Skip to main content

CWE archive

CWE-277 CVEs

Programmatic archive

71 CVEs tagged with CWE-2774 Critical, 20 High, 43 Medium, 4 Low, 0 Unrated.

CVE-2026-9046

Published Jul 16, 2026

A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-7891

Published May 7, 2026

A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not adequately describe the special behavior of the System.User en…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
32.6

CVE-2026-30266

Published Apr 20, 2026

Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbitrary code via a crafted file

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-20630

Published Feb 11, 2026

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be able to access protected user data.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-37174

Published Jan 13, 2026

Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful e…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-65111

Published Nov 21, 2025

SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to version 1.47.1, if a schema includes the following characte…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-64185

Published Nov 20, 2025

Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations in the GEM_PATH. Open OnDemand versions 4.0.…

CVSS 6.9 · Medium

CVE-2025-24327

Published Nov 11, 2025

Insecure inherited permissions for some Intel(R) Rapid Storage Technology Application before version 20.0.1021 within Ring 3: User Applications may allow an escalation of privileg…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-11554

Published Oct 9, 2025

A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown functionality of the file app/Http/Controllers/AccessLevelCo…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-58437

Published Sep 6, 2025

Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3, 2.25.0 and 2.25.1, Coder can be compromised through inse…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-9039

Published Aug 14, 2025

We identified an issue in the Amazon ECS agent where, under certain conditions, an introspection server could be accessed off-host by another instance if the instances are in the…

CVSS 5.3 · Medium

CVE-2025-36104

Published Jul 12, 2025

IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive information from files due to the insecure permissions inherited through the SMB protoc…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32797

Published Jun 16, 2025

Conda-build contains commands and tools to build conda packages. Prior to version 25.3.1, the write_build_scripts function in conda-build creates the temporary build script conda_…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3473

Published Jun 11, 2025

IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by the program.

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-22448

Published May 13, 2025

Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow an authenticated user to potentially enable denial of service v…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-20629

Published May 13, 2025

Insecure inherited permissions in the NVM Update Utility for some Intel(R) Ethernet Network Adapter E810 Series before version 4.60 may allow an authenticated user to potentially…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-20008

Published May 13, 2025

Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow a privileged user to potentially enable escalation of privilege…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-29982

Published Apr 2, 2025

Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insecure Inherited Permissions vulnerability. A low privileged attacker with local access could potentially expl…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28207

Published Mar 21, 2025

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A plug-in may be able to inherit app permissi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51448

Published Jan 18, 2025

IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files in the install inherit the file…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36294

Published Nov 13, 2024

Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local acce…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 71 CVEsPage 1 of 3