Skip to main content

CWE archive

CWE-266 CVEs

Programmatic archive

1,010 CVEs tagged with CWE-266109 Critical, 273 High, 374 Medium, 253 Low, 1 Unrated.

CVE-2026-23550

Published Jan 14, 2026

Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from n/a through <= 2.5.1.

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
32.6

CVE-2022-50927

Published Jan 13, 2026

Cyclades Serial Console Server 3.3.0 contains a local privilege escalation vulnerability due to overly permissive sudo privileges for the admin user and admin group. Attackers can…

CVSS 8.5 · High

CVE-2025-67279

Published Jan 9, 2026

An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via the application stores password hashes in MD5 format

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-67278

Published Jan 9, 2026

An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via a crafted HTTP request

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-31643

Published Jan 7, 2026

Incorrect Privilege Assignment vulnerability in Dasinfomedia WPCHURCH allows Privilege Escalation.This issue affects WPCHURCH: from n/a through 2.7.0.

CVSS 8.8 · High

CVE-2025-29004

Published Jan 6, 2026

Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing Page / Holding Page for WordPr…

CVSS 8.8 · High

CVE-2026-0574

Published Jan 4, 2026

A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function saveUserRole of the file warehouse\src\main\java\com\y…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2025-15126

Published Dec 28, 2025

A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/position/getPositionUserList. This man…

CVSS 1.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-15125

Published Dec 28, 2025

A security flaw has been discovered in JeecgBoot up to 3.9.0. Affected is the function queryDepartPermission of the file /sys/permission/queryDepartPermission. The manipulation of…

CVSS 1.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-15124

Published Dec 28, 2025

A vulnerability was identified in JeecgBoot up to 3.9.0. This impacts the function getParameterMap of the file /sys/sysDepartPermission/list. The manipulation of the argument depa…

CVSS 1.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-15123

Published Dec 28, 2025

A vulnerability was determined in JeecgBoot up to 3.9.0. This affects an unknown function of the file /sys/sysDepartPermission/datarule/. Executing manipulation can lead to improp…

CVSS 1.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-15122

Published Dec 28, 2025

A vulnerability was found in JeecgBoot up to 3.9.0. The impacted element is the function loadDatarule of the file /sys/sysDepartRole/datarule/. Performing manipulation of the argu…

CVSS 1.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-15120

Published Dec 28, 2025

A flaw has been found in JeecgBoot up to 3.9.0. Impacted is the function getDeptRoleList of the file /sys/sysDepartRole/getDeptRoleList. This manipulation of the argument departId…

CVSS 1.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-15119

Published Dec 28, 2025

A vulnerability was detected in JeecgBoot up to 3.9.0. This issue affects the function queryPageList of the file /sys/sysDepartRole/list. The manipulation of the argument deptId r…

CVSS 1.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-15118

Published Dec 28, 2025

A security vulnerability has been detected in macrozheng mall up to 1.0.3. This vulnerability affects unknown code of the file /member/address/update/ of the component Member Endp…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-15106

Published Dec 27, 2025

A weakness has been identified in getmaxun maxun up to 0.0.28. The affected element is the function router.get of the file server/src/routes/auth.ts of the component Authenticatio…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-15087

Published Dec 25, 2025

A security vulnerability has been detected in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function submitOrderPayment of the file mall-oms/oms-boot/src/main/java/com/youla…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-15086

Published Dec 25, 2025

A weakness has been identified in youlaitech youlai-mall 1.0.0/2.0.0. This impacts the function getMemberByMobile of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/c…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-15085

Published Dec 25, 2025

A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-15084

Published Dec 25, 2025

A vulnerability was identified in youlaitech youlai-mall 1.0.0/2.0.0. The impacted element is the function orderService.payOrder of the file mall-oms/oms-boot/src/main/java/com/yo…

CVSS 1.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-25249

Published Dec 24, 2025

devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hidden services through the htmlmgr CGI script. Attackers can…

CVSS 8.7 · High
Showing 351-375 of 1,010 CVEsPage 15 of 41