VulnSea

CWE-266

CVEs classified under CWE-266, newest first.

165 CVEsRSS

CVE-2026-19359Medium· 4.7
1mo ago

A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0

A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function SitewiseCustomFunction of the component Lambda Function Handler. Such manipulation leads to improper access controls.…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-19358Medium· 6.3
1mo ago

A weakness has been identified in 3CORESec Trapdoor up to 1.2.2

A weakness has been identified in 3CORESec Trapdoor up to 1.2.2. Affected by this vulnerability is the function DefaultFunction. This manipulation causes improper access controls. The attack can be initiated remotely. The vendor was cont…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-19195High· 7.8PoC
1mo ago

A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39

A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack ne…

▾ MidnightEPSS 0.16%via NVD
CVE-2026-19193High· 7.8PoC
1mo ago

A flaw has been found in Jiangmin Antivirus 21

A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to…

▾ MidnightEPSS 0.16%via NVD
CVE-2026-19192High· 7.8
1mo ago

A vulnerability was detected in DeepCool DisplayService 1.2.12

A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe. Performing a manipulation results in improper access con…

▾ TwilightEPSS 0.16%via NVD
CVE-2026-28183High· 7.2
1mo ago

Incorrect Privilege Assignment vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Privilege Escalation.This issue affects PublishPress Capabilities: from n/a through 2.45.0.

Incorrect Privilege Assignment vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Privilege Escalation.This issue affects PublishPress Capabilities: from n/a through 2.45.0.

▾ TwilightPublishPress · capability-manager-enhancedEPSS 0.46%via NVD
CVE-2026-10059Critical· 9.1
1mo ago

A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller

A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertent…

▾ MidnightRed Hat · multicluster-engine/cluster-curator-controller-rhel9EPSS 0.64%via NVD
CVE-2026-52791None
2mo ago

fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers

fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branch preserves SUID and SGID mode bits in main.c during open(O_TRUNC) and truncate handling on a copied-up file, allowin…

▾ SunlitEPSS 0.14%via NVD
CVE-2026-17434Medium· 6.3
2mo ago

A flaw has been found in nanocoai NanoClaw up to 2.0.64

A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing a manipulation can lead to improper authorization…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-17433Medium· 5.3
2mo ago

A vulnerability was detected in nanocoai NanoClaw up to 2.0.64

A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. Performing a manipulation results in im…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-17432Medium· 5.0
2mo ago

A vulnerability was detected in NousResearch hermes-agent 2026.6.5

A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. …

▾ SunlitEPSS 0.36%via NVD
CVE-2026-58435Medium· 5.4
2mo ago

Gitea LFS Deploy-Key Privilege Escalation

Gitea LFS Deploy-Key Privilege Escalation

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.29%via GHSA
CVE-2026-16224Medium· 4.3
2mo ago

A vulnerability was identified in jxxghp MoviePilot up to 2.13.5

A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the file /jxxghp/MoviePilot of the component Application API. The manipulation leads to improper authorization. Remote explo…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-16199Medium· 6.3
2mo ago

A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3

A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file goclaw/internal/tools/credentialed_exec.go. Executing a manipulation can lead to improper authorization. The att…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-16121Medium· 6.3
2mo ago

A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2

A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isSafeBin of the file internal/tools/exec_approval.go. The manipulation leads to improper authorization. It is possible to initiate the atta…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-15510Medium· 6.3
2mo ago

A vulnerability was found in Leantime up to 3.8.0

A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. The manipulation results in improper authorization. The attack may be performed from remote. The exploit has been made…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-15509Medium· 6.3
2mo ago

A vulnerability has been found in Leantime up to 3.8.0

A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON-RPC Endpoint. The manipulation of the argument role leads to improper authorization. The attack is possible to be ca…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-15499Medium· 6.3
2mo ago

A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.2

A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.2. Affected is the function FutureTaskTool.call of the file astrbot/core/tools/cron_tools.py of the component Scheduled Task Handler. Performing a manipulation of the …

▾ SunlitEPSS 0.35%via NVD
CVE-2026-15476Medium· 5.3
2mo ago

A security vulnerability has been detected in QILING Disk Master 6.0.0.0

A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an unknown function in the library diskbckp.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The at…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-15475Medium· 5.3
2mo ago

A weakness has been identified in MiniTool Partition Wizard up to 13.6

A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in the library pwdrvio.sys of the component Signed Kernel Driver. This manipulation causes improper access controls. The …

▾ SunlitEPSS 0.15%via NVD
CVE-2026-15474Medium· 4.3
2mo ago

A security flaw has been discovered in Eleveo Call Recording Software 9.7.0

A security flaw has been discovered in Eleveo Call Recording Software 9.7.0. Impacted is an unknown function of the file /callrec/audio.jsp of the component Call Recording Handler. The manipulation of the argument callId results in impro…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-15473Medium· 6.3
2mo ago

A vulnerability was identified in Eleveo Call Recording Software 9.7.0

A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This issue affects some unknown processing of the file /callrec/restoreCallAction.do of the component Recorded Calls Page. The manipulation leads to improper authori…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-15472Medium· 4.3
2mo ago

A vulnerability was determined in Eleveo Call Recording Software 9.7.0

A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/composeEmailAction.do. Executing a manipulation can lead to improper authorization. The attack can be ex…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-15471Medium· 4.3
2mo ago

A vulnerability was found in Eleveo Call Recording Software 9.7.0

A vulnerability was found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/pci_dss_status.jsp. Performing a manipulation results in improper authorization. Remote exploitation of the attack is po…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-15470Medium· 4.3
2mo ago

A vulnerability has been found in Eleveo Call Recording Software 9.7.0

A vulnerability has been found in Eleveo Call Recording Software 9.7.0. Affected by this issue is some unknown functionality of the file /callrec/group.jsp. Such manipulation leads to improper authorization. The attack may be launched re…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-15376Medium· 6.3
2mo ago

A vulnerability was found in Eleveo Call Recording Software 9.7.0

A vulnerability was found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/statisticReportAction.do. The manipulation results in improper authorization. The attack can be launched remotely. Th…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-15271High· 7.5
2mo ago

A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 up to 20260906

A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 up to 20260906. Affected by this issue is some unknown functionality of the file /etc/boa/boa.conf of the component We…

▾ TwilightEPSS 0.71%via NVD
CVE-2026-57501None· 0.0
2mo ago

Zen is a firefox-based browser

Zen is a firefox-based browser. Prior to 1.21.5b, Zen's glance and split-view context-menu actions, Open link in glance and Split link in new tab, load a page-controlled link URL with the System principal instead of the originating page'…

▾ SunlitEPSS 0.51%via NVD
CVE-2026-15270High· 7.5
2mo ago

A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207

A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. Executing a manipulation can lead to least priv…

▾ TwilightEPSS 0.85%via NVD
CVE-2026-53814High· 8.4
2mo ago

OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority

OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority

▾ Twilightopenclaw · openclawEPSS 0.39%via GHSA
CWE-266 vulnerabilities (CVEs) — page 4 · VulnSea