Skip to main content

CWE archive

CWE-276 CVEs

Programmatic archive

1,533 CVEs tagged with CWE-276118 Critical, 738 High, 616 Medium, 61 Low, 0 Unrated.

CVE-2026-39875

Published Jul 27, 2026

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to…

CVSS 7.8 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-39874

Published Jul 27, 2026

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to…

CVSS 7.8 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-17497

Published Jul 26, 2026

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. Java…

CVSS 8.3 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-16247

Published Jul 20, 2026

In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this process, existing permissions on %ProgramData% are deleted and re…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-16246

Published Jul 20, 2026

In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows group Everyone is granted full control over %ProgramData% in…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2024-58356

Published Jul 18, 2026

SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... OVERWRITE clause is used on tables defined with TYPE RELATION. Because table definit…

CVSS 2.3 · Low
evidence mentions
2
Buzz score
17.5

CVE-2023-54366

Published Jul 18, 2026

SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables without explicit permissions. Attac…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-40952

Published Jul 15, 2026

CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client o…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-61828

Published Jul 15, 2026

Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and 26.05 channel fixes, the NixOS module for MySQL services.my…

CVSS 8.5 · High
evidence mentions
7
Buzz score
25.8

CVE-2026-53657

Published Jul 10, 2026

Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to 2.1.3, on an instance of Lima running with the qemu driver, an arbitrary user in the VM…

CVSS 8.2 · High
evidence mentions
4
Buzz score
21.1

CVE-2025-27464

Published Jul 9, 2026

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities t…

CVSS 9.4 · Critical

CVE-2025-27463

Published Jul 9, 2026

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities t…

CVSS 9.4 · Critical

CVE-2025-27462

Published Jul 9, 2026

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities…

CVSS 9.4 · Critical

CVE-2026-57895

Published Jul 8, 2026

Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0. An attacker can place a malicious executable in the installation folder, which results in arbitrary…

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57919

Published Jun 29, 2026

PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DACL that grants GENERIC_READ and GENERIC_WRITE permissions t…

CVSS 7.8 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-57924

Published Jun 26, 2026

In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48935

Published Jun 26, 2026

A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all s…

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48725

Published Jun 24, 2026

Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp allows terminal output to request access to the local system…

CVSS 8.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-56301

Published Jun 23, 2026

Nuxt 4.0.0 before 4.4.7 and 3.18.0 before 3.21.7, when running the development server (nuxt dev) on Linux, binds the vite-node IPC server to an abstract-namespace Unix socket with…

CVSS 6.8 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-12602

Published Jun 22, 2026

Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assignment of inappropriate permissions during the software’s de…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-12823

Published Jun 22, 2026

A security flaw has been discovered in Browserbase Skills up to 20260526. This impacts an unknown function of the component Autobrowse Trace Artifact Handler. The manipulation res…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-53870

Published Jun 17, 2026

Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversation history and HMAC secrets to…

CVSS 6.8 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2025-15642

Published Jun 17, 2026

Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with admin privileges can lead to bypassing the NSClient Tamper Pr…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-50255

Published Jun 16, 2026

Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulnerability is exploited, arbitrary code may be executed with…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-11931

Published Jun 15, 2026

Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication token cache file to other local users or processes via world-r…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
21.0
Showing 1-25 of 1,533 CVEsPage 1 of 62