change" involving anonymous users.

  • CVE-2015-1806Oct 16, 2015
    risk 0.00cvss —epss 0.03

    The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors.

  • CVE-2014-3490Aug 19, 2014
    risk 0.00cvss —epss 0.05

    RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read…

  • CVE-2014-1402May 19, 2014
    risk 0.00cvss —epss 0.00

    The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with __jinja2_ in /tmp.