Skip to main content

CWE archive

CWE-379 CVEs

Programmatic archive

59 CVEs tagged with CWE-3790 Critical, 27 High, 31 Medium, 1 Low, 0 Unrated.

CVE-2026-14551

Published Jul 22, 2026

The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privilege…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-46388

Published Jul 10, 2026

osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, an unprivileged attacker can read the contents of an osquery file…

CVSS 4.4 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-7539

Published Jun 24, 2026

A potential security vulnerability has been identified in the HP Accessory WMI Provider installer for some HP Docking Stations, which might allow escalation of privilege and/or ar…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-54328

Published Jun 23, 2026

Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi versions with temporary npm or git extension package installs used predictable paths under the operating syst…

CVSS 7.3 · High
evidence mentions
5
Buzz score
22.9

CVE-2019-25677

Published Apr 5, 2026

WinRAR 5.61 contains a denial of service vulnerability that allows local attackers to crash the application by placing a malformed winrar.lng language file in the installation dir…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-2817

Published Feb 19, 2026

Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directories under the system temp location. On shared hosts, a local…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-10279

Published Feb 2, 2026

In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure world-writable permissions (0o777). This vulnerability allows…

CVSS 7.0 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-71176

Published Jan 22, 2026

pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.

CVSS 6.8 · Medium

CVE-2025-64896

Published Dec 9, 2025

Creative Cloud Desktop versions 6.4.0.361 and earlier are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could lead to applica…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-33111

Published Dec 8, 2025

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 is vulnerable to creation of temporary files without atomic operations which may expose se…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7562

Published Jun 12, 2025

A potential elevated privilege issue has been reported with InstallShield built Standalone MSI setups having multiple InstallScript custom actions configured. All supported versio…

CVSS 7.3 · High

CVE-2025-32802

Published May 28, 2025

Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API en…

CVSS 6.1 · Medium

CVE-2025-32438

Published Apr 15, 2025

make-initrd-ng is a tool for copying binaries and their dependencies. Local privilege escalation affecting all NixOS users. With systemd.shutdownRamfs.enable enabled (the default)…

CVSS 8.8 · High

CVE-2025-27148

Published Feb 25, 2025

Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. On Unix-like systems, the system temporary directory can be created with op…

CVSS 8.8 · High

CVE-2025-21162

Published Feb 11, 2025

Photoshop Elements versions 2025.0 and earlier are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could result in privilege es…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-9500

Published Nov 15, 2024

A maliciously crafted DLL file when placed in temporary files and folders that are leveraged by the Autodesk Installer could lead to escalation of privileges to NT AUTHORITY/SYSTE…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6080

Published Oct 18, 2024

Lakeside Software’s SysTrack LsiAgent Installer version 10.7.8 for Windows contains a local privilege escalation vulnerability which allows attackers SYSTEM level access.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38533

Published Jun 11, 2024

A vulnerability has been identified in TIA Administrator (All versions < V3 SP2). The affected component creates temporary download files in a directory with insecure permissions.…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24693

Published Mar 13, 2024

Improper access control in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user to conduct a denial of service via local access.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40438

Published Jan 10, 2024

An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14, iOS 16.7 and iPadOS 16.7. An app may be able to access edited photos save…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 59 CVEsPage 1 of 3