Skip to main content

CWE archive

CWE-276 CVEs

Programmatic archive

1,530 CVEs tagged with CWE-276118 Critical, 735 High, 616 Medium, 61 Low, 0 Unrated.

CVE-2025-23386

Published Apr 10, 2025

A Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed package gerbera allows the service user gerbera to escalate to root.,This issue affects gerbera on openSUS…

CVSS 7.8 · High

CVE-2025-29801

Published Apr 8, 2025

Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-29504

Published Apr 3, 2025

Insecure Permission vulnerability in student-manage 1 allows a local attacker to escalate privileges via the Unsafe permission verification.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-0014

Published Apr 2, 2025

Incorrect default permissions on the AMD Ryzen(TM) AI installation folder could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code executio…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-30465

Published Mar 31, 2025

A permissions issue was addressed with improved validation. This issue is fixed in iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sequoia 15.7.2, macOS Sonoma 14.7.5, macOS Sonoma 14.8.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-24277

Published Mar 31, 2025

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-24267

Published Mar 31, 2025

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain ro…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-24234

Published Mar 31, 2025

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to gain…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-24207

Published Mar 31, 2025

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to enable…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-24195

Published Mar 31, 2025

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A user may be able to eleva…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-24172

Published Mar 31, 2025

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. "Block All Remote Con…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-24170

Published Mar 31, 2025

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root priv…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-2782

Published Mar 28, 2025

The WatchGuard Terminal Services Agent on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated lo…

CVSS 6.3 · Medium

CVE-2025-2781

Published Mar 28, 2025

The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated…

CVSS 6.3 · Medium

CVE-2025-25535

Published Mar 26, 2025

HTTP Response Manipulation in SCRIPT CASE v.1.0.002 Build7 allows a remote attacker to escalate privileges via a crafted request.

CVSS 9.8 · Critical

CVE-2024-53351

Published Mar 21, 2025

Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalation of privileges.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-27612

Published Mar 21, 2025

libcontainer is a library for container control. Prior to libcontainer 0.5.3, while creating a tenant container, the tenant builder accepts a list of capabilities to be added in t…

CVSS 5.9 · Medium

CVE-2025-24915

Published Mar 21, 2025

When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not enforce secure permissions for sub-directories.  This could…

CVSS 7.8 · High

CVE-2024-0245

Published Mar 20, 2025

A misconfiguration in the AndroidManifest.xml file in hamza417/inure before build97 allows for task hijacking. This vulnerability permits malicious applications to inherit permiss…

CVSS 5.5 · Medium

CVE-2025-27926

Published Mar 10, 2025

In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are readable by unauthorized users.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-20910

Published Mar 6, 2025

Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery.

CVSS 6.2 · Medium

CVE-2025-24864

Published Mar 6, 2025

Incorrect access permission of a specific folder issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is exploited, a non-administrativ…

CVSS 7.8 · High
Showing 251-275 of 1,530 CVEsPage 11 of 62