A vulnerability was determined in SourceCodester Client Database Management System 1.0. The impacted element is an unkno
A vulnerability was identified in D-Link DIR-816 1.10CNB05. The impacted element is an unknown function of the file redi
A security vulnerability has been detected in D-Link DIR-823G 1.0.2B05. The affected element is the function GetDDNSSett
A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS
A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. The impacted element
A security vulnerability has been detected in chatwoot up to 4.11.1. The affected element is an unknown function of the
A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerabil
A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impacted is an unknown function of the file /
A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Th
A security vulnerability has been detected in perfree go-fastdfs-web up to 1.3.7. This affects an unknown part of the fi
A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. The affected element is an unknown function of
A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0. This affects an unknown function of the
A flaw has been found in nextlevelbuilder GoClaw and GoClaw Lite up to 3.8.5. This affects an unknown function of the co
A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the fil
A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown fun
A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Th
A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepa
A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client man
A vulnerability has been found in SourceCodester Water Billing Management System 1.0. This issue affects some unknown pr
A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This impacts the function ca
Unauthenticated Privilege Escalation in Listdom <= 5.5.0 versions.
A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1
Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perfor
A weakness has been identified in SourceCodester Inventory Management System 1.0. This vulnerability affects unknown cod
A weakness has been identified in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This affects the fun
A flaw has been found in SourceCodester Onlne Examination & Learning Management System 1.0. The impacted element is an u
A security vulnerability has been detected in SourceCodester Onlne Examination & Learning Management System 1.0. This af
A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. This affects the function IPAllowlist of the
A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class o
Incorrect Privilege Assignment vulnerability in XforWooCommerce Product Filter for WooCommerce prdctfltr allows Privileg
Incorrect Privilege Assignment vulnerability in ameliabooking Amelia ameliabooking allows Privilege Escalation.This issu
Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privil
Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component
Editor Privilege Escalation in AI Engine <= 3.4.9 versions.
Shop manager Privilege Escalation in WooCommerce Cart Abandonment Recovery < 2.1.0 versions.
Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.
HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to intr
Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.
The Linuxulator determined whether a binary was set-user-ID or set-group-ID by checking the P_SUGID process flag. Durin
A vulnerability has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this issue is some unknown func
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that all
OpenClaw before 2026.4.14 contains an authorization context reuse vulnerability in collect-mode queue batches that allow
Subscriber Privilege Escalation in JetFormBuilder <= 3.6.1 versions.
Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an incorrect privileg
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.1, contains an incorrect p
An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges vi
A vulnerability was determined in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This impac
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of se
A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where thi
A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some
Frequently Asked Questions
What is CWE-266?
CWE-266 (CWE-266) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-266?
There are 1,098 CVE records associated with CWE-266 in our database. Of these, 122 are critical severity, 343 are high severity, and 567 are medium severity.
How can I protect against CWE-266 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-266 using AI-powered security agents.
Detect CWE-266 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-266 vulnerabilities across your infrastructure.
Get Started