Skip to main content

CWE archive

CWE-266 CVEs

Programmatic archive

1,006 CVEs tagged with CWE-266107 Critical, 272 High, 374 Medium, 252 Low, 1 Unrated.

CVE-2026-42758

Published May 27, 2026

Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-42731

Published May 27, 2026

Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp ve…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-9604

Published May 26, 2026

A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/queryBy…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-9581

Published May 26, 2026

A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation leads to improper access contr…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-9580

Published May 26, 2026

A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This manipulation causes…

CVSS 5.5 · Medium
evidence mentions
7
Buzz score
27.3

CVE-2026-9579

Published May 26, 2026

A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the component SysUser. The manipulati…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-9562

Published May 26, 2026

A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The affected element is an unknown function of the component…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-9517

Published May 26, 2026

A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/students/addStudentView of the…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-45216

Published May 25, 2026

Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects Smart Manager: from n/a through 8.85.0.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-9484

Published May 25, 2026

A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/removeStudentFromClassro…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
32.3

CVE-2026-9483

Published May 25, 2026

A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the file grades.php. Performing a manipulation of the argument…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4

CVE-2026-9412

Published May 25, 2026

A vulnerability was determined in SourceCodester Indian Invoicing System 1.0. Impacted is an unknown function of the component Backend Endpoint. Executing a manipulation can lead…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4

CVE-2026-9410

Published May 25, 2026

A vulnerability has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This vulnerability affects unknown code of the file /profile of the com…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-9409

Published May 25, 2026

A flaw has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This affects an unknown part of the file /user of the component User Management…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-9397

Published May 24, 2026

A weakness has been identified in Besen BS20 EV Charging Station up to 20260426. Affected by this issue is some unknown functionality of the component OTA Update Installation Hand…

CVSS 8.2 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-9376

Published May 24, 2026

A vulnerability was determined in JPress up to 1.0.3. The affected element is an unknown function of the file /ucenter/article/doWriteSave of the component UCenter Article Submiss…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-22315

Published May 20, 2026

Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables the export  of user data, including cleartext passw…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-8752

Published May 17, 2026

A weakness has been identified in h2oai h2o-3 up to 7402. This vulnerability affects the function exec of the file h2o-core/src/main/java/water/rapids/ast/prims/misc/AstSetPropert…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-8747

Published May 17, 2026

A weakness has been identified in Z-BlogPHP 1.7.4.3430. This affects the function CheckComment of the file zb_system/function/c_system_event.php of the component Commend Approval…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
26.1

CVE-2026-8743

Published May 17, 2026

A vulnerability was found in Open5GS up to 2.7.6. This impacts the function ran_ue_find_by_amf_ue_ngap_id of the file src/amf/context.c of the component AMF/MME. Performing a mani…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
31.8
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-68420

Published May 14, 2026

Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to which a user logs in. It is possible for a local attacker…

CVSS 7.5 · High

CVE-2026-44997

Published May 11, 2026

OpenClaw before 2026.4.22 contains a security envelope constraint bypass vulnerability allowing restricted subagents to spawn ACP child sessions that fail to inherit depth, child-…

CVSS 2.3 · Low
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort
Showing 151-175 of 1,006 CVEsPage 7 of 41