VulnSea

CWE-266

CVEs classified under CWE-266, newest first.

165 CVEsRSS

CVE-2025-13806High· 7.3
10mo ago

A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT

A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-web3j/src/main/java/io/nutz/demo/simple/module/EthMo…

▾ Twilightnutzam · nutzbootEPSS 0.47%via NVD
CVE-2025-13808High· 7.3
10mo ago

A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1

A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this vulnerability is the function update of the file orion-ops-api/orion-ops-web/src/main/java/cn/orionsec/ops/controller/UserContro…

▾ Twilightorionsec · orion-opsEPSS 0.48%via NVD
CVE-2025-13807Medium· 4.3
10mo ago

A vulnerability was detected in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1

A vulnerability was detected in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected is the function MachineKeyController of the file orion-ops-api/orion-ops-web/src/main/java/cn/orionsec/ops/controller/MachineKeyC…

▾ Sunlitorionsec · orion-opsEPSS 0.36%via NVD
CVE-2025-13787Medium· 5.4
10mo ago

A flaw has been found in ZenTao up to 21.7.6-8564

A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper pr…

▾ Sunlitzentao · zentaoEPSS 0.38%via NVD
CVE-2025-2843High· 8.8
10mo ago

A flaw was found in the Observability Operator

A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Custom Resource MonitorStack. This issue allows an adversarial Kubernetes Account with onl…

▾ TwilightRed Hat · Cluster Observability Operator 1.3.1EPSS 0.33%via NVD
CVE-2024-32009High· 7.8
10mo ago

A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2)

A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to a local privilege escalation due to wrongly set permissions to a binary which allows any local attack…

▾ TwilightEPSS 0.11%via NVD
CVE-2025-12103Medium· 5.0
11mo ago

A flaw was found in Red Hat Openshift AI Service

A flaw was found in Red Hat Openshift AI Service. The TrustyAI component is granting all service accounts and users on a cluster permissions to get, list, watch any pod in any namespace on the cluster. TrustyAI is creating a role `trus…

▾ SunlitEPSS 0.24%via NVD
CVE-2025-10644Critical· 9.40day
1y ago

Wondershare Repairit SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability

Wondershare Repairit SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on Wondershare Repairit. Authentication is not required to exploit th…

▾ Hadalwondershare · repairitEPSS 3.0%via NVD
CVE-2025-10608Medium· 6.3
1y ago

A vulnerability was detected in Portabilis i-Educar up to 2.10

A vulnerability was detected in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /enrollment-history/. Performing manipulation results in improper access controls. The attack is possible to be carri…

▾ Sunlitportabilis · i-educarEPSS 0.38%via NVD
CVE-2025-10209Medium· 5.4
1y ago

A security flaw has been discovered in Papermerge DMS up to 3.5.3

A security flaw has been discovered in Papermerge DMS up to 3.5.3. This issue affects some unknown processing of the component Authorization Token Handler. Performing manipulation results in improper authorization. The attack can be init…

▾ SunlitEPSS 0.29%via NVD
CVE-2025-10072Medium· 6.3PoC
1y ago

A vulnerability was found in Portabilis i-Educar up to 2.10

A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /matricula/[ID_STUDENT]/enturmar/. Performing a manipulation results in improper access controls. It is possible to initi…

▾ Twilightportabilis · i-educarEPSS 0.32%via NVD
CVE-2025-4374Medium· 6.5
1y ago

A flaw was found in Quay

A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.

▾ Sunlitredhat · quayEPSS 0.32%via NVD
CVE-2024-45331High· 7.3
1y ago

A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.2, For…

A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.2, For…

▾ Twilightfortinet · fortianalyzerEPSS 0.21%via NVD
CVE-2025-5791High· 7.1
1y ago

users: `root` appended to group listings (CVE-2025-5791)

A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in th…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.20%via CSAF
CVE-2024-33503Medium· 6.7
1y ago

A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiManager Cloud 7.2.1 through 7.2.5, FortiManager Cloud 7.0 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0 through 7…

A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiManager Cloud 7.2.1 through 7.2.5, FortiManager Cloud 7.0 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0 through 7…

▾ Sunlitfortinet · fortianalyzerEPSS 0.22%via NVD
CWE-266 vulnerabilities (CVEs) — page 6 · VulnSea