Vulnerabilities > Incorrect Privilege Assignment

DATE CVE VULNERABILITY TITLE RISK
2025-03-15 CVE-2025-1653 Incorrect Privilege Assignment vulnerability in Stylemixthemes Ulisting
The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.7.
network
low complexity
stylemixthemes CWE-266
8.8
2025-03-14 CVE-2025-2320 A vulnerability has been found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical.
network
low complexity
CWE-266
7.3
2025-03-12 CVE-2025-2218 Incorrect Privilege Assignment vulnerability in Lovecards
A vulnerability has been found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical.
network
low complexity
lovecards CWE-266
critical
9.8
2025-03-09 CVE-2025-2114 A vulnerability, which was classified as problematic, has been found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 7.
network
high complexity
CWE-266
3.7
2025-03-03 CVE-2025-1881 Incorrect Privilege Assignment vulnerability in I-Drive I11 Firmware and I12 Firmware
A vulnerability was found in i-Drive i11 and i12 up to 20250227.
network
low complexity
i-drive CWE-266
4.3
2025-02-28 CVE-2024-8420 Incorrect Privilege Assignment vulnerability in Sitesao Dhvc Form
The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7.
network
low complexity
sitesao CWE-266
critical
9.8
2025-02-12 CVE-2025-1226 A vulnerability was found in ywoa up to 2024.07.03.
network
low complexity
CWE-266
5.3
2025-02-12 CVE-2024-12213 Incorrect Privilege Assignment vulnerability in Apusthemes Superio
The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.76.
network
low complexity
apusthemes CWE-266
critical
9.8
2025-02-06 CVE-2025-1078 A vulnerability has been found in AppHouseKitchen AlDente Charge Limiter up to 1.29 on macOS and classified as critical.
local
low complexity
CWE-266
5.3
2025-02-05 CVE-2024-49348 IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 allows restricting access to organizational data to valid contexts.
network
low complexity
CWE-266
4.3