Falhas do tipo CWE-266

951 resultados
CVE-2023-49647HIGHZoom Desktop Client for Windows - Improper Access ControlEPSS 0.2%CVE-2026-56251HIGHCapgo - Privilege Escalation via Broken Row Level Security in org_usersEPSS 0.2%CVE-2025-6531MEDIUMSIFUSM/MZZYG BD S1 RTSP Live Video Stream Endpoint access controlEPSS 0.2%CVE-2024-37293HIGHaws-deployment-framework's potential risk can lead to privilege escalationEPSS 0.2%CVE-2019-19351HIGHAn insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker with access to the EPSS 0.2%CVE-2019-19355HIGHAn insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An attacker with access EPSS 0.2%CVE-2025-15084LOWyoulaitech youlai-mall Order Payment OrderController.java orderService.payOrder access controlEPSS 0.2%CVE-2025-14889MEDIUMCampcodes Advanced Voting Management System Password voters_edit.php improper authorizationEPSS 0.2%CVE-2025-47291MEDIUMcontainerd CRI plugin: Incorrect cgroup hierarchy assignment for containers running in usernamespaced Kubernetes pods.EPSS 0.2%CVE-2024-25633MEDIUMIn eLabFTW, if administrators can create users, users can tooEPSS 0.2%CVE-2025-11080MEDIUMzhuimengshaonian wisdom-education ExamInfoController.java selectStudentExamInfoList improper authorizationEPSS 0.2%CVE-2026-1892LOWWeKan REST API boards.js setBoardOrgs improper authorizationEPSS 0.2%CVE-2026-27541HIGHWordPress Wholesale Suite plugin <= 2.2.6 - Privilege Escalation vulnerabilityEPSS 0.2%CVE-2025-56503MEDIUMAn issue in Sublime HQ Pty Ltd Sublime Text 4 4200 allows authenticated attackers with low-level privileges to escalate privileges to AdminiEPSS 0.2%CVE-2025-55948HIGHThis vulnerability fundamentally arises from yzcheng90 X-SpringBoot 6.0's implementation of role-based access control (RBAC) through dual deEPSS 0.2%CVE-2026-2206MEDIUMWeKan Administrative Repair fixDuplicateLists.js FixDuplicateBleed access controlEPSS 0.2%CVE-2026-49111HIGHWordPress Masteriyo - LMS plugin <= 2.2.0 - Privilege Escalation vulnerabilityEPSS 0.2%CVE-2026-47169HIGHQuest Bot: Manage Server users can configure AutoRole to grant Administrator to controlled joining accountsEPSS 0.2%CVE-2024-42441MEDIUMZoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS, Zoom Rooms Client for macOS - Incorrect Privilege AssignmentEPSS 0.2%CVE-2024-49348MEDIUMIBM Cloud Pak for Business Automation incorrect privilege assignmentEPSS 0.2%