CWE-266: CWE-266

417
Total CVEs
48
Critical
131
High
6.7
Avg CVSS

Yearly Trend

2026
74
2025
267
2024
59
2023
5
2022
4

Top Affected Vendors

1 Jeecg 11
2 Portabilis 11
3 Dell 10
4 Google 9
5 Fuyang Lipengjun 8
6 Macrozheng 8
7 Dlink 8
8 Totolink 7
9 Wekan Project 7
10 Youlai 6

All CWE-266 CVEs (417)

CVE-2025-14889
5.4

CVE-2025-14889 is an authorization bypass vulnerability in Campcodes Advanced Voting Management System 1.0 that allows attackers to manipulate voter r...

Dec 18, 2025
CVE-2025-14748
5.4

This vulnerability in Ningyuanda TC155 57.0.2.0 allows attackers on the local network to perform unauthorized factory resets via the ONVIF Device Mana...

Dec 16, 2025
CVE-2025-14016
5.4

This vulnerability in macrozheng mall-swarm allows unauthorized deletion of user read history records through improper authorization in the delete fun...

Dec 4, 2025
CVE-2025-13787
5.4

This vulnerability in ZenTao's file handler allows attackers to manipulate file deletion operations through improper privilege management. Attackers c...

Nov 30, 2025
CVE-2025-13443
5.4

This vulnerability in macrozheng mall allows attackers to bypass access controls and delete user read history records without proper authorization. Re...

Nov 20, 2025
CVE-2025-13117
5.4

This vulnerability allows attackers to cancel orders without proper authorization in macrozheng mall-swarm and mall applications. Attackers can exploi...

Nov 13, 2025
CVE-2025-13116
5.4

This vulnerability allows improper authorization in macrozheng mall-swarm and mall applications up to version 1.0.3. Attackers can manipulate the orde...

Nov 13, 2025
CVE-2025-11272
5.4

This vulnerability in SeriaWei ZKEACMS allows unauthorized deletion of URL redirection entries through improper authorization in the POST request hand...

Oct 4, 2025
CVE-2025-26517
5.4

This CVE describes a privilege escalation vulnerability in NetApp StorageGRID where authenticated attackers can discover Grid node names and IP addres...

Sep 19, 2025
CVE-2025-10390
5.4

CRMEB versions up to 5.6.1 contain an improper authorization vulnerability in the editAddress function that allows attackers to manipulate address IDs...

Sep 14, 2025
CVE-2025-10389
5.4

This vulnerability in CRMEB allows attackers to manipulate administrator password reset functionality to gain unauthorized access. It affects CRMEB in...

Sep 14, 2025
CVE-2025-9937
5.4

CVE-2025-9937 is an improper authorization vulnerability in elunez eladmin's LocalStorageController deleteFile function that allows unauthorized file ...

Sep 4, 2025
CVE-2025-42936
5.4

This vulnerability in SAP NetWeaver Application Server for ABAP allows authenticated users to bypass authorization controls in the barcode interface, ...

Aug 12, 2025
CVE-2025-7947
5.4

CVE-2025-7947 is an improper authorization vulnerability in jshERP's account deletion function that allows attackers to delete user accounts without p...

Jul 22, 2025
CVE-2025-2334
5.4

This vulnerability allows remote attackers to delete chat histories they shouldn't have access to due to improper access controls in the deleteChat fu...

Mar 15, 2025
CVE-2025-2089
5.4

This vulnerability in StarSea99 starsea-mall allows attackers to bypass access controls and modify user information by manipulating the userId paramet...

Mar 7, 2025
CVE-2022-2637
5.4

This vulnerability allows remote authenticated users to escalate their privileges in Hitachi Storage Plug-in for VMware vCenter. Attackers with existi...

Oct 6, 2022
CVE-2025-67279
5.3

This vulnerability in TIM BPM Suite & TIM FLOW allows remote attackers to escalate privileges by exploiting weak MD5 password hashes stored by the app...

Jan 9, 2026
CVE-2025-10992
5.3

This vulnerability in roncoo-pay allows improper authorization through manipulation of the /user/info/lookupList endpoint, potentially enabling unauth...

Sep 26, 2025
CVE-2025-5649
5.3

This critical vulnerability in SourceCodester Student Result Management System 1.0 allows unauthorized privileged user creation through improper acces...

Jun 5, 2025
CVE-2025-5175
5.3

CVE-2025-5175 is an improper authorization vulnerability in erdogant pypickle's Save function that allows local attackers to bypass intended access co...

May 26, 2025
CVE-2025-4118
5.3

This vulnerability in Weitong Mall 1.0.0 allows remote attackers to bypass access controls by manipulating the 'isDelete' parameter in the /historyLis...

Apr 30, 2025
CVE-2025-4064
5.3

CVE-2025-4064 is an improper access control vulnerability in ScriptAndTools Online-Travling-System 1.0 that allows unauthorized access to the admin vi...

Apr 29, 2025
CVE-2025-3790
5.3

This critical vulnerability in baseweb JSite 1.0's Apache Druid Monitoring Console allows unauthorized access to the /druid/index.html component due t...

Apr 18, 2025
CVE-2025-3675
5.3

This critical vulnerability in TOTOLINK A3700R routers allows attackers to bypass access controls on the setL2tpServerCfg function via the /cgi-bin/cs...

Apr 16, 2025
CVE-2025-3668
5.3

This vulnerability allows remote attackers to bypass access controls on TOTOLINK A3700R routers via the setScheduleCfg function in the web interface. ...

Apr 16, 2025
CVE-2025-3664
5.3

This critical vulnerability in TOTOLINK A3700R routers allows attackers to bypass access controls on the setWiFiEasyGuestCfg function via the /cgi-bin...

Apr 16, 2025
CVE-2025-3237
5.3

This vulnerability in Tenda FH1202 routers allows attackers to bypass access controls via the /goform/wrlwpsset endpoint, potentially enabling unautho...

Apr 4, 2025
CVE-2025-2996
5.3

This vulnerability in Tenda FH1202 routers allows attackers to bypass access controls on the web management interface's SysToolDDNS component. Attacke...

Mar 31, 2025
CVE-2025-2993
5.3

This critical vulnerability in Tenda FH1202 routers allows improper access controls through manipulation of the /default.cfg file, potentially enablin...

Mar 31, 2025
CVE-2025-2991
5.3

This critical vulnerability in Tenda FH1202 routers allows remote attackers to bypass access controls via the web management interface. Attackers can ...

Mar 31, 2025
CVE-2025-2990
5.3

This critical vulnerability in Tenda FH1202 routers allows attackers to bypass access controls via the /goform/AdvSetWrlGstset endpoint in the web man...

Mar 31, 2025
CVE-2025-2955
5.3

This vulnerability allows remote attackers to improperly access the IBMS configuration file handler in TOTOLINK A3000RU routers. Attackers can exploit...

Mar 30, 2025
CVE-2025-1226
5.3

This critical vulnerability in ywoa allows remote attackers to bypass authorization controls via the /oa/setup/setup.jsp file. It affects all ywoa ins...

Feb 12, 2025
CVE-2025-1078
5.3

This vulnerability in AlDente Charge Limiter allows local attackers to bypass authorization checks in the XPC service, potentially enabling unauthoriz...

Feb 6, 2025
CVE-2024-13188
5.3

This vulnerability in MicroWorld eScan Antivirus 7.0.32 on Linux allows local attackers to exploit incorrect default permissions in the installation h...

Jan 8, 2025
CVE-2025-0206
5.3

CVE-2025-0206 is a critical improper access control vulnerability in code-projects Online Shoe Store 1.0 that allows unauthorized access to the admin ...

Jan 4, 2025
CVE-2024-13109
5.3

This vulnerability allows unauthorized access to the /doc.html endpoint in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2...

Jan 2, 2025
CVE-2024-13106
5.3

This vulnerability in D-Link DIR-816 routers allows unauthorized access to the IP QoS configuration handler due to improper access controls. Attackers...

Jan 2, 2025
CVE-2024-13104
5.3

This vulnerability allows remote attackers to bypass authentication and access WiFi settings on affected D-Link DIR-816 A2 routers. Attackers can modi...

Jan 2, 2025
CVE-2024-13067
5.3

CVE-2024-13067 is an improper access control vulnerability in CodeAstro Online Food Ordering System 1.0 that allows unauthorized access to the admin/a...

Dec 31, 2024
CVE-2024-12901
5.3

This vulnerability in FoxCMS allows attackers to bypass authorization controls by manipulating password parameters in the API endpoint. It affects all...

Dec 23, 2024
CVE-2024-12347
5.3

This CVE describes an improper authorization vulnerability in the Druid monitoring interface of Jeewms warehouse management software. Attackers can re...

Dec 9, 2024
CVE-2023-26280
5.3

This vulnerability allows authenticated users in IBM Jazz Foundation to modify dashboards they shouldn't have access to by sending specially crafted H...

Nov 25, 2024
CVE-2024-11306
5.3

This critical vulnerability in Altenergy Power Control Software allows unauthorized access to database information through improper authorization on t...

Nov 18, 2024
CVE-2024-10654
5.3

This vulnerability allows remote attackers to bypass authentication on TOTOLINK LR350 routers by manipulating the authCode parameter in the /formLogin...

Nov 1, 2024
CVE-2024-23794
5.2

An incorrect privilege assignment vulnerability in OTRS allows agents with read-only permissions to gain full access to tickets in rare configurations...

Jul 15, 2024
CVE-2025-65842
5.1

This vulnerability in Aquarius HelperTool (1.0.003) on macOS allows local attackers to escalate privileges to root. The XPC service fails to validate ...

Dec 3, 2025
CVE-2025-43260
5.1

This macOS vulnerability allows malicious applications to hijack entitlements granted to other privileged apps, potentially gaining unauthorized acces...

Jul 30, 2025
CVE-2026-1892
5.0

This CVE describes an improper authorization vulnerability in WeKan's REST API that allows attackers to manipulate board organization settings through...

Feb 4, 2026

About CWE-266 (CWE-266)

Our database tracks 417 CVEs classified as CWE-266, with 48 rated critical and 131 rated high severity. The average CVSS score for CWE-266 vulnerabilities is 6.7.

External reference: View CWE-266 on MITRE CWE →

Monitor CWE-266 Vulnerabilities

Get alerted when new CWE-266 CVEs affect your infrastructure.

Start Monitoring Free