CWE-266
Incorrect Privilege Assignment
Description
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Hierarchy (View 1000)
CVEs mapped to this weakness (1,190)
page 60 of 60| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-3202 | Hig | 0.00 | 7.3 | 0.01 | Apr 4, 2025 | A vulnerability classified as critical has been found in ageerle ruoyi-ai up to 2.0.0. Affected is an unknown function of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/controller/system/SysNoticeController.java. The manipulation leads to improper… | ||
| CVE-2025-3199 | Hig | 0.00 | 7.3 | 0.01 | Apr 4, 2025 | A vulnerability was found in ageerle ruoyi-ai up to 2.0.1 and classified as critical. Affected by this issue is some unknown functionality of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/controller/system/SysModelController.java of the component API… | ||
| CVE-2025-2713 | Hig | 0.00 | 7.8 | 0.00 | Mar 28, 2025 | Google gVisor's runsc component exhibited a local privilege escalation vulnerability due to incorrect handling of file access permissions, which allowed unprivileged users to access restricted files. This occurred because the process initially ran with root-like permissions… | ||
| CVE-2024-37293 | Hig | 0.00 | 7.5 | 0.00 | Jun 11, 2024 | The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and regions within an AWS Organization. ADF allows for staged, parallel, multi-account, cross-region deployments of applications or resources via the structure defined… | ||
| CVE-2022-2626 | Hig | 0.00 | 7.2 | 0.01 | Aug 5, 2022 | Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6. | ||
| CVE-2022-1225 | Med | 0.00 | 6.5 | 0.01 | Apr 4, 2022 | Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6. | ||
| CVE-2015-1814 | 0.00 | — | 0.02 | Oct 16, 2015 | The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a "forced API token change" involving anonymous users. | |||
| CVE-2015-1806 | 0.00 | — | 0.03 | Oct 16, 2015 | The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors. | |||
| CVE-2014-3490 | 0.00 | — | 0.05 | Aug 19, 2014 | RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read… | |||
| CVE-2014-1402 | 0.00 | — | 0.00 | May 19, 2014 | The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with __jinja2_ in /tmp. |
- risk 0.00cvss 7.3epss 0.01
A vulnerability classified as critical has been found in ageerle ruoyi-ai up to 2.0.0. Affected is an unknown function of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/controller/system/SysNoticeController.java. The manipulation leads to improper…
- risk 0.00cvss 7.3epss 0.01
A vulnerability was found in ageerle ruoyi-ai up to 2.0.1 and classified as critical. Affected by this issue is some unknown functionality of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/controller/system/SysModelController.java of the component API…
- risk 0.00cvss 7.8epss 0.00
Google gVisor's runsc component exhibited a local privilege escalation vulnerability due to incorrect handling of file access permissions, which allowed unprivileged users to access restricted files. This occurred because the process initially ran with root-like permissions…
- risk 0.00cvss 7.5epss 0.00
The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and regions within an AWS Organization. ADF allows for staged, parallel, multi-account, cross-region deployments of applications or resources via the structure defined…
- risk 0.00cvss 7.2epss 0.01
Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.
- risk 0.00cvss 6.5epss 0.01
Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6.
- CVE-2015-1814Oct 16, 2015risk 0.00cvss —epss 0.02
The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a "forced API token change" involving anonymous users.
- CVE-2015-1806Oct 16, 2015risk 0.00cvss —epss 0.03
The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors.
- CVE-2014-3490Aug 19, 2014risk 0.00cvss —epss 0.05
RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read…
- CVE-2014-1402May 19, 2014risk 0.00cvss —epss 0.00
The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with __jinja2_ in /tmp.