Skip to main content

CWE archive

CWE-266 CVEs

Programmatic archive

1,006 CVEs tagged with CWE-266107 Critical, 272 High, 374 Medium, 252 Low, 1 Unrated.

CVE-2026-3209

Published Feb 25, 2026

A vulnerability has been found in fosrl Pangolin up to 1.15.4-s.3. This affects the function verifyRoleAccess/verifyApiKeyRoleAccess of the component Role Handler. The manipulatio…

CVSS 2.1 · Low
evidence mentions
9
Buzz score
31.0

CVE-2026-2983

Published Feb 23, 2026

A vulnerability was determined in SourceCodester Student Result Management System 1.0. The impacted element is an unknown function of the file /admin/core/import_users.php of the…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-2938

Published Feb 22, 2026

A vulnerability has been found in SourceCodester Student Result Management System 1.0. The affected element is an unknown function of the file /srms/script/admin/core/update_smtp.…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-2896

Published Feb 22, 2026

A weakness has been identified in funadmin up to 7.1.0-rc4. This affects the function setConfig of the file app/backend/controller/Ajax.php of the component Configuration Handler.…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-2860

Published Feb 21, 2026

A security vulnerability has been detected in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. Impacted is an unknown function of the…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-2852

Published Feb 20, 2026

A vulnerability was identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects the function addSales/updateSales/deleteSales of the file dat…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
30.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-2851

Published Feb 20, 2026

A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This vulnerability affects the function addInport/updateInport/deleteInport of t…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
30.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-2850

Published Feb 20, 2026

A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function addCustomer/updateCustomer/deleteCustomer of the file datas…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
30.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-2849

Published Feb 20, 2026

A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issue is the function deleteCache/removeAllCache/syncCache of t…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
30.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-69378

Published Feb 20, 2026

Incorrect Privilege Assignment vulnerability in XforWooCommerce Product Filter for WooCommerce prdctfltr allows Privilege Escalation.This issue affects Product Filter for WooComme…

CVSS 7.2 · High

CVE-2026-22268

Published Feb 19, 2026

Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with remote access could potential…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22267

Published Feb 19, 2026

Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with remote access could potential…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-2693

Published Feb 19, 2026

A vulnerability was determined in CoCoTeaNet CyreneAdmin up to 1.3.0. This vulnerability affects unknown code of the file /api/system/dashboard/getCount of the component System In…

CVSS 2.1 · Low
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-2676

Published Feb 18, 2026

A weakness has been identified in GoogTech sms-ssm up to e8534c766fd13f5f94c01dab475d75f286918a8d. Affected by this issue is the function preHandle of the file LoginInterceptor.ja…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-2563

Published Feb 16, 2026

A vulnerability was identified in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. Affected is the function set_stcreenen_deabled_status/get_status of the file /f/service/controlDe…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-2562

Published Feb 16, 2026

A vulnerability was determined in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. This impacts the function cast_streen of the file /jdcapi of the component jdcweb_rpc. Executing…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-2561

Published Feb 16, 2026

A vulnerability was found in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. This affects the function web_get_ddns_uptime of the file /jdcapi of the component jdcweb_rpc. Perform…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-2549

Published Feb 16, 2026

A vulnerability has been found in zhanghuanhao LibrarySystem 图书馆管理系统 up to 1.1.1. This impacts an unknown function of the file BookController.java. The manipulation leads to impro…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2025-14282

Published Feb 12, 2026

A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the socket forwardings requested by the remote client as root,…

CVSS 5.4 · Medium

CVE-2025-14778

Published Feb 9, 2026

A flaw was found in Keycloak. A significant Broken Access Control vulnerability exists in the UserManagedPermissionService (UMA Protection API). When updating or deleting a UMA po…

CVSS 5.4 · Medium

CVE-2026-2141

Published Feb 8, 2026

A security flaw has been discovered in WuKongOpenSource WukongCRM up to 11.3.3. This affects an unknown part of the file gateway/src/main/java/com/kakarote/gateway/service/impl/Pe…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 276-300 of 1,006 CVEsPage 12 of 41