Skip to main content

CWE archive

CWE-266 CVEs

Programmatic archive

1,010 CVEs tagged with CWE-266109 Critical, 273 High, 374 Medium, 253 Low, 1 Unrated.

CVE-2025-2334

Published Mar 15, 2025

A vulnerability classified as problematic has been found in 274056675 springboot-openai-chatgpt e84f6f5. This affects the function deleteChat of the file /api/mjkj-chat/chat/ai/de…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1653

Published Mar 15, 2025

The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.0. This is due to the stm_l…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-2320

Published Mar 14, 2025

A vulnerability has been found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by this vulnerability is the function submit of the file /api/bl…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2218

Published Mar 12, 2025

A vulnerability has been found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This vulnerability affects unknown code of the file /api/system/other of the compon…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2114

Published Mar 9, 2025

A vulnerability, which was classified as problematic, has been found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 7. This issue affects some unknown…

CVSS 6.3 · Medium

CVE-2025-2089

Published Mar 7, 2025

A vulnerability has been found in StarSea99 starsea-mall 1.0/2.X and classified as critical. Affected by this vulnerability is the function updateUserInfo of the file /personal/up…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-21092

Published Mar 5, 2025

GMOD Apollo does not have sufficient logical or access checks when updating a user's information. This could result in an attacker being able to escalate privileges for themselves…

CVSS 7.1 · High

CVE-2024-55570

Published Mar 3, 2025

/api/user/users in the web GUI for the Cubro EXA48200 network packet broker (build 20231025055018) fixed in V5.0R14.5P4-V3.3R1 allows remote authenticated users of the application…

CVSS 5.4 · Medium

CVE-2025-1847

Published Mar 3, 2025

A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to improper authorization. T…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1815

Published Mar 2, 2025

A vulnerability, which was classified as critical, was found in pbrong hrms up to 1.0.1. This affects the function HrmsDB of the file \resource\resource.go. The manipulation of th…

CVSS 6.9 · Medium

CVE-2025-1806

Published Mar 2, 2025

A vulnerability, which was classified as problematic, has been found in Eastnets PaymentSafe 2.5.26.0. Affected by this issue is some unknown functionality of the file /Default.as…

CVSS 5.3 · Medium

CVE-2024-8420

Published Feb 28, 2025

The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. This is due to the plugin allowing a user to supply the 'role…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-25767

Published Feb 21, 2025

A vertical privilege escalation vulnerability in the component /controller/UserController.java of MRCMS v3.1.2 allows attackers to arbitrarily delete users via a crafted request.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56000

Published Feb 18, 2025

Incorrect Privilege Assignment vulnerability in SeventhQueen K Elements k-elements allows Privilege Escalation.This issue affects K Elements: from n/a through < 5.4.0.

CVSS 9.8 · Critical

CVE-2025-26523

Published Feb 14, 2025

This vulnerability exists in RupeeWeb trading platform due to insufficient authorization controls on certain API endpoints handling addition and deletion operations. Successful ex…

CVSS 7.4 · High

CVE-2025-1226

Published Feb 12, 2025

A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown code of the file /oa/setup/setup.jsp. The manipulation lea…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12213

Published Feb 12, 2025

The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.3.16. This is due to the plugin allowing a user to supply the 'role' field…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-13421

Published Feb 12, 2025

The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricti…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-40591

Published Feb 11, 2025

An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated adm…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1078

Published Feb 6, 2025

A vulnerability has been found in AppHouseKitchen AlDente Charge Limiter up to 1.29 on macOS and classified as critical. This vulnerability affects the function shouldAcceptNewCon…

CVSS 4.8 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2024-49348

Published Feb 5, 2025

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 allows restricting acc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24648

Published Feb 4, 2025

Incorrect Privilege Assignment vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Privilege Escalation.This issue affects Admin and Site Enhanc…

CVSS 7.5 · High
Showing 726-750 of 1,010 CVEsPage 30 of 41