Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-266

MITRE ↗

CWE-266

122
CRITICAL
343
HIGH
567
MEDIUM
41
LOW
1,094 CVEs · Page 21/22
8.4
CVE-2023-28956

IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges

8.4
CVE-2023-30680

Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privi

8.4
CVE-2023-30691

Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to privilege escalation.

8.2
CVE-2023-5913

Incorrect Privilege Assignment vulnerability in opentext Fortify ScanCentral DAST. The vulnerability could be exploited

7.8
CVE-2023-20957

In onAttach of SettingsPreferenceFragment.java, there is a possible bypass of Factory Reset Protections due to a confuse

7.8
CVE-2023-21269

In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the back

7.6
CVE-2022-4441

Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated u

7.6
CVE-2023-25591

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenti

7.6
CVE-2023-5077

The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditio

7.5
CVE-2023-1874

The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.3.7. T

7.4
CVE-2023-3518

HashiCorp Consul and Consul Enterprise 1.16.0 when using JWT Auth for service mesh incorrectly allows/denies access rega

5.9
CVE-2022-4041

Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated u

5.4
CVE-2023-39173

In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full account access

5.3
CVE-2023-3300

HashiCorp Nomad and Nomad Enterprise 0.11.0 up to 1.5.6 and 1.4.1 HTTP search API can reveal names of available CSI plug

5.0
CVE-2023-3114

Terraform Enterprise since v202207-1 did not properly implement authorization rules for agent pools, allowing the worksp

4.4
CVE-2023-2485

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15.10.8, all versions star

4.2
CVE-2023-3775

A Vault Enterprise Sentinel Role Governing Policy created by an operator to restrict access to resources in one namespac

4.1
CVE-2023-3072

HashiCorp Nomad and Nomad Enterprise 0.7.0 up to 1.5.6 and 1.4.10 ACL policies using a block without a label generates u

3.2
CVE-2023-29066

The FACSChorus software does not properly assign data access privileges for operating system user accounts. A non-admini

8.8
CVE-2022-20759

A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA)

7.9
CVE-2022-20855

A vulnerability in the self-healing functionality of Cisco IOS XE Software for Embedded Wireless Controllers on Catalyst

7.8
CVE-2022-20681

A vulnerability in the CLI of Cisco IOS XE Software for Cisco Catalyst 9000 Family Switches and Cisco Catalyst 9000 Fami

7.8
CVE-2020-10728

A flaw was found in automationbroker/apb container in versions up to and including 2.0.4-1. This container grants all us

7.6
CVE-2022-1746

The authentication mechanism used by poll workers to administer voting using the tested version of Dominion Voting Syste

7.3
CVE-2022-4273

A vulnerability, which was classified as critical, has been found in SourceCodester Human Resource Management System 1.0

7.2
CVE-2022-2626

Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.

6.5
CVE-2022-1225

Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6.

6.5
CVE-2022-20782

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat

6.5
CVE-2022-20819

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat

6.3
CVE-2022-3436

A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance System 1.0. Affected by t

6.3
CVE-2022-3458

A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and classified as critical. Affect

6.3
CVE-2022-3496

A vulnerability was found in SourceCodester Human Resource Management System 1.0 and classified as critical. This issue

6.3
CVE-2022-3735

A vulnerability was found in seccome Ehoney. It has been rated as critical. This issue affects some unknown processing o

6.3
CVE-2022-3770

A vulnerability classified as critical was found in Yunjing CMS. This vulnerability affects unknown code of the file /in

6.3
CVE-2022-3771

A vulnerability, which was classified as critical, has been found in easyii CMS. This issue affects the function file of

6.3
CVE-2022-3944

A vulnerability was found in jerryhanjj ERP. It has been declared as critical. Affected by this vulnerability is the fun

6.3
CVE-2022-4272

A vulnerability, which was classified as critical, has been found in FeMiner wms. Affected by this issue is some unknown

6.3
CVE-2022-4276

A vulnerability was found in House Rental System and classified as critical. Affected by this issue is some unknown func

6.3
CVE-2022-4281

A vulnerability has been found in Facepay 1.0 and classified as critical. Affected by this vulnerability is an unknown f

5.5
CVE-2022-42825

This issue was addressed by removing additional entitlements. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchO

5.4
CVE-2022-2637

Incorrect Privilege Assignment vulnerability in Hitachi Hitachi Storage Plug-in for VMware vCenter allows remote authent

5.0
CVE-2022-4613

A vulnerability was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as cr

4.7
CVE-2022-3549

A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been rated as problematic.

4.7
CVE-2022-4232

A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. Affected i

4.3
CVE-2022-3826

A vulnerability was found in Huaxia ERP. It has been classified as problematic. This affects an unknown part of the file

4.3
CVE-2022-4280

A vulnerability, which was classified as problematic, has been found in Dot Tech Smart Campus System. Affected by this i

4.3
CVE-2022-3876

A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Br

8.8
CVE-2021-1303

A vulnerability in the user management roles of Cisco DNA Center could allow an authenticated, remote attacker to execut

7.8
CVE-2019-19349

An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-me

7.8
CVE-2019-19350

An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as ship

Frequently Asked Questions

What is CWE-266?

CWE-266 (CWE-266) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-266?

There are 1,098 CVE records associated with CWE-266 in our database. Of these, 122 are critical severity, 343 are high severity, and 567 are medium severity.

How can I protect against CWE-266 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-266 using AI-powered security agents.

Detect CWE-266 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-266 vulnerabilities across your infrastructure.

Get Started