Skip to main content

CWE archive

CWE-266 CVEs

Programmatic archive

1,010 CVEs tagged with CWE-266109 Critical, 273 High, 374 Medium, 253 Low, 1 Unrated.

CVE-2025-64188

Published Dec 18, 2025

Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affects Soledad: from n/a through <= 8.6.9.

CVSS 9.8 · Critical

CVE-2025-59134

Published Dec 18, 2025

Incorrect Privilege Assignment vulnerability in Jthemes Sale! Immigration law, Visa services support, Migration Agent Consulting immiex allows Privilege Escalation.This issue affe…

CVSS 8.8 · High

CVE-2025-58710

Published Dec 18, 2025

Incorrect Privilege Assignment vulnerability in e-plugins Hotel Listing hotel-listing allows Privilege Escalation.This issue affects Hotel Listing: from n/a through <= 1.4.0.

CVSS 8.8 · High

CVE-2025-55707

Published Dec 18, 2025

Incorrect Privilege Assignment vulnerability in WPXPO PostX ultimate-post allows Privilege Escalation.This issue affects PostX: from n/a through <= 4.1.35.

CVSS 7.2 · High

CVE-2025-49379

Published Dec 18, 2025

Incorrect Privilege Assignment vulnerability in silverplugins217 Custom Fields Account Registration For Woocommerce custom-fields-account-registration-for-woocommerce allows Privi…

CVSS 7.2 · High

CVE-2025-14503

Published Dec 15, 2025

An overly-permissive IAM trust policy in the Harmonix on AWS framework may allow IAM principals in the same AWS account to escalate privileges via role assumption. The sample code…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-13888

Published Dec 15, 2025

A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in other namespaces,…

CVSS 9.1 · Critical

CVE-2025-14660

Published Dec 14, 2025

A flaw has been found in DecoCMS Mesh up to 1.0.0-alpha.31. Affected by this vulnerability is the function createTool of the file packages/sdk/src/mcp/teams/api.ts of the componen…

CVSS 2.9 · Low

CVE-2025-65807

Published Dec 10, 2025

An issue in sd command v1.0.0 and before allows attackers to escalate privileges to root via a crafted command.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-14089

Published Dec 5, 2025

A vulnerability was identified in Himool ERP up to 2.2. Affected by this issue is the function update_account of the file /api/admin/update_account/ of the component AdminActionVi…

CVSS 2.1 · Low

CVE-2025-14088

Published Dec 5, 2025

A vulnerability was determined in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is an unknown functionality of the file /je/load. This manipulation of the argument Autho…

CVSS 2.1 · Low

CVE-2025-14086

Published Dec 5, 2025

A vulnerability was found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is an unknown function of the file /app-api/v1/members/openid/. The manipulation of the argument openid r…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-14052

Published Dec 5, 2025

A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function getMemberById of the file /mall-ums/app-api/v1/members/. The m…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-55948

Published Dec 4, 2025

This vulnerability fundamentally arises from yzcheng90 X-SpringBoot 6.0's implementation of role-based access control (RBAC) through dual dependency on frontend menu systems and b…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-14016

Published Dec 4, 2025

A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the file /member/readHistory/delete. Such manipulation of the a…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-65842

Published Dec 3, 2025

The Aquarius HelperTool (1.0.003) privileged XPC service on macOS contains multiple flaws that allow local privilege escalation. The service accepts XPC connections from any local…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66296

Published Dec 1, 2025

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin plugin due to the absence of username uniqueness validation…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-13808

Published Dec 1, 2025

A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this vulnerability is the function update of the file orion-ops-api/orion-o…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-13807

Published Dec 1, 2025

A vulnerability was detected in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected is the function MachineKeyController of the file orion-ops-api/orion-op…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-13806

Published Dec 1, 2025

A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-s…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 376-400 of 1,010 CVEsPage 16 of 41