VulnSea

CWE-266

CVEs classified under CWE-266, newest first.

142 CVEsRSS

CVE-2026-94048Medium· 6.6PoC
yesterday

A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0

A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The manipulation of the argument role_id results in improper privilege man…

TwilightCodeAstro · QR Code Attendance Management SystemEPSS 0.23%via NVD
CVE-2026-94047Medium· 6.3
yesterday

A security vulnerability has been detected in samanhappy MCPHub up to 1.0.32

A security vulnerability has been detected in samanhappy MCPHub up to 1.0.32. The impacted element is the function importTemplate of the file src/services/templateService.ts of the component Template Import Endpoint. The manipulation lea…

Sunlitsamanhappy · MCPHubEPSS 0.41%via NVD
CVE-2026-94036High· 8.8PoC
yesterday

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results…

MidnightD-Link · DIR-X1860EPSS 0.47%via NVD
CVE-2026-93968Low· 3.8
yesterday

A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1

A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file backend/rbac/serializers.py of the component UserSerializer. Executing a manipulation can lead to improper privilege management. T…

Sunlitaiyiyi121 · SxDevOpsEPSS 0.26%via NVD
CVE-2026-93961Medium· 5.3
yesterday

A security flaw has been discovered in Dromara UJCMS up to 12.3.1

A security flaw has been discovered in Dromara UJCMS up to 12.3.1. The affected element is the function usernameExist of the file ujcms-cms/src/main/java/com/ujcms/cms/core/web/api/UserController.java of the component UserController. Per…

SunlitDromara · UJCMSEPSS 0.42%via NVD
CVE-2026-63349High· 7.0
3d ago

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and anyio.open_process(), but open_proce…

Twilightanyio · anyioEPSS 0.11%via NVD
CVE-2026-93504Medium· 6.3
3d ago

A vulnerability has been found in SveltyCMS 0.0.6

A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+server.ts of the component User Attribute Update Endpoint. Such manipulation leads to improper access controls. It is p…

SunlitEPSS 0.35%via NVD
CVE-2026-91099Critical· 9.8⚖ disputed
5d ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

Midnighthp · linux_imaging_and_printingEPSS 0.33%via NVD
CVE-2026-91100Critical· 9.8⚖ disputed
5d ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

Midnighthp · linux_imaging_and_printingEPSS 0.25%via NVD
CVE-2026-91101Critical· 9.8⚖ disputed
5d ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

Midnighthp · linux_imaging_and_printingEPSS 0.29%via NVD
CVE-2026-91105Critical· 9.8
5d ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

Midnighthp · linux_imaging_and_printingEPSS 0.67%via NVD
CVE-2026-91103Critical· 9.8⚖ disputed
5d ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

Midnighthp · linux_imaging_and_printingEPSS 0.29%via NVD
CVE-2026-73461High· 8.0
5d ago

On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the wrong privilege level, resulting in an authorization using the wrong AAA method list

On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the wrong privilege level, resulting in an authorization using the wrong AAA method list. Th…

TwilightArista Networks · EOSEPSS 0.30%via NVD
CVE-2026-91930High· 7.5PoC
6d ago

Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs

Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, cre…

MidnightFlowiseAI · FlowiseEPSS 0.37%via NVD
CVE-2026-92015High· 8.8
6d ago

Privilege escalation in the WebExtensions component

Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.28%via NVD
CVE-2026-92012High· 8.8
6d ago

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16…

TwilightMozilla · FirefoxEPSS 0.28%via NVD
CVE-2026-92017High· 8.8
6d ago

Privilege escalation in the DOM: Service Workers component

Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.26%via NVD
CVE-2026-92033High· 8.8
6d ago

Privilege escalation in Firefox for Android

Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.

TwilightMozilla · FirefoxEPSS 0.21%via NVD
CVE-2026-92047High· 8.8⚖ disputed
6d ago

Privilege escalation in the Crash Reporting component

Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.24%via NVD
CVE-2026-92053High· 8.8⚖ disputed
6d ago

Privilege escalation in the Graphics: CanvasWebGL component

Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.26%via NVD
CVE-2026-92062High· 8.8⚖ disputed
6d ago

Privilege escalation in the Session Restore component

Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.24%via NVD
CVE-2026-92073High· 8.8⚖ disputed
6d ago

Privilege escalation in the Enterprise Policies component

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.24%via NVD
CVE-2026-90856High· 7.3PoC
6d ago

A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0

A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts an unknown function of the file signup.php of the component Registration Flow. Such manipulation of the argument role …

MidnightSourceCodester · College Notes Gallery Management SystemEPSS 0.29%via NVD
CVE-2026-90851Medium· 6.3PoC
6d ago

A flaw has been found in PHPGurukul Hostel Management System 3.0

A flaw has been found in PHPGurukul Hostel Management System 3.0. This affects an unknown part of the file /admin/includes/checklogin.php. This manipulation of the argument ID causes improper access controls. Remote exploitation of the a…

TwilightPHPGurukul · Hostel Management SystemEPSS 0.21%via NVD
CVE-2026-90812Medium· 4.3PoC
1w ago

A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0

A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0. This impacts the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Permission. The manipulation…

Twilightcosmicstack-labs · mercury-agentEPSS 0.22%via NVD
CVE-2026-86830High· 7.2
1w ago

Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or r…

Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or r…

TwilightAWS · iam-identity-center-teamEPSS 0.38%via NVD
CVE-2026-90810Medium· 6.3PoC
1w ago

A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13

A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell…

Twilightcosmicstack-labs · mercury-agentEPSS 0.21%via NVD
CVE-2026-78330Critical· 9.8
1w ago

Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a succ…

Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a succ…

MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-springEPSS 0.60%via NVD
CVE-2026-90787High· 7.3PoC
1w ago

A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e

A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is the function RegisterServlet.doPost of the file code/WebContent/register.html of the component Registration Workflow.…

MidnightSoarkey · StudentManagementEPSS 0.40%via NVD
CVE-2026-90493High· 8.8PoC
1w ago

A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows

A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper acces…

MidnightTonec · Internet Download ManagerEPSS 0.11%via NVD
CWE-266 vulnerabilities (CVEs) · VulnSea