Skip to main content

CWE archive

CWE-266 CVEs

Programmatic archive

1,010 CVEs tagged with CWE-266109 Critical, 273 High, 374 Medium, 253 Low, 1 Unrated.

CVE-2026-1892

Published Feb 4, 2026

A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file models/boards.js of the component REST API. Such manipulation of…

CVSS 2.3 · Low
evidence mentions
6
Buzz score
26.0
Vendor/product tagsBeta · best-effort

CVE-2025-13881

Published Feb 2, 2026

A flaw was found in Keycloak Admin API. This vulnerability allows an administrator with limited privileges to retrieve sensitive custom attributes via the /unmanagedAttributes end…

CVSS 2.7 · Low

CVE-2026-1733

Published Feb 1, 2026

A vulnerability was identified in Zhong Bang CRMEB up to 5.6.3. This affects the function detail/tidyOrder of the file /api/store_integral/order/detail/:uni. The manipulation of t…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-1702

Published Jan 30, 2026

A vulnerability was detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknown function of the file /admin/operation/user.php of the component User Ma…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-1597

Published Jan 29, 2026

A vulnerability has been found in Bdtask SalesERP up to 20260116. This issue affects some unknown processing of the component Administrative Endpoint. Such manipulation of the arg…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2026-1550

Published Jan 28, 2026

A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/hospital/docappsystem/admin…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-1411

Published Jan 26, 2026

A flaw has been found in Beetel 777VR1 up to 01.00.09/01.00.09_55. The affected element is an unknown function of the component UART Interface. This manipulation causes improper a…

CVSS 4.5 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2025-69293

Published Jan 22, 2026

Incorrect Privilege Assignment vulnerability in e-plugins Final User final-user allows Privilege Escalation.This issue affects Final User: from n/a through <= 1.2.5.

CVSS 8.8 · High

CVE-2025-69292

Published Jan 22, 2026

Incorrect Privilege Assignment vulnerability in e-plugins WP Membership wp-membership allows Privilege Escalation.This issue affects WP Membership: from n/a through <= 1.6.4.

CVSS 8.8 · High

CVE-2025-69183

Published Jan 22, 2026

Incorrect Privilege Assignment vulnerability in e-plugins Hospital Doctor Directory hospital-doctor-directory allows Privilege Escalation.This issue affects Hospital Doctor Direct…

CVSS 8.8 · High

CVE-2025-69182

Published Jan 22, 2026

Incorrect Privilege Assignment vulnerability in e-plugins Institutions Directory institutions-directory allows Privilege Escalation.This issue affects Institutions Directory: from…

CVSS 8.8 · High

CVE-2025-68869

Published Jan 22, 2026

Incorrect Privilege Assignment vulnerability in LazyCoders LLC LazyTasks lazytasks-project-task-management allows Privilege Escalation.This issue affects LazyTasks: from n/a throu…

CVSS 9.8 · Critical

CVE-2025-68027

Published Jan 22, 2026

Incorrect Privilege Assignment vulnerability in Themefic Hydra Booking hydra-booking allows Privilege Escalation.This issue affects Hydra Booking: from n/a through <= 1.1.32.

CVSS 7.3 · High

CVE-2025-67966

Published Jan 22, 2026

Incorrect Privilege Assignment vulnerability in e-plugins Lawyer Directory lawyer-directory allows Privilege Escalation.This issue affects Lawyer Directory: from n/a through <= 1.…

CVSS 8.8 · High

CVE-2025-67953

Published Jan 22, 2026

Incorrect Privilege Assignment vulnerability in Booking Activities Team Booking Activities booking-activities allows Privilege Escalation.This issue affects Booking Activities: fr…

CVSS 8.1 · High

CVE-2025-50007

Published Jan 22, 2026

Incorrect Privilege Assignment vulnerability in Jthemes xSmart xsmart allows Privilege Escalation.This issue affects xSmart: from n/a through <= 1.2.9.4.

CVSS 8.8 · High

CVE-2026-1193

Published Jan 19, 2026

A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation l…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-1141

Published Jan 19, 2026

A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /admin/add-subadmins.php of the component Add Sub-Admin Page.…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0
Vendor/product tagsBeta · best-effort

CVE-2026-1112

Published Jan 18, 2026

A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-trade/src/main/java/com/publiccms/controller/web/trade/Trade…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-1106

Published Jan 18, 2026

A security flaw has been discovered in Chamilo LMS up to 2.0.0 Beta 1. This issue affects the function deleteLegal of the file src/CoreBundle/Controller/SocialController.php of th…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-23800

Published Jan 16, 2026

Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from 2.5.2 before 2.6.0.

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2021-47799

Published Jan 15, 2026

Visual Tools DVR VX16 version 4.2.28 contains a local privilege escalation vulnerability in its Sudo configuration that allows attackers to gain root access. Attackers can exploit…

CVSS 8.5 · High

CVE-2026-22916

Published Jan 15, 2026

An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without proper restrictions, potentially leading to service disrup…

CVSS 4.3 · Medium
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2026-22914

Published Jan 15, 2026

An attacker with limited permissions may still be able to write files to specific locations on the device, potentially leading to system manipulation.

CVSS 4.3 · Medium
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2026-22908

Published Jan 15, 2026

Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confidentiality.

CVSS 9.1 · Critical
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort
Showing 326-350 of 1,010 CVEsPage 14 of 41