A vulnerability classified as problematic was found in NOYAFA/Xiami LF9 Pro up to 20250611. Affected by this vulnerabili
A vulnerability, which was classified as problematic, was found in linlinjava litemall 1.8.0. Affected is an unknown fun
A vulnerability was found in Portabilis i-Educar up to 2.9.0. It has been declared as critical. This vulnerability affec
Incorrect Privilege Assignment vulnerability in chandrashekharsahu Site Offline site-offline allows Exploiting Incorrect
A vulnerability was identified in fuyang_lipengjun platform 1.0.0. This issue affects the function AdController of the f
A vulnerability was determined in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Ap
A vulnerability was identified in elunez eladmin up to 2.7. This affects the function queryErrorLogDetail of the file /a
A security flaw has been discovered in JeecgBoot up to 3.8.2. Affected by this issue is some unknown functionality of th
A vulnerability has been found in newbee-mall up to 613a662adf1da7623ec34459bc83e3c1b12d8ce7. This issue affects the fun
A vulnerability was identified in fuyang_lipengjun platform 1.0. This affects the function AttributeCategoryController o
A security flaw has been discovered in fuyang_lipengjun platform 1.0. This impacts the function AttributeController of t
A weakness has been identified in fuyang_lipengjun platform 1.0. Affected is the function BrandController of the file /b
A security vulnerability has been detected in fuyang_lipengjun platform 1.0. This issue affects the function UserCouponC
A vulnerability was detected in fuyang_lipengjun platform 1.0. Impacted is the function TopicController of the file /top
A flaw has been found in fuyang_lipengjun platform 1.0. The affected element is the function TopicCategoryController of
A vulnerability has been found in fuyang_lipengjun platform 1.0. The impacted element is the function SysSmsLogControlle
A security flaw has been discovered in JeecgBoot up to 3.8.2. The affected element is an unknown function of the file /s
A weakness has been identified in JeecgBoot up to 3.8.2. The impacted element is an unknown function of the file /sys/ro
A security vulnerability has been detected in JeecgBoot up to 3.8.2. This affects an unknown function of the file /sys/p
A vulnerability was detected in JeecgBoot up to 3.8.2. This impacts an unknown function of the file /sys/tenant/exportXl
A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. This vulnerability affects
A vulnerability was determined in JhumanJ OpnForm up to 1.9.3. Impacted is an unknown function of the file /edit. Execut
A vulnerability has been found in dulaiduwang003 TIME-SEA-PLUS up to fb299162f18498dd9cf17da906886d80a077d53b. This affe
A security flaw has been discovered in macrozheng mall-swarm and mall up to 1.0.3. This impacts the function detail of t
A vulnerability was detected in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected is the funct
A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of th
A weakness has been identified in youlaitech youlai-mall 1.0.0/2.0.0. This impacts the function getMemberByMobile of the
A security vulnerability has been detected in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function submitOrderPa
A security vulnerability has been detected in macrozheng mall up to 1.0.3. This vulnerability affects unknown code of th
A vulnerability has been found in code-projects Student File Management System 1.0. The affected element is an unknown f
PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has potentially elevated
In multiple functions of RoleService.java, there is a possible permission squatting vulnerability due to a logic error i
In createMultiProfilePagerAdapter of ChooserActivity.java , there is a possible way for an app to launch the ChooserActi
In multiple locations, there is a possible way to overlay biometrics due to a tapjacking/overlay attack. This could lead
In apk-versions.txt, there is a possible corruption of telemetry opt-in settings on other watches when setting up a new
In android_app of Android.bp, there is a possible way to launch any activity as a system user. This could lead to local
A vulnerability was determined in Tomofun Furbo 360 and Furbo Mini. This impacts an unknown function of the component Tr
A vulnerability, which was classified as problematic, has been found in Shenzhen Sixun Software Sixun Shanghui Group Bus
A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750
A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been declared as problematic. This vulne
A vulnerability, which was classified as problematic, was found in mannaandpoem OpenManus up to 2025.3.13. This affects
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a
Deno is a JavaScript, TypeScript, and WebAssembly runtime. In versions prior to 2.5.3 and 2.2.15, `Deno.FsFile.prototype
A vulnerability classified as problematic has been found in y_project RuoYi 4.8.0. Affected is an unknown function of th
A vulnerability, which was classified as problematic, was found in 70mai M300 up to 20250611. Affected is an unknown fun
A vulnerability was found in Buttercup buttercup-browser-extension up to 0.14.2. Affected by this vulnerability is an un
A flaw has been found in elunez eladmin up to 2.7. This impacts the function updateUserEmail of the file /api/users/upda
A vulnerability was determined in JeecgBoot up to 3.8.2. This issue affects some unknown processing of the file /api/get
A vulnerability was identified in JeecgBoot up to 3.8.2. Impacted is an unknown function of the file /sys/tenant/deleteB
A vulnerability was identified in youlaitech youlai-mall 1.0.0/2.0.0. The impacted element is the function orderService.
Frequently Asked Questions
What is CWE-266?
CWE-266 (CWE-266) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-266?
There are 1,098 CVE records associated with CWE-266 in our database. Of these, 122 are critical severity, 343 are high severity, and 567 are medium severity.
How can I protect against CWE-266 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-266 using AI-powered security agents.
Detect CWE-266 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-266 vulnerabilities across your infrastructure.
Get Started