CWE-266 · 1 169 записей
Incorrect Privilege Assignment
CVE этого класса
1 173 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
70На этой неделе | CVE-2026-48172Готовый эксплойт | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026.litespeedtech · litespeed cpanel plugin · CWE-266 | Критическая10,0 | KEV | 1,0 % | 20 мая 2026 г. |
59В плане | CVE-2024-28000Proof of concept | WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerabilitylitespeedtech · litespeed cache · CWE-266 | Критическая9,8 | — | 68,3 % | 21 авг. 2024 г. |
55В плане | CVE-2025-27007Готовый эксплойт | WordPress SureTriggers <= 1.0.82 - Privilege Escalation Vulnerabilitybrainstorm force · ottokit · CWE-266 | Критическая9,8 | — | 53,9 % | 1 мая 2025 г. |
47В плане | CVE-2025-47539Proof of concept | WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerabilitythemewinter · eventin · CWE-266 | Критическая9,8 | — | 27,9 % | 23 мая 2025 г. |
46В плане | CVE-2026-23550Proof of concept | WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerabilitymodular ds · modular ds · CWE-266 | Критическая9,8 | — | 21,7 % | 14 янв. 2026 г. |
44В плане | CVE-2025-41115Proof of concept | Incorrect privilege assignmentgrafana · grafana · CWE-266 | Критическая9,8 | — | 16,9 % | 21 нояб. 2025 г. |
43В плане | CVE-2022-20759Эксплойта нет | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Privilege Escalation Vulnerabilitycisco · secure firewall threat defense · CWE-266 | Высокая8,8 | — | 28,2 % | 3 мая 2022 г. |
41В плане | CVE-2025-49388Proof of concept | WordPress Miraculous Core Plugin Plugin <= 2.0.7 - Privilege Escalation Vulnerabilitykamleshyadav · miraculous core plugin · CWE-266 | Критическая9,8 | — | 5,7 % | 28 авг. 2025 г. |
40В плане | CVE-2024-24882Proof of concept | WordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerabilitythemegrill · masteriyo · CWE-266 | Критическая9,8 | — | 2,1 % | 17 мая 2024 г. |
40В плане | CVE-2024-54363Proof of concept | WordPress Wp NssUser Register plugin <= 1.0.0 - Privilege Escalation vulnerabilitysaiful.total · wp nssuser register · CWE-266 | Критическая9,8 | — | 1,9 % | 16 дек. 2024 г. |
40В плане | CVE-2026-27542Proof of concept | WordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Privilege Escalation vulnerabilityrymera web co pty ltd. · woocommerce wholesale lead capture · CWE-266 | Критическая9,8 | — | 1,8 % | 19 мар. 2026 г. |
40В плане | CVE-2026-23800Эксплойта нет | WordPress Modular DS plugin <= 2.5.2 - Privilege Escalation vulnerabilityCWE-266 | Критическая10,0 | — | 0,5 % | 16 янв. 2026 г. |
40В плане | CVE-2024-9478Эксплойта нет | Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue aupkeeper solutions · upkeeper instant privilege access · CWE-266 | Критическая10,0 | — | 0,4 % | 20 нояб. 2024 г. |
40В плане | CVE-2024-9479Эксплойта нет | Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue aupkeeper solutions · upkeeper instant privilege access · CWE-266 | Критическая10,0 | — | 0,4 % | 20 нояб. 2024 г. |
39Наблюдать | CVE-2026-49060Proof of concept | WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vulnerabilityhippoo · hippoo mobile app for woocommerce · CWE-266 | Критическая9,8 | — | 1,6 % | 11 июн. 2026 г. |
39Наблюдать | CVE-2019-10940Эксплойта нет | A vulnerability has been identified in SINEMA Server (All versions < V14.0 SP2 Update 1).siemens · sinema server · CWE-266 | Критическая9,9 | — | 1,2 % | 16 янв. 2020 г. |
39Наблюдать | CVE-2024-54383Proof of concept | WordPress WooCommerce - PDF Vouchers plugin < 4.9.9 - Broken Authentication vulnerabilitywpwebelite · woocommerce pdf vouchers · CWE-266 | Критическая9,8 | — | 1,2 % | 18 дек. 2024 г. |
39Наблюдать | CVE-2024-50485Proof of concept | WordPress Exam Matrix plugin <= 1.5 - Privilege Escalation vulnerabilityudit rawat · exam matrix · CWE-266 | Критическая9,8 | — | 1,0 % | 29 окт. 2024 г. |
39Наблюдать | CVE-2024-50550Эксплойта нет | WordPress LiteSpeed Cache plugin <= 6.5.1 - Privilege Escalation vulnerabilitylitespeedtech · litespeed cache · CWE-266 | Критическая9,8 | — | 0,9 % | 29 окт. 2024 г. |
39Наблюдать | CVE-2024-2409Эксплойта нет | MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX Actionstylemixthemes · masterstudy lms · CWE-266 | Критическая9,8 | — | 0,8 % | 29 мар. 2024 г. |
39Наблюдать | CVE-2022-4272Эксплойта нет | FeMiner wms unrestricted uploadwarehouse management system project · warehouse management system · CWE-266 | Критическая9,8 | — | 0,8 % | 3 дек. 2022 г. |
39Наблюдать | CVE-2022-4273Эксплойта нет | SourceCodester Human Resource Management System Content-Type employee.php unrestricted uploadoretnom23 · human resource management system · CWE-266 | Критическая9,8 | — | 0,8 % | 3 дек. 2022 г. |
39Наблюдать | CVE-2025-32491Эксплойта нет | WordPress Rankology SEO – On-site SEO plugin <= 2.2.4 - Privilege Escalation Vulnerabilityrankology · rankology seo – on-site seo · CWE-266 | Критическая9,8 | — | 0,8 % | 11 апр. 2025 г. |
39Наблюдать | CVE-2024-13421Эксплойта нет | Real Estate 7 WordPress <= 3.5.1 - Unauthenticated Privilege Escalation to Administratorcontempothemes · real estate 7 · CWE-266 | Критическая9,8 | — | 0,8 % | 12 февр. 2025 г. |
39Наблюдать | CVE-2024-56040Эксплойта нет | WordPress VibeBP plugin <= 1.9.9.4.1 - Unauthenticated Privilege Escalation vulnerabilityvibethemes · vibebp · CWE-266 | Критическая9,8 | — | 0,8 % | 31 дек. 2024 г. |
- CVE-2026-4817270На этой неделе
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026.
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 1 %litespeedtech · litespeed cpanel plugin20 мая 2026 г.
- CVE-2024-2800059В плане
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 68 %litespeedtech · litespeed cache21 авг. 2024 г.
- CVE-2025-2700755В плане
WordPress SureTriggers <= 1.0.82 - Privilege Escalation Vulnerability
КритическаяCVSS 9,8Готовый эксплойтEPSS 54 %brainstorm force · ottokit1 мая 2025 г.
- CVE-2025-4753947В плане
WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 28 %themewinter · eventin23 мая 2025 г.
- CVE-2026-2355046В плане
WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 22 %modular ds · modular ds14 янв. 2026 г.
- CVE-2025-4111544В плане
Incorrect privilege assignment
КритическаяCVSS 9,8Proof of conceptEPSS 17 %grafana · grafana21 нояб. 2025 г.
- CVE-2022-2075943В плане
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Privilege Escalation Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 28 %cisco · secure firewall threat defense3 мая 2022 г.
- CVE-2025-4938841В плане
WordPress Miraculous Core Plugin Plugin <= 2.0.7 - Privilege Escalation Vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 6 %kamleshyadav · miraculous core plugin28 авг. 2025 г.
- CVE-2024-2488240В плане
WordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 2 %themegrill · masteriyo17 мая 2024 г.
- CVE-2024-5436340В плане
WordPress Wp NssUser Register plugin <= 1.0.0 - Privilege Escalation vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 2 %saiful.total · wp nssuser register16 дек. 2024 г.
- CVE-2026-2754240В плане
WordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Privilege Escalation vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 2 %rymera web co pty ltd. · woocommerce wholesale lead capture19 мар. 2026 г.
- CVE-2026-2380040В плане
WordPress Modular DS plugin <= 2.5.2 - Privilege Escalation vulnerability
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %16 янв. 2026 г.
- CVE-2024-947840В плане
Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue a
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %upkeeper solutions · upkeeper instant privilege access20 нояб. 2024 г.
- CVE-2024-947940В плане
Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue a
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %upkeeper solutions · upkeeper instant privilege access20 нояб. 2024 г.
- CVE-2026-4906039Наблюдать
WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 2 %hippoo · hippoo mobile app for woocommerce11 июн. 2026 г.
- CVE-2019-1094039Наблюдать
A vulnerability has been identified in SINEMA Server (All versions < V14.0 SP2 Update 1).
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %siemens · sinema server16 янв. 2020 г.
- CVE-2024-5438339Наблюдать
WordPress WooCommerce - PDF Vouchers plugin < 4.9.9 - Broken Authentication vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 1 %wpwebelite · woocommerce pdf vouchers18 дек. 2024 г.
- CVE-2024-5048539Наблюдать
WordPress Exam Matrix plugin <= 1.5 - Privilege Escalation vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 1 %udit rawat · exam matrix29 окт. 2024 г.
- CVE-2024-5055039Наблюдать
WordPress LiteSpeed Cache plugin <= 6.5.1 - Privilege Escalation vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %litespeedtech · litespeed cache29 окт. 2024 г.
- CVE-2024-240939Наблюдать
MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX Action
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %stylemixthemes · masterstudy lms29 мар. 2024 г.
- CVE-2022-427239Наблюдать
FeMiner wms unrestricted upload
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %warehouse management system project · warehouse management system3 дек. 2022 г.
- CVE-2022-427339Наблюдать
SourceCodester Human Resource Management System Content-Type employee.php unrestricted upload
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %oretnom23 · human resource management system3 дек. 2022 г.
- CVE-2025-3249139Наблюдать
WordPress Rankology SEO – On-site SEO plugin <= 2.2.4 - Privilege Escalation Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rankology · rankology seo – on-site seo11 апр. 2025 г.
- CVE-2024-1342139Наблюдать
Real Estate 7 WordPress <= 3.5.1 - Unauthenticated Privilege Escalation to Administrator
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %contempothemes · real estate 712 февр. 2025 г.
- CVE-2024-5604039Наблюдать
WordPress VibeBP plugin <= 1.9.9.4.1 - Unauthenticated Privilege Escalation vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %vibethemes · vibebp31 дек. 2024 г.