Skip to main content

CWE archive

CWE-266 CVEs

Programmatic archive

1,006 CVEs tagged with CWE-266107 Critical, 272 High, 374 Medium, 252 Low, 1 Unrated.

CVE-2025-62007

Published Oct 22, 2025

Incorrect Privilege Assignment vulnerability in bPlugins Voice Feedback voice-feedback allows Privilege Escalation.This issue affects Voice Feedback: from n/a through <= 1.0.3.

CVSS 8.8 · High

CVE-2025-60222

Published Oct 22, 2025

Incorrect Privilege Assignment vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Privilege Escalation.This issue affects SUMO Memberships f…

CVSS 8.8 · High

CVE-2025-60220

Published Oct 22, 2025

Incorrect Privilege Assignment vulnerability in pebas CouponXxL couponxxl allows Privilege Escalation.This issue affects CouponXxL: from n/a through <= 3.0.0.

CVSS 9.8 · Critical

CVE-2025-60211

Published Oct 22, 2025

Incorrect Privilege Assignment vulnerability in extendons WooCommerce Registration Fields Plugin - Custom Signup Fields extendons-registration-fields allows Privilege Escalation.T…

CVSS 8.8 · High

CVE-2025-59580

Published Oct 22, 2025

Incorrect Privilege Assignment vulnerability in GoodLayers Goodlayers Core goodlayers-core allows Privilege Escalation.This issue affects Goodlayers Core: from n/a through < 2.1.7.

CVSS 8.8 · High

CVE-2025-53428

Published Oct 22, 2025

Incorrect Privilege Assignment vulnerability in N-Media Simple User Registration wp-registration allows Privilege Escalation.This issue affects Simple User Registration: from n/a…

CVSS 8.8 · High

CVE-2025-53425

Published Oct 22, 2025

Incorrect Privilege Assignment vulnerability in Dokan, Inc. Dokan dokan-lite allows Privilege Escalation.This issue affects Dokan: from n/a through <= 4.1.3.

CVSS 7.2 · High

CVE-2025-49924

Published Oct 22, 2025

Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privilege Escalation.This issue affects Wholesale Suite: from n/a…

CVSS 7.2 · High

CVE-2025-48082

Published Oct 22, 2025

Incorrect Privilege Assignment vulnerability in Progress Planner Progress Planner progress-planner allows Privilege Escalation.This issue affects Progress Planner: from n/a throug…

CVSS 8.8 · High

CVE-2025-11853

Published Oct 16, 2025

A vulnerability was determined in Sismics Teedy up to 1.11. This affects an unknown function of the file /api/file of the component API Endpoint. Executing a manipulation can lead…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-10577

Published Oct 15, 2025

Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege.…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-10576

Published Oct 15, 2025

Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege.…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-10038

Published Oct 15, 2025

The Binary MLM Plan plugin for WordPress is vulnerable to limited Privilege Escalation in all versions up to, and including, 3.0. This is due to bmp_user role granting all users w…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
31.1

CVE-2025-11554

Published Oct 9, 2025

A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown functionality of the file app/Http/Controllers/AccessLevelCo…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-11440

Published Oct 8, 2025

A vulnerability was determined in JhumanJ OpnForm up to 1.9.3. Impacted is an unknown function of the file /edit. Executing manipulation can lead to improper access controls. The…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-61785

Published Oct 8, 2025

Deno is a JavaScript, TypeScript, and WebAssembly runtime. In versions prior to 2.5.3 and 2.2.15, `Deno.FsFile.prototype.utime` and `Deno.FsFile.prototype.utimeSync` are not limit…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-43914

Published Oct 7, 2025

Dell PowerProtect Data Domain BoostFS for Linux Ubuntu systems of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-11281

Published Oct 5, 2025

A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished Course Handler. Such manipulati…

CVSS 1.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-11272

Published Oct 4, 2025

A vulnerability has been found in SeriaWei ZKEACMS up to 4.3. This affects the function Delete of the file src/ZKEACMS.Redirection/Controllers/UrlRedirectionController.cs of the c…

CVSS 2.1 · Low

CVE-2025-10725

Published Sep 30, 2025

A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for example as a data scientist using a standard Jupyter noteb…

CVSS 9.9 · Critical
evidence mentions
10
Buzz score
40.5

CVE-2025-11080

Published Sep 27, 2025

A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. This vulnerability affects the function selectStudentExamInfoList of the file src/main…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2025-11050

Published Sep 27, 2025

A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /periodo-lancamento. Executing manipulation can lead to improper authorization. T…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 426-450 of 1,006 CVEsPage 18 of 41