VulnSea

CWE-266

CVEs classified under CWE-266, newest first.

165 CVEsRSS

CVE-2026-9795High· 7.3
2mo ago

Keycloak has privilege escalation via improper scope mapping enforcement

Keycloak has privilege escalation via improper scope mapping enforcement

▾ Twilightkeycloak · org.keycloak:keycloak-servicesEPSS 0.49%via GHSA
CVE-2026-13524Medium· 5.6
3mo ago

A security vulnerability has been detected in CherryHQ cherry-studio up to 1.9.6

A security vulnerability has been detected in CherryHQ cherry-studio up to 1.9.6. This vulnerability affects unknown code of the file src/main/services/mcp/oauth/callback.ts of the component MCP OAuth Local Callback Server. The manipulat…

▾ SunlitEPSS 0.42%via NVD
CVE-2026-13511Low· 3.1
3mo ago

A vulnerability was determined in VoltAgent up to 2.1.17

A vulnerability was determined in VoltAgent up to 2.1.17. Affected by this issue is the function handleGetMemoryConversation of the file packages/server-core/src/handlers/memory.handlers.ts of the component Memory REST API. Executing a m…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-12823Low· 3.3
3mo ago

A security flaw has been discovered in Browserbase Skills up to 20260526

A security flaw has been discovered in Browserbase Skills up to 20260526. This impacts an unknown function of the component Autobrowse Trace Artifact Handler. The manipulation results in incorrect default permissions. The attack requires…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-12799Medium· 4.3
3mo ago

BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure

BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure

▾ Sunlitlitellm · litellmEPSS 0.43%via OSV
CVE-2026-12770Medium· 5.4
3mo ago

LiteLLM: Admin Key Handler Has Improper Authorization

LiteLLM: Admin Key Handler Has Improper Authorization

▾ Sunlitlitellm · litellmEPSS 0.57%via OSV
CVE-2026-12771Medium· 5.0
3mo ago

LiteLLM: M2M JWT Handler Has Improper Authorization

LiteLLM: M2M JWT Handler Has Improper Authorization

▾ Sunlitlitellm · litellmEPSS 0.43%via OSV
GHSA-6jcq-6546-qrrwHigh· 8.8
3mo ago

PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable

PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable

▾ Twilightpraisonai · praisonaivia GHSA
CVE-2026-53847Medium
3mo ago

OpenClaw: Active Memory write scope could mutate global config

OpenClaw: Active Memory write scope could mutate global config

▾ Sunlitopenclaw · openclawEPSS 0.30%via GHSA
CVE-2026-54196Medium· 6.8
3mo ago

Incorrect Privilege Assignment vulnerability in Jetmonsters JetFormBuilder allows Privilege Escalation. This issue affects JetFormBuilder: from n/a through 3.6.1.

Incorrect Privilege Assignment vulnerability in Jetmonsters JetFormBuilder allows Privilege Escalation. This issue affects JetFormBuilder: from n/a through 3.6.1.

▾ SunlitJetmonsters · JetFormBuilderEPSS 0.28%via NVD
CVE-2026-12294Critical· 9.6
3mo ago

Sandbox escape in the DOM: Workers component

Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

▾ Midnightmozilla · firefoxEPSS 0.36%via NVD
CVE-2026-12289High· 8.8
3mo ago

Privilege escalation in the Graphics: WebRender component

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

▾ Twilightmozilla · firefoxEPSS 0.40%via NVD
GHSA-58wc-8wrv-xp9jMedium· 5.4
3mo ago

Duplicate Advisory: Active Memory write scope could mutate global config

Duplicate Advisory: Active Memory write scope could mutate global config

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-h9h6-pwqv-j9hvLow· 4.2
3mo ago

Duplicate Advisory: Bootstrap token replay could widen pending pairing scopes

Duplicate Advisory: Bootstrap token replay could widen pending pairing scopes

▾ Sunlitopenclaw · openclawvia GHSA
CVE-2025-10263Critical· 9.1
3mo ago

Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may all…

Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may all…

▾ MidnightEPSS 0.54%via NVD
CVE-2026-8241Medium· 5.3
4mo ago

A vulnerability has been found in Industrial Application Software IAS Canias ERP 8.03

A vulnerability has been found in Industrial Application Software IAS Canias ERP 8.03. The affected element is the function iasGetServerInfoEvent of the component RMI Interface. Such manipulation leads to improper authorization. The atta…

▾ SunlitEPSS 0.48%via NVD
CVE-2026-8233Medium· 4.6
4mo ago

A vulnerability was determined in Dotouch XproUPF 2.0.0-release-088aa7c4

A vulnerability was determined in Dotouch XproUPF 2.0.0-release-088aa7c4. Affected is an unknown function of the component UPF. This manipulation causes improper access controls. A high degree of complexity is needed for the attack. The …

▾ SunlitEPSS 0.20%via NVD
CVE-2026-43510Medium· 5.9
4mo ago

manage.get.gov is the .gov TLD registrar maintained by CISA

manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assign domain manager privileges for domains not already in another organization. Fixed in 1.176.0 on or around 2026-04-30.

▾ SunlitEPSS 0.59%via NVD
CVE-2026-5569High· 7.3
5mo ago

A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30

A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impacted is an unknown function of the file /Technostrobe/ of the component Endpoint. The manipulation results in improper access controls. The attack may be perf…

▾ Twilighttechnostrobe · hi-led-wr120-g2_firmwareEPSS 0.70%via NVD
CVE-2026-5529Medium· 4.3
5mo ago

A vulnerability was detected in Dromara lamp-cloud up to 5.8.1

A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the file /defUser/pageUser of the component DefUserController. Performing a manipulation results in improper authorizatio…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-5526High· 7.3
5mo ago

A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1

A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionality of the file /bin/httpd. The manipulation results in improper access controls. The att…

▾ Twilighttenda · 4g03_pro_firmwareEPSS 0.65%via NVD
CVE-2026-5484Medium· 5.3
5mo ago

A weakness has been identified in BookStackApp BookStack up to 26.03

A weakness has been identified in BookStackApp BookStack up to 26.03. Affected is the function chapterToMarkdown of the file app/Exports/ExportFormatter.php of the component Chapter Export Handler. Executing a manipulation of the argumen…

▾ SunlitEPSS 0.55%via NVD
CVE-2026-32916Critical· 9.4
6mo ago

OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes

OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes. Remote unauthenticated r…

▾ Midnightopenclaw · openclawEPSS 0.63%via NVD
CVE-2026-33997Medium· 6.8
6mo ago

Moby is an open source container framework

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privile…

▾ Sunlitdocker · engineEPSS 0.51%via NVD
CVE-2026-2015Medium· 6.3PoC
7mo ago

A weakness has been identified in Portabilis i-Educar up to 2.10

A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file FinalStatusImportService.php of the component Final Status Import. Executing a manipulation of the argument school_id can lead …

▾ Twilightportabilis · i-educarEPSS 0.31%via NVD
CVE-2026-20852High· 7.7
8mo ago

Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.

Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.51%via NVD
CVE-2026-20804High· 7.7
8mo ago

Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.

Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.51%via NVD
CVE-2025-64188Critical· 9.8
9mo ago

Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affects Soledad: from n/a through <= 8.6.9.

Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affects Soledad: from n/a through <= 8.6.9.

▾ MidnightEPSS 0.43%via NVD
CVE-2025-14052Medium· 6.3
9mo ago

A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0

A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function getMemberById of the file /mall-ums/app-api/v1/members/. The manipulation of the argument memberId leads to improper acc…

▾ Sunlityoulai · youlai-mallEPSS 0.26%via NVD
CVE-2025-66296High· 8.8
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin plugin due to the absence of username uniqueness validation when creating users. A user with the create user permissio…

▾ Twilightgetgrav · gravEPSS 0.32%via NVD
CWE-266 vulnerabilities (CVEs) — page 5 · VulnSea