Incorrect Privilege Assignment vulnerability in Booking Activities Team Booking Activities booking-activities allows Pri
Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A
Incorrect Privilege Assignment vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submis
Incorrect Privilege Assignment vulnerability in wordpresschef Salon Booking System Pro salon-booking-plugin-pro allows P
Incorrect Privilege Assignment vulnerability in wpeverest User Registration user-registration allows Privilege Escalatio
A weakness has been identified in Besen BS20 EV Charging Station up to 20260426. Affected by this issue is some unknown
Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions.
An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors r
A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can e
Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions.
Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could
Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to versio
A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts
NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM
Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
A security vulnerability has been detected in DVDFab Virtual Drive 2.0.0.5. Impacted is an unknown function in the libra
A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This vulnerability affects unknown code in th
A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issue affects some unknown processing in the
A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in the library amwrtdrv.s
A vulnerability was identified in EaseUS Partition Master up to 14.5. The affected element is an unknown function in the
A security flaw has been discovered in EaseUS Partition Master up to 14.5. The impacted element is an unknown function i
A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown function in the librar
A vulnerability has been found in Ezbsystems UltraISO Premium Edition up to 9.76. Affected by this issue is some unknown
A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown function
A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functional
A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Fil
A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code o
A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C
A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys
A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in th
A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unkn
Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d651197475f69 contains a potential incorrect priv
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.
Subscriber Privilege Escalation in MultiLoca <= 4.2.15 versions.
A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security harde
Decidim is a participatory democracy framework. Starting in version 0.19.0 and prior to versions 0.30.5 and 0.31.1, a vu
Contributor Privilege Escalation in LatePoint <= 5.5.1 versions.
A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functi
A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 u
Incorrect Privilege Assignment vulnerability in Themefic Hydra Booking hydra-booking allows Privilege Escalation.This is
A vulnerability has been found in zhanghuanhao LibrarySystem 图书馆管理系统 up to 1.1.1. This impacts an unknown function of th
A vulnerability was found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This affects an
A weakness has been identified in funadmin up to 7.1.0-rc4. This affects the function setConfig of the file app/backend/
A vulnerability has been found in SourceCodester Student Result Management System 1.0. The affected element is an unknow
A vulnerability was determined in SourceCodester Student Result Management System 1.0. The impacted element is an unknow
A flaw has been found in SourceCodester Client Database Management System 1.0. Affected is an unknown function of the fi
A vulnerability has been found in SourceCodester Client Database Management System 1.0/3.1. Impacted is an unknown funct
Frequently Asked Questions
What is CWE-266?
CWE-266 (CWE-266) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-266?
There are 1,098 CVE records associated with CWE-266 in our database. Of these, 122 are critical severity, 343 are high severity, and 567 are medium severity.
How can I protect against CWE-266 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-266 using AI-powered security agents.
Detect CWE-266 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-266 vulnerabilities across your infrastructure.
Get Started