CWE-266: CWE-266

417
Total CVEs
48
Critical
131
High
6.7
Avg CVSS

Yearly Trend

2026
74
2025
267
2024
59
2023
5
2022
4

Top Affected Vendors

1 Jeecg 11
2 Portabilis 11
3 Dell 10
4 Google 9
5 Fuyang Lipengjun 8
6 Macrozheng 8
7 Dlink 8
8 Totolink 7
9 Wekan Project 7
10 Youlai 6

All CWE-266 CVEs (417)

CVE-2025-49924
7.3

This vulnerability allows attackers to escalate privileges in WooCommerce Wholesale Suite, potentially granting unauthorized administrative access. It...

Oct 22, 2025
CVE-2025-11030
7.3

This CVE describes an improper authorization vulnerability in the Tutorials-Website Employee Management System's HTTP Request Handler component. Attac...

Sep 26, 2025
CVE-2025-10374
7.3

This CVE describes an improper authorization vulnerability in Shenzhen Sixun Business Management System versions 7 and 11. Attackers can remotely expl...

Sep 13, 2025
CVE-2025-8261
7.3

This critical vulnerability in Vaelsys 4.1.0 allows remote attackers to create unauthorized user accounts via the /grid/vgrid_server.php endpoint due ...

Jul 28, 2025
CVE-2025-5522
7.3

This critical vulnerability in the jack0240 bskms 蓝天幼儿园管理系统 (Blue Sky Kindergarten Management System) allows unauthorized attackers ...

Jun 3, 2025
CVE-2025-39459
7.3

This vulnerability allows attackers to escalate privileges in the Contempo Themes Real Estate 7 WordPress theme. Attackers can gain higher-level acces...

May 19, 2025
CVE-2025-4066
7.3

This critical vulnerability in ScriptAndTools Online-Travling-System 1.0 allows attackers to bypass access controls on the /admin/addpackage.php file,...

Apr 29, 2025
CVE-2025-3199
7.3

This CVE describes an improper authorization vulnerability in the ruoyi-ai software up to version 2.0.1. Attackers can remotely exploit this flaw to a...

Apr 4, 2025
CVE-2025-2360
7.3

A critical vulnerability in D-Link DIR-823G routers allows remote attackers to bypass authorization controls via manipulation of the SOAPAction parame...

Mar 17, 2025
CVE-2025-2359
7.3

This critical vulnerability in D-Link DIR-823G routers allows attackers to bypass authorization controls and manipulate DDNS settings remotely via the...

Mar 17, 2025
CVE-2025-2320
7.3

This CVE describes an improper authorization vulnerability in the springboot-openai-chatgpt project's user submission API endpoint. Attackers can remo...

Mar 14, 2025
CVE-2025-0802
7.3

This critical vulnerability in SourceCodester Best Employee Management System 1.0 allows attackers to bypass access controls on the administrative end...

Jan 29, 2025
CVE-2024-45331
7.3

This CVE describes an incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer, FortiManager, and FortiAnalyzer Cloud products. Attacker...

Jan 16, 2025
CVE-2025-0484
7.3

This vulnerability in Fanli2012 native-php-cms 1.0 allows attackers to bypass authorization controls in the backend administration component. Attacker...

Jan 15, 2025
CVE-2024-13200
7.3

This critical vulnerability in wander-chu SpringBoot-Blog 1.0 allows remote attackers to bypass access controls via improper handling of HTTP POST req...

Jan 9, 2025
CVE-2024-13189
7.3

CVE-2024-13189 is a critical permission vulnerability in ZeroWdd myblog 1.0 that allows remote attackers to bypass authorization controls. The vulnera...

Jan 8, 2025
CVE-2024-13030
7.3

This critical vulnerability in D-Link DIR-823G routers allows unauthorized attackers to remotely modify critical system settings through the web manag...

Dec 30, 2024
CVE-2025-55707
7.2

This vulnerability allows attackers to escalate privileges in WordPress sites using the PostX (ultimate-post) plugin. Attackers can gain administrativ...

Dec 18, 2025
CVE-2025-49379
7.2

This vulnerability allows attackers to escalate privileges in the Custom Fields Account Registration For Woocommerce WordPress plugin. Attackers can g...

Dec 18, 2025
CVE-2025-14503
7.2

This vulnerability in the Harmonix on AWS framework allows IAM principals within the same AWS account to assume an administrative role due to an overl...

Dec 15, 2025
CVE-2025-64761
7.2

OpenBao versions before 2.4.4 contain a privilege escalation vulnerability where privileged operators without policy access can add root policies to i...

Nov 25, 2025
CVE-2025-54697
7.2

This vulnerability allows attackers to escalate privileges in the Kadence WooCommerce Email Designer WordPress plugin. Attackers can gain administrati...

Aug 14, 2025
CVE-2025-53744
7.2

A privilege escalation vulnerability in FortiOS Security Fabric allows remote authenticated attackers with high privileges to gain super-admin access ...

Aug 12, 2025
CVE-2025-5999
7.2

A privileged Vault operator with write permissions to the root namespace's identity endpoint can escalate token privileges to Vault's root policy, gra...

Aug 1, 2025
CVE-2024-9180
7.2

This vulnerability allows a Vault operator with write permissions to the root namespace's identity endpoint to escalate their own or another user's pr...

Oct 10, 2024
CVE-2025-8757
7.0

This vulnerability in TRENDnet TV-IP110WN IP cameras allows local attackers to bypass intended privilege restrictions through manipulation of the boa....

Aug 9, 2025
CVE-2020-1742
7.0

This vulnerability allows attackers with access to containers using nmstate/kubernetes-nmstate-handler to modify the /etc/passwd file and escalate pri...

Jun 7, 2021
CVE-2020-35514
7.0

This vulnerability allows attackers with access to a container mounting /etc/kubernetes or local node access to copy the kubeconfig file and potential...

Jun 2, 2021
CVE-2019-19352
7.0

This vulnerability allows an attacker with access to a container running the vulnerable operator-framework/presto component in Red Hat OpenShift 4 to ...

Mar 24, 2021
CVE-2025-42992
6.9

This vulnerability in SAPCAR allows authenticated attackers with high privileges to create malicious SAR archives that bypass signature validation. Th...

Jul 8, 2025
CVE-2025-4692
6.8

Attackers can craft malicious JSON Web Tokens (JWTs) to escalate privileges on the ABUP Cloud Update Platform. Successful exploitation allows unauthor...

May 23, 2025
CVE-2024-45759
6.8

Dell PowerProtect Data Domain has a local privilege escalation vulnerability where authenticated low-privileged users can execute unauthorized command...

Nov 8, 2024
CVE-2026-21425
6.7

Dell PowerScale OneFS contains an incorrect privilege assignment vulnerability that allows local low-privileged attackers to elevate their privileges....

Mar 4, 2026
CVE-2025-36612
6.7

Dell SupportAssist for Business PCs versions 4.5.3 and earlier contain an incorrect privilege assignment vulnerability (CWE-266). A local attacker wit...

Aug 14, 2025
CVE-2025-38738
6.7

This vulnerability allows a low-privileged local attacker to gain elevated privileges through the Dell SupportAssist installer. It affects users runni...

Aug 14, 2025
CVE-2024-33503
6.7

This vulnerability allows attackers to escalate privileges on Fortinet FortiManager and FortiAnalyzer systems by executing specific shell commands. Af...

Jan 14, 2025
CVE-2024-39579
6.7

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an incorrect privilege assignment vulnerability. A local high-privileged attacker could...

Aug 31, 2024
CVE-2024-37132
6.7

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an incorrect privilege assignment vulnerability. A high-privileged attacker with local ...

Jul 2, 2024
CVE-2024-37134
6.7

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability that allows a local high-privileged atta...

Jul 2, 2024
CVE-2026-2669
6.5

This vulnerability allows unauthorized deletion of user accounts in the Rongzhitong Visual Integrated Command and Dispatch Platform due to improper ac...

Feb 18, 2026
CVE-2025-67278
6.5

A privilege escalation vulnerability in TIM Solution GmbH's TIM BPM Suite and TIM FLOW allows remote attackers to gain elevated privileges through spe...

Jan 9, 2026
CVE-2025-14206
6.5

This vulnerability in SourceCodester Online Student Clearance System 1.0 allows attackers to bypass authorization controls and delete fee records with...

Dec 8, 2025
CVE-2025-63384
6.5

This vulnerability in RISC-V Rocket-Chip allows privilege escalation by failing to properly downgrade from Machine-mode to Supervisor-mode when execut...

Nov 10, 2025
CVE-2025-56503
6.5

This CVE describes a local privilege escalation vulnerability in Sublime Text 4 where authenticated users with low-level privileges could potentially ...

Nov 10, 2025
CVE-2025-46204
6.5

A privilege escalation vulnerability in Unifiedtransform v2.0 allows remote attackers to gain elevated privileges through the /course/edit/{id} endpoi...

Jun 4, 2025
CVE-2025-4493
6.5

This vulnerability allows a PAM (Privileged Access Management) user in Devolutions Server to perform JIT (Just-In-Time) privilege requests on groups t...

May 28, 2025
CVE-2025-4374
6.5

A privilege escalation vulnerability in Quay container registry allows users or robots to gain administrative permissions on newly created repositorie...

May 6, 2025
CVE-2025-3536
6.5

This vulnerability allows attackers to bypass authorization controls in Tutorials-Website Employee Management System 1.0 by manipulating the ID parame...

Apr 13, 2025
CVE-2025-2686
6.5

This CVE describes an improper access control vulnerability in the mingyuefusu library management system's backend admin component. Attackers can remo...

Mar 24, 2025
CVE-2025-21092
6.5

GMOD Apollo lacks proper access controls when updating user information, allowing attackers to escalate privileges for themselves or other users. This...

Mar 5, 2025

About CWE-266 (CWE-266)

Our database tracks 417 CVEs classified as CWE-266, with 48 rated critical and 131 rated high severity. The average CVSS score for CWE-266 vulnerabilities is 6.7.

External reference: View CWE-266 on MITRE CWE →

Monitor CWE-266 Vulnerabilities

Get alerted when new CWE-266 CVEs affect your infrastructure.

Start Monitoring Free