Vulnerabilities > Incorrect Privilege Assignment

DATE CVE VULNERABILITY TITLE RISK
2025-04-29 CVE-2025-4064 Incorrect Privilege Assignment vulnerability in Scriptandtools Online Traveling System 1.0
A vulnerability was found in ScriptAndTools Online-Travling-System 1.0.
network
low complexity
scriptandtools CWE-266
5.3
2025-04-28 CVE-2025-4016 A vulnerability classified as critical has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160.
network
low complexity
CWE-266
5.4
2025-04-28 CVE-2025-4017 A vulnerability classified as problematic was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160.
network
low complexity
CWE-266
4.3
2025-04-26 CVE-2025-2850 A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 Marble, GL-BE3600 Slate 7, GL-E750, GL-E750V2 Mudi, GL-MT300N-V2 Mango, GL-MT1300 Beryl, GL-MT2500 Brume 2, GL-MT3000 Beryl AX, GL-MT6000 Flint 2, GL-SFT1200 Opal, GL-X300B Collie, GL-X750 Spitz, GL-X3000 Spitz AX, GL-XE300 Puli and GL-XE3000 Puli AX 4.x.
low complexity
CWE-266
3.5
2025-04-25 CVE-2025-2470 The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, is vulnerable to privilege escalation in all versions up to, and including, 5.1.
network
low complexity
CWE-266
critical
9.8
2025-04-18 CVE-2025-3790 A vulnerability classified as critical has been found in baseweb JSite 1.0.
network
low complexity
CWE-266
5.3
2025-04-16 CVE-2025-3675 Incorrect Privilege Assignment vulnerability in Totolink A3700R Firmware 9.1.2U.5822B20200513
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513.
network
low complexity
totolink CWE-266
5.3
2025-04-16 CVE-2025-3667 Incorrect Privilege Assignment vulnerability in Totolink A3700R Firmware 9.1.2U.5822B20200513
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513.
network
low complexity
totolink CWE-266
5.3
2025-04-16 CVE-2025-3668 Incorrect Privilege Assignment vulnerability in Totolink A3700R Firmware 9.1.2U.5822B20200513
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513.
network
low complexity
totolink CWE-266
5.3
2025-04-16 CVE-2025-3666 Incorrect Privilege Assignment vulnerability in Totolink A3700R Firmware 9.1.2U.5822B20200513
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical.
network
low complexity
totolink CWE-266
5.3