Skip to main content

CWE archive

CWE-266 CVEs

Programmatic archive

1,063 CVEs tagged with CWE-266116 Critical, 291 High, 383 Medium, 272 Low, 1 Unrated.

CVE-2024-46511

Published Sep 30, 2024

LoadZilla LLC LoadLogic v1.4.3 was discovered to contain insecure permissions vulnerability which allows a remote attacker to execute arbitrary code via the LogicLoadEc2DeployLamb…

CVSS 7.5 · High

CVE-2024-46540

Published Sep 30, 2024

A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attackers to use remote file downloads and self-extract fucntions…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9082

Published Sep 22, 2024

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /classes/Users…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22303

Published Sep 17, 2024

Incorrect Privilege Assignment vulnerability in favethemes Houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 3.2.4.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2024-21743

Published Sep 17, 2024

Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez Login Register: from n/a through 3.2.5.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2024-8253

Published Sep 11, 2024

The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to 2.2.90. This is due to the plugin not properly restricting…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-39579

Published Aug 31, 2024

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contains an incorrect privilege assignment vulnerability. A local high privileged attacker could potentially exploit this vu…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4555

Published Aug 28, 2024

Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specific scenario. This issue affects NetIQ Access Manager before…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45187

Published Aug 23, 2024

Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high privileges and specifically given access to remotely execute…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39576

Published Aug 22, 2024

Dell Power Manager (DPM), versions 3.15.0 and prior, contains an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-20466

Published Aug 21, 2024

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28000

Published Aug 21, 2024

Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1.

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
34.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-6322

Published Aug 20, 2024

Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any oth…

CVSS 5.4 · Medium

CVE-2024-34738

Published Aug 15, 2024

In multiple functions of AppOpsService.java, there is a possible way for unprivileged apps to read their own restrictRead app-op states due to a logic error in the code. This coul…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-25633

Published Aug 15, 2024

eLabFTW is an open source electronic lab notebook for research labs. In an eLabFTW system, one can configure who is allowed to create new user accounts. A vulnerability has been f…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43153

Published Aug 13, 2024

Incorrect Privilege Assignment vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <= 5.4.10.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-7480

Published Aug 8, 2024

An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read arbitr…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41139

Published Jul 29, 2024

Incorrect privilege assignment vulnerability exists in SKYSEA Client View Ver.6.010.06 to Ver.19.210.04e. If a user who can log in to the PC where the product's Windows client is…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-40433

Published Jul 26, 2024

Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view component.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36534

Published Jul 24, 2024

Insecure permissions in hwameistor v0.14.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

CVSS 8.4 · High

CVE-2024-23794

Published Jul 15, 2024

An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escalation. This flaw allows an agent with read-only permissions…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37927

Published Jul 12, 2024

Incorrect Privilege Assignment vulnerability in NooTheme Jobmonster noo-jobmonster allows Privilege Escalation.This issue affects Jobmonster: from n/a through <= 4.7.5.

CVSS 9.8 · Critical
Showing 901-925 of 1,063 CVEsPage 37 of 43