Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-266

MITRE ↗

CWE-266

122
CRITICAL
343
HIGH
567
MEDIUM
41
LOW
1,094 CVEs · Page 19/22
8.8
CVE-2024-8253

The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to

8.8
CVE-2024-21743

Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez L

8.8
CVE-2024-22303

Incorrect Privilege Assignment vulnerability in favethemes Houzez allows Privilege Escalation.This issue affects Houzez:

8.8
CVE-2024-49219

Incorrect Privilege Assignment vulnerability in themexpo RS-Members rs-members allows Privilege Escalation.This issue af

8.8
CVE-2024-49608

Incorrect Privilege Assignment vulnerability in gerryworks GERRYWORKS Post by Mail gerryworks-post-by-mail allows Privil

8.8
CVE-2024-50481

Incorrect Privilege Assignment vulnerability in stackthemes Bstone Demo Importer bstone-demo-importer allows Privilege E

8.8
CVE-2024-50504

Incorrect Privilege Assignment vulnerability in webxmedia Bulk Change Role bulk-role-change allows Privilege Escalation.

8.8
CVE-2024-50506

Incorrect Privilege Assignment vulnerability in azexo Marketing Automation by AZEXO marketing-automation-by-azexo allows

8.8
CVE-2024-54365

Incorrect Privilege Assignment vulnerability in Knowhalim KH Easy User Settings kh-easy-user-settings allows Privilege E

8.6
CVE-2023-50437

An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/defau

8.6
CVE-2024-27453

In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the

8.6
CVE-2024-25632

eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a us

8.4
CVE-2024-36534

Insecure permissions in hwameistor v0.14.3 allows attackers to access sensitive data and escalate privileges by obtainin

8.1
CVE-2024-27273

IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose app

8.1
CVE-2024-50550

Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege

8.0
CVE-2023-38296

Various software builds for the following TCL 30Z and TCL A3X devices leak the ICCID to a system property that can be ac

7.8
CVE-2023-40109

In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions

7.8
CVE-2024-23288

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma

7.8
CVE-2024-20320

A vulnerability in the SSH client feature of Cisco IOS XR Software for Cisco 8000 Series Routers and Cisco Network Conve

7.8
CVE-2024-31771

Insecure Permission vulnerability in TotalAV v.6.0.740 allows a local attacker to escalate privileges via a crafted file

7.8
CVE-2024-20389

A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated

7.8
CVE-2024-36587

Insecure permissions in DNSCrypt-proxy v2.0.0alpha9 to v2.1.5 allows non-privileged attackers to escalate privileges to

7.8
CVE-2024-31315

In multiple functions of ManagedServices.java, there is a possible way to hide an app with notification access in the De

7.8
CVE-2024-41139

Incorrect privilege assignment vulnerability exists in SKYSEA Client View Ver.6.010.06 to Ver.19.210.04e. If a user who

7.8
CVE-2024-34738

In multiple functions of AppOpsService.java, there is a possible way for unprivileged apps to read their own restrictRea

7.8
CVE-2024-47904

A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fir

7.8
CVE-2024-29119

A vulnerability has been identified in Spectrum Power 7 (All versions < V24Q3). The affected product contains several ro

7.8
CVE-2024-12786

A vulnerability, which was classified as critical, was found in X1a0He Adobe Downloader up to 1.3.1 on macOS. Affected i

7.8
CVE-2024-52048

A LogServer link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on

7.8
CVE-2024-52049

A LogServer link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on

7.7
CVE-2024-4555

Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specif

7.5
CVE-2021-47241

In the Linux kernel, the following vulnerability has been resolved: ethtool: strset: fix message length calculation Ou

7.5
CVE-2024-37293

The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and region

7.5
CVE-2024-31912

IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under certain configurations du

7.5
CVE-2024-40681

IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifically define

7.5
CVE-2024-46511

LoadZilla LLC LoadLogic v1.4.3 was discovered to contain insecure permissions vulnerability which allows a remote attack

7.5
CVE-2020-25720

A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory

7.5
CVE-2024-9779

A flaw was found in Open Cluster Management (OCM) when a user has access to the worker nodes which contain the cluster-m

7.4
CVE-2024-27275

IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority req

7.3
CVE-2024-12782

A vulnerability has been found in Fujifilm Business Innovation Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 an

7.3
CVE-2024-13030

A vulnerability was found in D-Link DIR-823G 1.0.2B05_20181207. It has been rated as critical. This issue affects the fu

7.2
CVE-2024-4870

The Frontend Registration – Contact Form 7 plugin for WordPress is vulnerable to privilege escalation in versions up to,

7.2
CVE-2024-9519

The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check

7.2
CVE-2024-9180

A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or

7.1
CVE-2024-45187

Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high p

6.8
CVE-2023-5080

A privilege escalation vulnerability was reported in some Lenovo tablet products that could allow local applications acc

6.8
CVE-2024-45759

Dell PowerProtect Data Domain, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an escalation of

6.7
CVE-2023-6477

An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting

6.7
CVE-2024-27460

A privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below.

6.7
CVE-2024-37132

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an incorrect privilege assignment vulnerability. A high p

Frequently Asked Questions

What is CWE-266?

CWE-266 (CWE-266) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-266?

There are 1,098 CVE records associated with CWE-266 in our database. Of these, 122 are critical severity, 343 are high severity, and 567 are medium severity.

How can I protect against CWE-266 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-266 using AI-powered security agents.

Detect CWE-266 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-266 vulnerabilities across your infrastructure.

Get Started