Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-266

MITRE ↗

CWE-266

122
CRITICAL
343
HIGH
567
MEDIUM
41
LOW
1,094 CVEs · Page 20/22
6.7
CVE-2024-37134

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local h

6.7
CVE-2024-39579

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contains an incorrect privilege assignment vulnerability. A local

6.6
CVE-2024-38278

A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.9.0), RUGGEDCOM RMC8388NC V5.X (All ver

6.5
CVE-2023-6815

Incorrect Privilege Assignment vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series Safety CPU R08/16/32/

6.5
CVE-2024-6758

Improper Privilege Management in Sprecher Automation SPRECON-E below version 8.71j allows a remote attacker with low pri

6.5
CVE-2024-20466

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat

6.5
CVE-2024-47653

This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requ

6.5
CVE-2024-11860

A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This af

6.5
CVE-2024-12678

Nomad Community and Nomad Enterprise ("Nomad") allocations are vulnerable to privilege escalation within a namespace thr

6.3
CVE-2024-25083

An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1. When an low-privileged user initiat

6.3
CVE-2024-3013

A flaw has been found in Teledyne FLIR AX8 up to 1.46.16. The impacted element is an unknown function of the file /tools

6.3
CVE-2024-0085

NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged op

6.3
CVE-2024-9082

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been rated as critical. Affected by this iss

6.3
CVE-2024-46540

A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attacke

6.3
CVE-2024-10764

A vulnerability classified as critical has been found in Codezips Online Institute Management System 1.0. This affects a

6.3
CVE-2024-10765

A vulnerability classified as critical was found in Codezips Online Institute Management System up to 1.0. This vulnerab

6.3
CVE-2024-10766

A vulnerability, which was classified as critical, has been found in Codezips Free Exam Hall Seating Management System 1

6.3
CVE-2024-47595

An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access.

6.3
CVE-2024-11484

A vulnerability classified as critical was found in Code4Berry Decoration Management System 1.0. Affected by this vulner

6.3
CVE-2024-11485

A vulnerability, which was classified as critical, has been found in Code4Berry Decoration Management System 1.0. Affect

6.3
CVE-2024-12235

A vulnerability was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 1.0.0. It has been declared a

6.2
CVE-2024-42441

Incorrect privilege assignment in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and

6.0
CVE-2024-23976

When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Applianc

5.4
CVE-2024-25633

eLabFTW is an open source electronic lab notebook for research labs. In an eLabFTW system, one can configure who is allo

5.4
CVE-2024-6322

Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user

5.4
CVE-2024-48941

The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to byp

5.4
CVE-2024-50702

TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an adminis

5.3
CVE-2023-7270

An issue was discovered in SoftMaker Office 2024 / NX before revision 1214 and SoftMaker FreeOffice 2014 before revision

5.3
CVE-2024-10654

A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerab

5.3
CVE-2024-11306

A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. Th

5.3
CVE-2023-26280

IBM Jazz Foundation 7.0.2 and 7.0.3 could allow a user to change their dashboard using a specially crafted HTTP request

5.3
CVE-2024-12347

A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms up to 1.0.0 and classified as critical. This

5.3
CVE-2024-12901

A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown funct

5.3
CVE-2024-13067

A vulnerability was found in CodeAstro Online Food Ordering System 1.0 and classified as critical. This issue affects so

5.2
CVE-2024-23794

An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escala

4.7
CVE-2024-31760

An issue in sanluan flipped-aurora gin-vue-admin 2.4.x allows an attacker to escalate privileges via the Session Expirat

4.7
CVE-2024-12666

A vulnerability has been found in ClassCMS up to 4.8 and classified as critical. Affected by this vulnerability is an un

4.3
CVE-2024-11073

A vulnerability classified as problematic has been found in SourceCodester Hospital Management System 1.0. This affects

4.3
CVE-2024-11486

A vulnerability, which was classified as problematic, was found in Code4Berry Decoration Management System 1.0. This aff

4.3
CVE-2024-50701

TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a

4.2
CVE-2024-7480

An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interfa

4.2
CVE-2024-10978

Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows

4.0
CVE-2023-47140

IBM CICS Transaction Gateway 9.3 could allow a user to transfer or view files due to improper access controls.

CVE-2024-9476

A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to re

CVE-2024-9478

Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Esc

CVE-2024-9479

Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Esc

9.8
CVE-2023-1174

This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected r

8.8
CVE-2023-4153

The BAN Users plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.5.3 due to

8.8
CVE-2023-6009

The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.4 due to in

8.7
CVE-2023-2816

Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via serv

Frequently Asked Questions

What is CWE-266?

CWE-266 (CWE-266) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-266?

There are 1,098 CVE records associated with CWE-266 in our database. Of these, 122 are critical severity, 343 are high severity, and 567 are medium severity.

How can I protect against CWE-266 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-266 using AI-powered security agents.

Detect CWE-266 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-266 vulnerabilities across your infrastructure.

Get Started