A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /mat
A weakness has been identified in fuyang_lipengjun platform 1.0.0. This issue affects the function queryAll of the file
A security vulnerability has been detected in JEPaaS 7.2.8. This vulnerability affects the function doFilterInternal of
A weakness has been identified in YunaiV yudao-cloud up to 2025.09. This affects an unknown part of the file /crm/busine
A security vulnerability has been detected in YunaiV ruoyi-vue-pro up to 2025.09. This vulnerability affects unknown cod
A vulnerability was detected in YunaiV yudao-cloud up to 2025.09. This issue affects some unknown processing of the file
A flaw has been found in YunaiV ruoyi-vue-pro up to 2025.09. Impacted is an unknown function of the file /crm/contact/tr
A weakness has been identified in linlinjava litemall up to 1.8.0. This affects the function WxAftersaleController of th
A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of t
A vulnerability was detected in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file
A weakness has been identified in JeecgBoot up to 3.8.2. Affected is an unknown function of the file /message/sysMessage
A vulnerability was determined in YunaiV yudao-cloud up to 2025.09. Affected by this issue is some unknown functionality
A vulnerability was identified in YunaiV ruoyi-vue-pro up to 2025.09. This affects an unknown part of the file /crm/busi
A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This vulnerability affects unknown code of the f
A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /module/Ap
A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unkno
A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of
A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /periodo-lancamento. E
A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown f
A vulnerability was detected in Tomofun Furbo 360 and Furbo Mini. This vulnerability affects unknown code of the compone
A vulnerability was determined in Sismics Teedy up to 1.11. This affects an unknown function of the file /api/file of th
A vulnerability was identified in macrozheng mall-swarm up to 1.0.3. This affects the function updateAttr of the file /c
A vulnerability was detected in macrozheng mall-swarm up to 1.0.3. Affected by this issue is the function paySuccess of
A vulnerability was detected in WeiYe-Jing datax-web up to 2.1.2. This impacts the function remove/update/pause/start/tr
A vulnerability was detected in code-projects Blog Site 1.0. The affected element is an unknown function of the file /ad
A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function get
A vulnerability was found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is an unknown function of the file /app-api/v1
A vulnerability was determined in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is an unknown functionality of
A vulnerability was identified in Himool ERP up to 2.2. Affected by this issue is the function update_account of the fil
A vulnerability was identified in Ningyuanda TC155 57.0.2.0. This impacts an unknown function of the file /onvif/device_
A weakness has been identified in getmaxun maxun up to 0.0.28. The affected element is the function router.get of the fi
An insufficient access control vulnerability was found in the Red Hat Developer Hub rhdh/rhdh-hub-rhel9 container image.
An issue in hackathon-starter v.8.1.0 allows a remote attacker to escalate privileges via the user.js component.
A flaw has been found in DecoCMS Mesh up to 1.0.0-alpha.31. Affected by this vulnerability is the function createTool of
Incorrect Privilege Assignment vulnerability in Drupal Private content allows Target Influence via Framing.This issue af
A vulnerability, which was classified as critical, has been found in Audi UTR Dashcam 2.0. Affected by this issue is som
A vulnerability was found in code-projects Human Resource Management System 1.0.1 and classified as critical. This issue
Incorrect Privilege Assignment vulnerability in John Luetke Media Author media-author allows Privilege Escalation.This i
/api/user/users in the web GUI for the Cubro EXA48200 network packet broker (build 20231025055018) fixed in V5.0R14.5P4-
A vulnerability has been found in StarSea99 starsea-mall 1.0/2.X and classified as critical. Affected by this vulnerabil
A vulnerability classified as problematic has been found in 274056675 springboot-openai-chatgpt e84f6f5. This affects th
A vulnerability was found in itwanger paicoding 1.0.3. It has been classified as critical. This affects an unknown part
A vulnerability classified as critical has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f
A vulnerability was found in Weitong Mall 1.0.0. It has been classified as critical. This affects an unknown part of the
A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been rated as critical. Affected by this issue
A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /
A vulnerability was determined in jshERP up to 3.5. Affected is an unknown function of the file /jshERP-boot/user/delete
The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations fo
A security flaw has been discovered in elunez eladmin 1.1. Impacted is the function deleteFile of the component LocalSto
A security flaw has been discovered in Papermerge DMS up to 3.5.3. This issue affects some unknown processing of the com
Frequently Asked Questions
What is CWE-266?
CWE-266 (CWE-266) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-266?
There are 1,098 CVE records associated with CWE-266 in our database. Of these, 122 are critical severity, 343 are high severity, and 567 are medium severity.
How can I protect against CWE-266 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-266 using AI-powered security agents.
Detect CWE-266 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-266 vulnerabilities across your infrastructure.
Get Started