Skip to main content

CWE archive

CWE-266 CVEs

Programmatic archive

1,011 CVEs tagged with CWE-266109 Critical, 273 High, 374 Medium, 254 Low, 1 Unrated.

CVE-2025-25023

Published Apr 9, 2025

IBM Security Guardium 11.4 and 12.1 could allow a privileged user to read any file on the system due to incorrect privilege assignment.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-23407

Published Apr 9, 2025

Incorrect privilege assignment vulnerability in the WEB UI (the setting page) exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a remote attacker who can log in to the p…

CVSS 4.3 · Medium

CVE-2025-3398

Published Apr 8, 2025

A vulnerability classified as critical was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the function configure of the file blogserver/src/main/java/org/sang…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3325

Published Apr 6, 2025

A vulnerability, which was classified as problematic, was found in iteaj iboot 物联网网关 1.1.3. This affects an unknown part of the file /core/admin/pwd of the component Admin Passwor…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3305

Published Apr 5, 2025

A vulnerability has been found in 1902756969/code-projects IKUN_Library 1.0 and classified as problematic. This vulnerability affects the function addInterceptors of the file MvcC…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3298

Published Apr 5, 2025

A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /oew…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3256

Published Apr 4, 2025

A vulnerability was found in xujiangfei admintwo 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user/updateSet. The manipula…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3255

Published Apr 4, 2025

A vulnerability was found in xujiangfei admintwo 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /user/home. The m…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51800

Published Apr 4, 2025

Incorrect Privilege Assignment vulnerability in Favethemes Homey allows Privilege Escalation.This issue affects Homey: from n/a through 2.4.1.

CVSS 9.8 · Critical

CVE-2025-31420

Published Apr 4, 2025

Incorrect Privilege Assignment vulnerability in Tomdever wpForo Forum wpforo allows Privilege Escalation.This issue affects wpForo Forum: from n/a through <= 2.4.2.

CVSS 7.6 · High

CVE-2025-3237

Published Apr 4, 2025

A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue affects some unknown processing of the file /goform/wrlwpsset. The manipulation…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3236

Published Apr 4, 2025

A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vulnerability affects unknown code of the file /goform/VirSerDMZ of the component W…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3202

Published Apr 4, 2025

A vulnerability classified as critical has been found in ageerle ruoyi-ai up to 2.0.0. Affected is an unknown function of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruo…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3199

Published Apr 4, 2025

A vulnerability was found in ageerle ruoyi-ai up to 2.0.1 and classified as critical. Affected by this issue is some unknown functionality of the file ruoyi-modules/ruoyi-system/s…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-31560

Published Apr 1, 2025

Incorrect Privilege Assignment vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Privilege Escalation.This issue affects Salon booking system: from…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-29036

Published Apr 1, 2025

An issue in hackathon-starter v.8.1.0 allows a remote attacker to escalate privileges via the user.js component.

CVSS 5.9 · Medium

CVE-2025-27095

Published Mar 31, 2025

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.8.0 and 3.10.18, an attacker with a low-privileged account can access…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2996

Published Mar 31, 2025

A vulnerability was found in Tenda FH1202 1.2.0.14(408) and classified as critical. This issue affects some unknown processing of the file /goform/SysToolDDNS of the component Web…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2995

Published Mar 31, 2025

A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. This vulnerability affects unknown code of the file /goform/SysToolChangePwd of the compon…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2994

Published Mar 31, 2025

A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). This affects an unknown part of the file /goform/qossetting of the component Web Manage…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2993

Published Mar 31, 2025

A vulnerability, which was classified as critical, has been found in Tenda FH1202 1.2.0.14(408). Affected by this issue is some unknown functionality of the file /default.cfg. The…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2992

Published Mar 31, 2025

A vulnerability classified as critical was found in Tenda FH1202 1.2.0.14(408). Affected by this vulnerability is an unknown functionality of the file /goform/AdvSetWrlsafeset of…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2991

Published Mar 31, 2025

A vulnerability classified as critical has been found in Tenda FH1202 1.2.0.14(408). Affected is an unknown function of the file /goform/AdvSetWrlmacfilter of the component Web Ma…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2990

Published Mar 31, 2025

A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue affects some unknown processing of the file /goform/AdvSetWrlGstset of the compo…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2989

Published Mar 31, 2025

A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vulnerability affects unknown code of the file /goform/AdvSetWrl of the component W…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 676-700 of 1,011 CVEsPage 28 of 41