Skip to main content

CWE archive

CWE-266 CVEs

Programmatic archive

1,013 CVEs tagged with CWE-266109 Critical, 273 High, 374 Medium, 256 Low, 1 Unrated.

CVE-2026-17434

Published Jul 26, 2026

A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. E…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-17433

Published Jul 26, 2026

A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MC…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-17432

Published Jul 26, 2026

A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/a…

CVSS 1.3 · Low
evidence mentions
9
Buzz score
29.5

CVE-2026-16764

Published Jul 23, 2026

A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such man…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-61951

Published Jul 23, 2026

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-59541

Published Jul 23, 2026

Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-59540

Published Jul 23, 2026

Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-47237

Published Jul 21, 2026

Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manife…

CVSS 8.0 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-21824

Published Jul 20, 2026

HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative ope…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-16224

Published Jul 19, 2026

A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the file /jxxghp/MoviePilot of the component Application API. The…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
27.3

CVE-2026-16199

Published Jul 19, 2026

A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file goclaw/internal/tools/credentialed_exec.go. Executing…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-16121

Published Jul 18, 2026

A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isSafeBin of the file internal/tools/exec_approval.go. The manipulation leads to i…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-50562

Published Jul 15, 2026

FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted pull request code in .github/w…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-15594

Published Jul 13, 2026

A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the library src/lib/media/hash.ts of the component Media Handler…

CVSS 2.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-57813

Published Jul 13, 2026

Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through <= 1.2.77.3.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-57768

Published Jul 13, 2026

Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue affects Houzez Login Register: from n…

CVSS 8.2 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57410

Published Jul 13, 2026

Incorrect Privilege Assignment vulnerability in MailerPress Team MailerPress mailerpress allows Privilege Escalation.This issue affects MailerPress: from n/a through <= 2.0.2.

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57386

Published Jul 13, 2026

Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects aBlocks: from n/a through < 2.9.1.

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-15510

Published Jul 12, 2026

A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. The manipulation results in improper authorization. The atta…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
27.9

CVE-2026-15509

Published Jul 12, 2026

A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON-RPC Endpoint. The manipulation of the argument role leads…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
27.9

CVE-2026-15499

Published Jul 12, 2026

A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.2. Affected is the function FutureTaskTool.call of the file astrbot/core/tools/cron_tools.py of the component…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-15476

Published Jul 12, 2026

A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an unknown function in the library diskbckp.sys of the component Kernel Driver. S…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-15475

Published Jul 12, 2026

A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in the library pwdrvio.sys of the component Signed Kernel Drive…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-15474

Published Jul 12, 2026

A security flaw has been discovered in Eleveo Call Recording Software 9.7.0. Impacted is an unknown function of the file /callrec/audio.jsp of the component Call Recording Handler…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
27.5

CVE-2026-15473

Published Jul 12, 2026

A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This issue affects some unknown processing of the file /callrec/restoreCallAction.do of the component Recor…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
27.5
Showing 1-25 of 1,013 CVEsPage 1 of 41