Skip to main content

CWE archive

CWE-276 CVEs

Programmatic archive

1,530 CVEs tagged with CWE-276118 Critical, 735 High, 616 Medium, 61 Low, 0 Unrated.

CVE-2025-22447

Published Mar 6, 2025

Incorrect access permission of a specific service issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is exploited, a non-administrati…

CVSS 7.8 · High

CVE-2025-27521

Published Mar 4, 2025

Vulnerability of improper access permission in the process management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-58050

Published Mar 4, 2025

Vulnerability of improper access permission in the HDC module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-58049

Published Mar 4, 2025

Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-58047

Published Mar 4, 2025

Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-58046

Published Mar 4, 2025

Permission management vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27154

Published Feb 27, 2025

Spotipy is a lightweight Python library for the Spotify Web API. The `CacheHandler` class creates a cache file to store the auth token. Prior to version 2.25.1, the file created h…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-56525

Published Feb 24, 2025

In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the…

CVSS 9.8 · Critical

CVE-2025-21106

Published Feb 20, 2025

Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission vulnerability. A low privileged Local attacker could potentially exploit this vulnerability, l…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-57604

Published Feb 12, 2025

An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-51440

Published Feb 12, 2025

An issue in Nothing Tech Nothing OS v.2.6 allows a local attacker to escalate privileges via the NtBpfService component.

CVSS 7.8 · High

CVE-2024-42419

Published Feb 12, 2025

Incorrect default permissions for some Intel(R) GPA and Intel(R) GPA Framework software installers may allow an authenticated user to potentially enable escalation of privilege vi…

CVSS 5.4 · Medium

CVE-2024-32942

Published Feb 12, 2025

Incorrect default permissions for some Intel(R) DSA installer for Windows before version 24.2.19.5 may allow an authenticated user to potentially enable escalation of privilege vi…

CVSS 5.4 · Medium

CVE-2023-31360

Published Feb 11, 2025

Incorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation directory could allow an attacker to achieve privilege escalat…

CVSS 7.3 · High

CVE-2024-55215

Published Feb 7, 2025

An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization interface /auth/register.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-11468

Published Feb 4, 2025

Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installation process. Successful exploitation of this issue may all…

CVSS 7.8 · High

CVE-2025-24891

Published Jan 31, 2025

Dumb Drop is a file upload application. Users with permission to upload to the service are able to exploit a path traversal vulnerability to overwrite arbitrary system files. As t…

CVSS 9.6 · Critical

CVE-2025-0797

Published Jan 29, 2025

A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been declared as problematic. This vulnerability affects unknown code of the file /var/Microworld/…

CVSS 4.8 · Medium
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-24826

Published Jan 28, 2025

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 4625.

CVSS 6.7 · Medium
Showing 276-300 of 1,530 CVEsPage 12 of 62