Skip to main content

CWE archive

CWE-266 CVEs

Programmatic archive

1,060 CVEs tagged with CWE-266116 Critical, 291 High, 383 Medium, 269 Low, 1 Unrated.

CVE-2025-6736

Published Jun 27, 2025

A vulnerability classified as critical was found in juzaweb CMS 3.4.2. Affected by this vulnerability is an unknown functionality of the file /admin-cp/theme/install of the compon…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-6735

Published Jun 27, 2025

A vulnerability classified as critical has been found in juzaweb CMS 3.4.2. Affected is an unknown function of the file /admin-cp/imports of the component Import Page. The manipul…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-6702

Published Jun 26, 2025

A vulnerability, which was classified as problematic, was found in linlinjava litemall 1.8.0. Affected is an unknown function of the file /wx/comment/post. The manipulation of the…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-41255

Published Jun 25, 2025

Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store…

CVSS 8.0 · High
evidence mentions
2
Buzz score
16.0

CVE-2025-23260

Published Jun 24, 2025

NVIDIA AIStore contains a vulnerability in the AIS Operator where a user may gain elevated k8s cluster access by using the ServiceAccount attached to the ClusterRole. A successful…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-6531

Published Jun 24, 2025

A vulnerability was found in SIFUSM/MZZYG BD S1 up to 20250611. It has been declared as problematic. This vulnerability affects unknown code of the component RTSP Live Video Strea…

CVSS 2.1 · Low

CVE-2025-6527

Published Jun 23, 2025

A vulnerability, which was classified as problematic, was found in 70mai M300 up to 20250611. Affected is an unknown function of the component Web Server. The manipulation leads t…

CVSS 1.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-6525

Published Jun 23, 2025

A vulnerability classified as problematic was found in 70mai 1S up to 20250611. This vulnerability affects unknown code of the file /cgi-bin/Config.cgi?action=set of the component…

CVSS 2.1 · Low

CVE-2025-6099

Published Jun 16, 2025

A vulnerability was found in szluyu99 gin-vue-blog up to 61dd11ccd296e8642a318ada3ef7b3f7776d2410. It has been declared as critical. This vulnerability affects unknown code of the…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2025-49580

Published Jun 13, 2025

XWiki is a generic wiki platform. From 8.2 and 7.4.5 until 17.1.0-rc-1, 16.10.4, and 16.4.7, pages can gain script or programming rights when they contain a link and the target of…

CVSS 8.5 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-4228

Published Jun 13, 2025

An incorrect privilege assignment vulnerability in Palo Alto Networks Cortex® XDR Broker VM allows an authenticated administrative user to execute certain files available within t…

CVSS 4.6 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-4922

Published Jun 11, 2025

Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identified as CVE-2025-4922…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-48129

Published Jun 9, 2025

Incorrect Privilege Assignment vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light excel-like-price-change-for-woocommerce-and-…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-47561

Published Jun 9, 2025

Incorrect Privilege Assignment vulnerability in RomanCode MapSVG mapsvg allows Privilege Escalation.This issue affects MapSVG: from n/a through < 8.6.13.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-23974

Published Jun 9, 2025

Incorrect Privilege Assignment vulnerability in ifkooo One-Login one-login allows Privilege Escalation.This issue affects One-Login: from n/a through <= 1.4.

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-5791

Published Jun 6, 2025

A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups…

CVSS 7.1 · High
evidence mentions
7
Buzz score
40.3

CVE-2025-48911

Published Jun 6, 2025

Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-5649

Published Jun 5, 2025

A vulnerability classified as critical has been found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /admin/core/new_user of the…

CVSS 6.9 · Medium
evidence mentions
5
Buzz score
30.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-46204

Published Jun 4, 2025

An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
20.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-46203

Published Jun 4, 2025

An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
20.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-5522

Published Jun 3, 2025

A vulnerability was found in jack0240 魏 bskms 蓝天幼儿园管理系统 up to dffe6640b5b54d8e29da6f060e0493fea74b3fad. It has been rated as critical. Affected by this issue is some unknown funct…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2025-5511

Published Jun 3, 2025

A vulnerability, which was classified as critical, has been found in quequnlong shiyi-blog up to 1.2.1. This issue affects some unknown processing of the file /dev api/app/album/p…

CVSS 6.9 · Medium
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-5429

Published Jun 2, 2025

A vulnerability classified as critical was found in juzaweb CMS up to 3.4.2. This vulnerability affects unknown code of the file /admin-cp/plugin/install of the component Plugins…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-5428

Published Jun 2, 2025

A vulnerability classified as critical has been found in juzaweb CMS up to 3.4.2. This affects an unknown part of the file /admin-cp/log-viewer of the component Error Logs Page. T…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 626-650 of 1,060 CVEsPage 26 of 43