Skip to main content

CWE archive

CWE-266 CVEs

Programmatic archive

1,006 CVEs tagged with CWE-266107 Critical, 272 High, 374 Medium, 252 Low, 1 Unrated.

CVE-2026-11438

Published Jun 6, 2026

A vulnerability has been found in theonedev onedev up to 15.0.5. Affected by this vulnerability is an unknown functionality of the file /projects. The manipulation of the argument…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
27.5

CVE-2026-11336

Published Jun 5, 2026

A vulnerability has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. Affected is an unknown f…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-10876

Published Jun 5, 2026

A weakness has been identified in SourceCodester Ship Ferry Ticket Reservation System 1.0. This affects an unknown function of the file /admin/. This manipulation of the argument…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2025-15656

Published Jun 3, 2026

Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affects School Management: from n/a through 93.2.0.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-10693

Published Jun 3, 2026

A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the component Admini…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2025-53209

Published Jun 2, 2026

Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue affects Masteriyo LMS PRO: from n/a through 2.20.0.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-10294

Published Jun 1, 2026

A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function g_file_test of the file src/pk-transaction.c of the component API. Such manipulation of the argu…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-10285

Published Jun 1, 2026

A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper::recordUpdated of the file app/Helpers…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-10284

Published Jun 1, 2026

A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerability is the function editComment/doDeleteComment of the file app/Filament/Reso…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-10282

Published Jun 1, 2026

A security vulnerability has been detected in Bottelet DaybydayCRM up to 2.2.1. This impacts the function view of the file app/Http/Controllers/DocumentsController.php. Such manip…

CVSS 5.3 · Medium
evidence mentions
8
Buzz score
28.5

CVE-2026-10277

Published Jun 1, 2026

A vulnerability was found in j3k0 mcp-google-workspace up to 831790e7d5c2663325733d9f5579cc339a267c4c. This issue affects the function saveToDisk of the file src/tools/gmail.ts of…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-10272

Published Jun 1, 2026

A vulnerability has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The impacted element is an unknown function of the file admin/dele…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-10269

Published Jun 1, 2026

A security vulnerability has been detected in decolua 9router up to 0.4.0. This issue affects the function isAuthenticated of the file src/dashboardGuard.js of the component HTTP…

CVSS 5.3 · Medium
evidence mentions
8
Buzz score
28.5

CVE-2026-48879

Published Jun 1, 2026

Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-42680

Published Jun 1, 2026

Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation. This issue affects Contest Gallery Pr…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-10255

Published Jun 1, 2026

A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function sell_statement of the file application/con…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-10236

Published Jun 1, 2026

A vulnerability has been found in SourceCodester Water Billing Management System 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=save of the compo…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-10218

Published Jun 1, 2026

A vulnerability has been found in nextlevelbuilder GoClaw up to 3.11.3. This affects the function auth of the file internal/http/evolution_handlers.go. Such manipulation leads to…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-10217

Published Jun 1, 2026

A flaw has been found in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function handleSave of the file internal/http/tts_config.go of the component RoleAdmin G…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-10215

Published Jun 1, 2026

A security vulnerability has been detected in Dolibarr ERP CRM up to 23.0.1. Impacted is the function checkUserAccessToObject of the file htdocs/holiday/class/api_holidays.class.p…

CVSS 2.1 · Low
evidence mentions
9
Buzz score
29.5

CVE-2026-10152

Published May 30, 2026

A vulnerability was detected in TaleLin lin-cms-spring-boot up to 0.2.1. This issue affects some unknown processing of the file src/main/java/io/github/talelin/latticy/controller/…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-10070

Published May 29, 2026

A vulnerability was found in macrozheng mall up to 1.0.3. This affects an unknown function of the file /admin/update/ of the component Super Admin Password Handler. Performing a m…

CVSS 5.1 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-43000

Published May 28, 2026

An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a projec…

CVSS 6.0 · Medium
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2026-35671

Published May 28, 2026

phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrators to change any use…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-9795

Published May 28, 2026

A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can exploit this vulnerability to assig…

CVSS 7.3 · High
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort
Showing 126-150 of 1,006 CVEsPage 6 of 41