CWE-266: CWE-266

417
Total CVEs
48
Critical
131
High
6.7
Avg CVSS

Yearly Trend

2026
74
2025
267
2024
59
2023
5
2022
4

Top Affected Vendors

1 Jeecg 11
2 Portabilis 11
3 Dell 10
4 Google 9
5 Fuyang Lipengjun 8
6 Macrozheng 8
7 Dlink 8
8 Totolink 7
9 Wekan Project 7
10 Youlai 6

All CWE-266 CVEs (417)

CVE-2024-11860
6.5

This critical vulnerability in SourceCodester Best House Rental Management System 1.0 allows unauthorized deletion of tenant records via a POST reques...

Nov 27, 2024
CVE-2024-47653
6.5

This vulnerability allows authenticated attackers to modify or cancel requests belonging to other users in Shilpi Client Dashboard through unauthorize...

Oct 4, 2024
CVE-2024-6758
6.5

This vulnerability allows remote attackers with low privileges to save unauthorized protection assignments in Sprecher Automation SPRECON-E systems. T...

Aug 12, 2024
CVE-2025-48695
6.4

A privilege escalation vulnerability in CyberDAVA allows low-privileged authenticated users to elevate their privileges to admin by exploiting an API ...

May 23, 2025
CVE-2025-15597
6.3

CVE-2025-15597 is an improper access control vulnerability in Dataease SQLBot up to version 1.4.0 that allows unauthorized access to API endpoints. At...

Mar 2, 2026
CVE-2026-3209
6.3

This vulnerability allows attackers to bypass access controls in fosrl Pangolin's Role Handler component, potentially gaining unauthorized access to r...

Feb 25, 2026
CVE-2026-2860
6.3

This CVE describes an improper authorization vulnerability in the EmployeeController.java file of the feng_ha_ha/megagao ssm-erp and production_ssm pr...

Feb 21, 2026
CVE-2026-2850
6.3

This CVE describes an improper access control vulnerability in the yeqifu warehouse software's customer management endpoints. Attackers can manipulate...

Feb 20, 2026
CVE-2026-2676
6.3

This CVE describes an improper authorization vulnerability in GoogTech sms-ssm's API interface that allows attackers to bypass authentication controls...

Feb 18, 2026
CVE-2026-2563
6.3

A remote privilege escalation vulnerability in JingDong JD Cloud Box AX6600 allows attackers to gain elevated privileges by manipulating the set_stcre...

Feb 16, 2026
CVE-2026-2561
6.3

This vulnerability allows remote attackers to escalate privileges on JingDong JD Cloud Box AX6600 devices by exploiting a flaw in the web_get_ddns_upt...

Feb 16, 2026
CVE-2026-2141
6.3

This CVE describes an improper authorization vulnerability in WuKongOpenSource WukongCRM that allows attackers to bypass access controls via URL manip...

Feb 8, 2026
CVE-2026-2206
6.3

This vulnerability in WeKan allows improper access controls through the Administrative Repair Handler component. Attackers can remotely exploit this f...

Feb 8, 2026
CVE-2026-2209
6.3

This vulnerability in WeKan allows remote attackers to bypass authorization controls in the custom translation handler. Attackers can manipulate trans...

Feb 8, 2026
CVE-2026-2107
6.3

This CVE describes an improper authorization vulnerability in the yeqifu warehouse software's log info handler component. Attackers can remotely explo...

Feb 7, 2026
CVE-2026-2106
6.3

This CVE describes an improper authorization vulnerability in the Notice Management component of yeqifu warehouse software. Attackers can remotely exp...

Feb 7, 2026
CVE-2026-2105
6.3

This CVE-2026-2105 vulnerability allows unauthorized users to manipulate department management functions (add, update, delete) in yeqifu warehouse sof...

Feb 7, 2026
CVE-2026-2079
6.3

This CVE describes an improper authorization vulnerability in yeqifu warehouse's menu management functions (addMenu/updateMenu/deleteMenu). Attackers ...

Feb 7, 2026
CVE-2026-2078
6.3

This CVE describes an improper authorization vulnerability in yeqifu warehouse's permission management functions. Attackers can remotely manipulate pe...

Feb 7, 2026
CVE-2026-2077
6.3

This CVE describes an improper authorization vulnerability in yeqifu warehouse's role management functions (addRole/updateRole/deleteRole) that allows...

Feb 7, 2026
CVE-2026-2076
6.3

This CVE describes an improper authorization vulnerability in the yeqifu warehouse user management endpoints (addUser/updateUser/deleteUser). Attacker...

Feb 7, 2026
CVE-2026-2075
6.3

This CVE describes an improper access control vulnerability in yeqifu warehouse's role-permission binding handler. Attackers can remotely exploit this...

Feb 7, 2026
CVE-2026-2015
6.3

This vulnerability in Portabilis i-Educar allows remote attackers to bypass authorization controls by manipulating the school_id parameter in the Fina...

Feb 6, 2026
CVE-2026-2009
6.3

This vulnerability allows improper access control in SourceCodester Gas Agency Management System 1.0, enabling unauthorized user creation or privilege...

Feb 6, 2026
CVE-2026-1963
6.3

This CVE describes an improper access control vulnerability in WeKan's attachment storage component. Attackers can remotely exploit this to access or ...

Feb 5, 2026
CVE-2026-1962
6.3

This vulnerability in WeKan's attachment migration component allows attackers to bypass access controls and potentially access or manipulate attachmen...

Feb 5, 2026
CVE-2026-1898
6.3

This vulnerability in WeKan's LDAP user synchronization component allows improper access controls, potentially enabling unauthorized access to user ac...

Feb 5, 2026
CVE-2026-1896
6.3

This vulnerability in WeKan allows attackers to bypass access controls during board migration operations by manipulating the boardId argument. Attacke...

Feb 5, 2026
CVE-2026-1894
6.3

This vulnerability in WeKan allows attackers to bypass authorization checks in the REST API by manipulating card/board ID parameters. Remote attackers...

Feb 4, 2026
CVE-2026-1895
6.3

CVE-2026-1895 is an improper access control vulnerability in WeKan's attachment storage handler that allows remote attackers to bypass intended restri...

Feb 4, 2026
CVE-2026-1702
6.3

This vulnerability allows remote attackers to bypass authorization controls in Pet Grooming Management Software 1.0 by manipulating the group_id param...

Jan 30, 2026
CVE-2026-1597
6.3

This vulnerability in Bdtask SalesERP allows attackers to bypass authorization controls by manipulating the ci_session parameter on administrative end...

Jan 29, 2026
CVE-2026-1550
6.3

CVE-2026-1550 is an improper authorization vulnerability in PHPGurukul Hospital Management System 1.0 that allows attackers to bypass access controls ...

Jan 28, 2026
CVE-2026-1193
6.3

This vulnerability in MineAdmin 1.x/2.x allows attackers to bypass authorization controls via the /system/cache/view interface, potentially accessing ...

Jan 19, 2026
CVE-2026-0574
6.3

This CVE describes an improper authorization vulnerability in the yeqifu warehouse software that allows vertical privilege escalation. Attackers can r...

Jan 4, 2026
CVE-2025-15106
6.3

CVE-2025-15106 is an improper authorization vulnerability in getmaxun maxun's authentication endpoint that allows attackers to bypass authorization co...

Dec 27, 2025
CVE-2025-14749
6.3

This vulnerability allows unauthorized remote control of PTZ (Pan-Tilt-Zoom) cameras on the Ningyuanda TC155 device via the ONVIF interface. Attackers...

Dec 16, 2025
CVE-2025-14089
6.3

CVE-2025-14089 is an improper authorization vulnerability in Himool ERP that allows remote attackers to perform unauthorized account updates via the A...

Dec 5, 2025
CVE-2025-14088
6.3

This vulnerability in ketr JEPaaS allows attackers to bypass authorization controls via manipulation of the Authorization parameter in the /je/load en...

Dec 5, 2025
CVE-2025-14086
6.3

This vulnerability in youlaitech youlai-mall allows attackers to bypass access controls by manipulating the openid parameter in the /app-api/v1/member...

Dec 5, 2025
CVE-2025-14052
6.3

This vulnerability in youlai-mall allows attackers to bypass access controls by manipulating the memberId parameter in the getMemberById function. Att...

Dec 5, 2025
CVE-2025-13576
6.3

CVE-2025-13576 is an improper authorization vulnerability in code-projects Blog Site 1.0 that allows remote attackers to bypass authentication on the ...

Nov 24, 2025
CVE-2025-13250
6.3

This vulnerability in WeiYe-Jing datax-web up to version 2.1.2 allows remote attackers to bypass access controls on job management functions (remove/u...

Nov 16, 2025
CVE-2025-13118
6.3

This vulnerability in macrozheng mall-swarm and mall allows attackers to bypass authorization by manipulating the orderID parameter in the paySuccess ...

Nov 13, 2025
CVE-2025-13114
6.3

This vulnerability in macrozheng mall-swarm allows attackers to bypass authorization controls when manipulating the updateAttr function in the cart up...

Nov 13, 2025
CVE-2025-11853
6.3

CVE-2025-11853 is an improper access control vulnerability in Sismics Teedy's API endpoint that allows unauthorized access to files. Attackers can exp...

Oct 16, 2025
CVE-2025-11646
6.3

This vulnerability allows attackers on the same local network to bypass access controls in Tomofun Furbo pet cameras via the GATT Service, potentially...

Oct 12, 2025
CVE-2025-11554
6.3

This vulnerability in Portabilis i-Educar allows attackers to escalate privileges through insecure inherited permissions in the User Type Handler comp...

Oct 9, 2025
CVE-2025-11050
6.3

CVE-2025-11050 is an improper authorization vulnerability in Portabilis i-Educar's /periodo-lancamento endpoint that allows remote attackers to bypass...

Sep 27, 2025
CVE-2025-11049
6.3

CVE-2025-11049 is an improper authorization vulnerability in Portabilis i-Educar's /unificacao-aluno endpoint that allows unauthorized access to stude...

Sep 27, 2025

About CWE-266 (CWE-266)

Our database tracks 417 CVEs classified as CWE-266, with 48 rated critical and 131 rated high severity. The average CVSS score for CWE-266 vulnerabilities is 6.7.

External reference: View CWE-266 on MITRE CWE →

Monitor CWE-266 Vulnerabilities

Get alerted when new CWE-266 CVEs affect your infrastructure.

Start Monitoring Free