Skip to main content

CWE archive

CWE-378 CVEs

Programmatic archive

46 CVEs tagged with CWE-3781 Critical, 21 High, 18 Medium, 6 Low, 0 Unrated.

CVE-2026-46388

Published Jul 10, 2026

osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, an unprivileged attacker can read the contents of an osquery file…

CVSS 4.4 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-4137

Published May 18, 2026

In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py` creates temporary directories with world-writable permissions…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-33572

Published Mar 29, 2026

OpenClaw before 2026.2.17 creates session transcript JSONL files with overly broad default permissions, allowing local users to read transcript contents. Attackers with local acce…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-4822

Published Mar 25, 2026

A vulnerability was detected in Enter Software Iperius Backup up to 8.7.3. Affected is an unknown function of the file C:\ProgramData\IperiusBackup\Jobs\ of the component Backup S…

CVSS 6.4 · Medium
evidence mentions
5
Buzz score
29.4

CVE-2026-2817

Published Feb 19, 2026

Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directories under the system temp location. On shared hosts, a local…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-46685

Published Jan 13, 2026

Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local acce…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-46684

Published Jan 13, 2026

Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local acce…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34352

Published Dec 2, 2025

JumpCloud Remote Assist for Windows versions prior to 0.317.0 include an uninstaller that is invoked by the JumpCloud Windows Agent as NT AUTHORITY\SYSTEM during agent uninstall o…

CVSS 8.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2025-7647

Published Sep 27, 2025

The llama-index-core package, up to version 0.12.44, contains a vulnerability in the `get_cache_dir()` function where a predictable, hardcoded directory path `/tmp/llama_index` is…

CVSS 7.3 · High

CVE-2025-4953

Published Sep 16, 2025

A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files creat…

CVSS 7.4 · High

CVE-2025-9474

Published Aug 26, 2025

A vulnerability was detected in Mihomo Party up to 1.8.1 on macOS. Affected is the function enableSysProxy of the file src/main/sys/sysproxy.ts of the component Socket Handler. Th…

CVSS 1.1 · Low

CVE-2025-55629

Published Aug 22, 2025

Insecure permissions in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allow attackers to arbitrarily change other users' passwords vi…

CVSS 6.5 · Medium

CVE-2025-38747

Published Aug 6, 2025

Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissions vulnerability. A local authenticated attacker could pote…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-32979

Published Apr 25, 2025

NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32438

Published Apr 15, 2025

make-initrd-ng is a tool for copying binaries and their dependencies. Local privilege escalation affecting all NixOS users. With systemd.shutdownRamfs.enable enabled (the default)…

CVSS 8.8 · High

CVE-2025-27148

Published Feb 25, 2025

Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. On Unix-like systems, the system temporary directory can be created with op…

CVSS 8.8 · High

CVE-2024-52543

Published Dec 25, 2024

Dell NativeEdge, version(s) 2.1.0.0, contain(s) a Creation of Temporary File With Insecure Permissions vulnerability. A high privileged attacker with local access could potentiall…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47884

Published Oct 11, 2024

foxmarks is a CLI read-only interface for Firefox's bookmarks and history. A temporary file was created under the /tmp directory with read permissions for all users containing a c…

CVSS 2.4 · Low

CVE-2024-23454

Published Sep 25, 2024

Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be present in this file, all the other local users may be able to…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7358

Published Aug 1, 2024

A vulnerability was found in Point B Ltd Getscreen Agent 2.19.6 on Windows. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the fil…

CVSS 8.5 · High

CVE-2024-42052

Published Jul 28, 2024

The MSI installer for Splashtop Streamer for Windows before 3.5.8.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate pr…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39872

Published Jul 9, 2024

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly assign rights to temporary files created…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-26603

Published Apr 26, 2024

JumpCloud Agent before 1.178.0 Creates a Temporary File in a Directory with Insecure Permissions. This allows privilege escalation to SYSTEM via a repair action in the installer.

CVSS 5.9 · Medium

CVE-2023-28600

Published Jun 13, 2023

Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to delete/replace Zoom Client files potentially causing a lo…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 46 CVEsPage 1 of 2