Перейти к содержимому
Noroxi

CWE-266 · 1 169 записей

Incorrect Privilege Assignment

CVE этого класса

1 173 записей

  • CVE-2026-48172
    70На этой неделе

    LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026.

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 1 %

    litespeedtech · litespeed cpanel plugin20 мая 2026 г.

  • CVE-2024-28000
    59В плане

    WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability

    КритическаяCVSS 9,8Proof of conceptEPSS 68 %

    litespeedtech · litespeed cache21 авг. 2024 г.

  • CVE-2025-27007
    55В плане

    WordPress SureTriggers <= 1.0.82 - Privilege Escalation Vulnerability

    КритическаяCVSS 9,8Готовый эксплойтEPSS 54 %

    brainstorm force · ottokit1 мая 2025 г.

  • CVE-2025-47539
    47В плане

    WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability

    КритическаяCVSS 9,8Proof of conceptEPSS 28 %

    themewinter · eventin23 мая 2025 г.

  • CVE-2026-23550
    46В плане

    WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability

    КритическаяCVSS 9,8Proof of conceptEPSS 22 %

    modular ds · modular ds14 янв. 2026 г.

  • CVE-2025-41115
    44В плане

    Incorrect privilege assignment

    КритическаяCVSS 9,8Proof of conceptEPSS 17 %

    grafana · grafana21 нояб. 2025 г.

  • CVE-2022-20759
    43В плане

    Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Privilege Escalation Vulnerability

    ВысокаяCVSS 8,8Эксплойта нетEPSS 28 %

    cisco · secure firewall threat defense3 мая 2022 г.

  • CVE-2025-49388
    41В плане

    WordPress Miraculous Core Plugin Plugin <= 2.0.7 - Privilege Escalation Vulnerability

    КритическаяCVSS 9,8Proof of conceptEPSS 6 %

    kamleshyadav · miraculous core plugin28 авг. 2025 г.

  • CVE-2024-24882
    40В плане

    WordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerability

    КритическаяCVSS 9,8Proof of conceptEPSS 2 %

    themegrill · masteriyo17 мая 2024 г.

  • CVE-2024-54363
    40В плане

    WordPress Wp NssUser Register plugin <= 1.0.0 - Privilege Escalation vulnerability

    КритическаяCVSS 9,8Proof of conceptEPSS 2 %

    saiful.total · wp nssuser register16 дек. 2024 г.

  • CVE-2026-27542
    40В плане

    WordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Privilege Escalation vulnerability

    КритическаяCVSS 9,8Proof of conceptEPSS 2 %

    rymera web co pty ltd. · woocommerce wholesale lead capture19 мар. 2026 г.

  • CVE-2026-23800
    40В плане

    WordPress Modular DS plugin <= 2.5.2 - Privilege Escalation vulnerability

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    16 янв. 2026 г.

  • CVE-2024-9478
    40В плане

    Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue a

    КритическаяCVSS 10,0Эксплойта нетEPSS 0 %

    upkeeper solutions · upkeeper instant privilege access20 нояб. 2024 г.

  • CVE-2024-9479
    40В плане

    Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue a

    КритическаяCVSS 10,0Эксплойта нетEPSS 0 %

    upkeeper solutions · upkeeper instant privilege access20 нояб. 2024 г.

  • CVE-2026-49060
    39Наблюдать

    WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vulnerability

    КритическаяCVSS 9,8Proof of conceptEPSS 2 %

    hippoo · hippoo mobile app for woocommerce11 июн. 2026 г.

  • CVE-2019-10940
    39Наблюдать

    A vulnerability has been identified in SINEMA Server (All versions < V14.0 SP2 Update 1).

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    siemens · sinema server16 янв. 2020 г.

  • CVE-2024-54383
    39Наблюдать

    WordPress WooCommerce - PDF Vouchers plugin < 4.9.9 - Broken Authentication vulnerability

    КритическаяCVSS 9,8Proof of conceptEPSS 1 %

    wpwebelite · woocommerce pdf vouchers18 дек. 2024 г.

  • CVE-2024-50485
    39Наблюдать

    WordPress Exam Matrix plugin <= 1.5 - Privilege Escalation vulnerability

    КритическаяCVSS 9,8Proof of conceptEPSS 1 %

    udit rawat · exam matrix29 окт. 2024 г.

  • CVE-2024-50550
    39Наблюдать

    WordPress LiteSpeed Cache plugin <= 6.5.1 - Privilege Escalation vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    litespeedtech · litespeed cache29 окт. 2024 г.

  • CVE-2024-2409
    39Наблюдать

    MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX Action

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    stylemixthemes · masterstudy lms29 мар. 2024 г.

  • CVE-2022-4272
    39Наблюдать

    FeMiner wms unrestricted upload

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    warehouse management system project · warehouse management system3 дек. 2022 г.

  • CVE-2022-4273
    39Наблюдать

    SourceCodester Human Resource Management System Content-Type employee.php unrestricted upload

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    oretnom23 · human resource management system3 дек. 2022 г.

  • CVE-2025-32491
    39Наблюдать

    WordPress Rankology SEO – On-site SEO plugin <= 2.2.4 - Privilege Escalation Vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    rankology · rankology seo – on-site seo11 апр. 2025 г.

  • CVE-2024-13421
    39Наблюдать

    Real Estate 7 WordPress <= 3.5.1 - Unauthenticated Privilege Escalation to Administrator

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    contempothemes · real estate 712 февр. 2025 г.

  • CVE-2024-56040
    39Наблюдать

    WordPress VibeBP plugin <= 1.9.9.4.1 - Unauthenticated Privilege Escalation vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    vibethemes · vibebp31 дек. 2024 г.

Все классы уязвимостей