CWE-266: CWE-266

417
Total CVEs
48
Critical
131
High
6.7
Avg CVSS

Yearly Trend

2026
74
2025
267
2024
59
2023
5
2022
4

Top Affected Vendors

1 Jeecg 11
2 Portabilis 11
3 Dell 10
4 Google 9
5 Fuyang Lipengjun 8
6 Macrozheng 8
7 Dlink 8
8 Totolink 7
9 Wekan Project 7
10 Youlai 6

All CWE-266 CVEs (417)

CVE-2025-12103
5.0

This vulnerability in Red Hat OpenShift AI Service's TrustyAI component grants excessive permissions to all authenticated users and service accounts. ...

Oct 28, 2025
CVE-2025-11281
5.0

This vulnerability in Frappe LMS 2.35.0 allows attackers to bypass access controls on unpublished courses through the /courses/ endpoint. Attackers ca...

Oct 5, 2025
CVE-2024-12666
4.7

This vulnerability in ClassCMS allows attackers to perform vertical privilege escalation through improper privilege handling in the user management co...

Dec 16, 2024
CVE-2026-2693
4.3

This vulnerability allows unauthorized access to system dashboard information in CoCoTeaNet CyreneAdmin up to version 1.3.0. Attackers can remotely ex...

Feb 19, 2026
CVE-2026-1964
4.3

This vulnerability in WeKan allows improper access controls through the REST endpoint, potentially enabling unauthorized access to board data. It affe...

Feb 5, 2026
CVE-2026-1733
4.3

This CVE describes an improper authorization vulnerability in Zhong Bang CRMEB's store integration API endpoint. Attackers can manipulate the order_id...

Feb 1, 2026
CVE-2026-22914
4.3

This vulnerability allows attackers with limited permissions to write files to specific locations on affected devices, potentially enabling system man...

Jan 15, 2026
CVE-2026-22916
4.3

This vulnerability allows low-privileged attackers to trigger critical system functions like reboot or factory reset without proper authorization. It ...

Jan 15, 2026
CVE-2025-15213
4.3

This vulnerability in Student File Management System 1.0 allows attackers to bypass authorization controls when downloading files via the /download.ph...

Dec 30, 2025
CVE-2025-15118
4.3

This vulnerability allows unauthorized modification of member address data in macrozheng mall versions up to 1.0.3. Attackers can exploit improper aut...

Dec 28, 2025
CVE-2025-15087
4.3

This vulnerability allows improper authorization in the submitOrderPayment function of youlai-mall, potentially enabling unauthorized order manipulati...

Dec 25, 2025
CVE-2025-15086
4.3

This vulnerability in youlaitech youlai-mall allows improper access controls via the getMemberByMobile function, enabling unauthorized access to membe...

Dec 25, 2025
CVE-2025-15085
4.3

This vulnerability allows unauthorized users to manipulate the balance deduction function in youlai-mall e-commerce platform, potentially enabling una...

Dec 25, 2025
CVE-2025-13807
4.3

This CVE describes an improper authorization vulnerability in orionsec orion-ops API that allows unauthorized access to machine key functionality. Att...

Dec 1, 2025
CVE-2025-13115
4.3

This vulnerability allows unauthorized access to order details in macrozheng mall-swarm and mall applications. Attackers can manipulate the orderId pa...

Nov 13, 2025
CVE-2025-12304
4.3

This vulnerability allows attackers to bypass authorization checks in the TIME-SEA-PLUS software's order status handler. Remote attackers can exploit ...

Oct 27, 2025
CVE-2025-11440
4.3

This vulnerability in JhumanJ OpnForm up to version 1.9.3 allows improper access controls via the /edit endpoint, potentially enabling unauthorized ac...

Oct 8, 2025
CVE-2025-11080
4.3

This CVE describes an improper authorization vulnerability in the wisdom-education software up to version 1.0.4. Attackers can remotely manipulate the...

Sep 27, 2025
CVE-2025-10981
4.3

This vulnerability in JeecgBoot allows unauthorized access to the tenant export function via the /sys/tenant/exportXls endpoint. Attackers can remotel...

Sep 26, 2025
CVE-2025-10980
4.3

JeecgBoot up to version 3.8.2 contains an improper authorization vulnerability in the /sys/position/exportXls endpoint that allows remote attackers to...

Sep 26, 2025
CVE-2025-10978
4.3

This vulnerability in JeecgBoot allows unauthorized access to the user export functionality via the /sys/user/exportXls endpoint. Attackers can exploi...

Sep 25, 2025
CVE-2025-10979
4.3

JeecgBoot up to version 3.8.2 has an improper authorization vulnerability in the /sys/role/exportXls endpoint that allows unauthorized access to role ...

Sep 25, 2025
CVE-2025-10822
4.3

CVE-2025-10822 is an improper authorization vulnerability in the fuyang_lipengjun platform 1.0 that allows unauthorized access to SMS log data via the...

Sep 23, 2025
CVE-2025-10821
4.3

This vulnerability allows unauthorized access to topic category data in fuyang_lipengjun platform 1.0 due to improper authorization in the TopicCatego...

Sep 22, 2025
CVE-2025-10820
4.3

This vulnerability in the fuyang_lipengjun platform 1.0 allows unauthorized access to the TopicController's queryAll function, enabling attackers to r...

Sep 22, 2025
CVE-2025-10819
4.3

This vulnerability in fuyang_lipengjun platform 1.0 allows unauthorized access to user coupon data through the UserCouponController queryAll function....

Sep 22, 2025
CVE-2025-10676
4.3

This vulnerability in fuyang_lipengjun platform 1.0 allows improper authorization through the BrandController function at /brand/queryAll. Attackers c...

Sep 18, 2025
CVE-2025-10674
4.3

CVE-2025-10674 is an improper authorization vulnerability in the fuyang_lipengjun platform 1.0 that allows attackers to access the /attributecategory/...

Sep 18, 2025
CVE-2025-10675
4.3

This vulnerability in fuyang_lipengjun platform 1.0 allows improper authorization via the AttributeController function at /attribute/queryAll, enablin...

Sep 18, 2025
CVE-2025-10422
4.3

This vulnerability in newbee-mall's order status handler allows attackers to manipulate order numbers to bypass authorization checks. Remote attackers...

Sep 15, 2025
CVE-2025-10084
4.3

This vulnerability allows unauthorized access to error log details in elunez eladmin systems. Attackers can remotely exploit improper authorization in...

Sep 8, 2025
CVE-2025-10073
4.3

This vulnerability in Portabilis i-Educar allows unauthorized access to class information through the /module/Api/turma endpoint. Attackers can exploi...

Sep 8, 2025
CVE-2025-48348
4.3

This vulnerability allows attackers to bypass intended access controls in the Site Offline WordPress plugin, potentially accessing restricted function...

Aug 28, 2025
CVE-2025-8790
4.3

This vulnerability in Portabilis i-Educar allows attackers to bypass authorization controls by manipulating the ID parameter in the /module/Api/pessoa...

Aug 10, 2025
CVE-2025-6702
4.3

This is a mass assignment vulnerability in Litemall 1.8.0 that allows unauthorized manipulation of adminComment parameters. Attackers can exploit this...

Jun 26, 2025
CVE-2025-6531
4.3

This vulnerability allows unauthenticated access to live video streams and recorded video files from SIFUSM/MZZYG BD S1 dashcams. Attackers on the sam...

Jun 24, 2025
CVE-2025-6525
4.3

This vulnerability allows unauthorized configuration changes on 70mai 1S dashcams via a local network attack. Attackers on the same network can modify...

Jun 23, 2025
CVE-2025-4017
4.3

This vulnerability in Novel-Plus allows unauthorized access to log viewing functionality due to improper authorization in the LogController. Attackers...

Apr 28, 2025
CVE-2025-3977
4.3

CVE-2025-3977 is an improper authorization vulnerability in iteachyou Dreamer CMS that allows attackers to bypass access controls on the attachment do...

Apr 27, 2025
CVE-2025-3564
4.3

This vulnerability allows unauthorized access to the Teacher String Handler component in huanfenz/code-projects StudentManager, potentially enabling a...

Apr 14, 2025
CVE-2025-3305
4.3

CVE-2025-3305 is an improper access control vulnerability in IKUN_Library 1.0 that allows remote attackers to bypass authorization checks in the Borro...

Apr 5, 2025
CVE-2025-3298
4.3

This vulnerability in SourceCodester Online Eyewear Shop 1.0 allows attackers to bypass access controls through manipulation of the email parameter in...

Apr 5, 2025
CVE-2025-27095
4.3

This vulnerability allows attackers with low-privileged JumpServer accounts to manipulate Kubernetes session configurations to redirect API requests t...

Mar 31, 2025
CVE-2025-2688
4.3

This vulnerability in TOTOLINK A3000RU routers allows improper access to the Syslog configuration file handler via /cgi-bin/ExportSyslog.sh. Attackers...

Mar 24, 2025
CVE-2025-2638
4.3

This vulnerability in JIZHICMS allows improper authorization through manipulation of the 'ishot' parameter in the Article Handler component. Attackers...

Mar 23, 2025
CVE-2025-2553
4.3

This vulnerability in D-Link DIR-618 and DIR-605L routers allows improper access control to the /goform/formVirtualServ endpoint, potentially enabling...

Mar 20, 2025
CVE-2025-2551
4.3

This vulnerability in D-Link DIR-618 and DIR-605L routers allows attackers with local network access to bypass access controls via the /goform/formSet...

Mar 20, 2025
CVE-2025-2549
4.3

This CVE describes an improper access control vulnerability in D-Link DIR-618 and DIR-605L routers affecting the /goform/formSetPassword endpoint. Att...

Mar 20, 2025
CVE-2025-1881
4.3

This vulnerability allows unauthorized access to video footage and live video streams in i-Drive i11 and i12 devices due to improper access controls. ...

Mar 3, 2025
CVE-2024-50701
4.3

TeamPass versions before 3.1.3.1 contain an authorization bypass vulnerability where users can access folder information without proper permission che...

Dec 30, 2024

About CWE-266 (CWE-266)

Our database tracks 417 CVEs classified as CWE-266, with 48 rated critical and 131 rated high severity. The average CVSS score for CWE-266 vulnerabilities is 6.7.

External reference: View CWE-266 on MITRE CWE →

Monitor CWE-266 Vulnerabilities

Get alerted when new CWE-266 CVEs affect your infrastructure.

Start Monitoring Free