Skip to main content

CWE archive

CWE-732 CVEs

Programmatic archive

1,724 CVEs tagged with CWE-732143 Critical, 849 High, 634 Medium, 98 Low, 0 Unrated.

CVE-2026-50602

Published Aug 17, 2026

A security vulnerability has been identified in Planet9 due to incorrect file permissions assigned to an application executable used by the Planet9 background service. The service…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-73664

Published Aug 13, 2026

FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administrator's SSH public key and app…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-58432

Published Aug 13, 2026

Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Un…

CVSS 5.9 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-50544

Published Aug 13, 2026

NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default install, the file at `src/platfor…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65940

Published Aug 12, 2026

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-14478

Published Aug 12, 2026

A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify…

CVSS 7.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-48790

Published Aug 11, 2026

Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `settings.json` using Viper's de…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2025-0046

Published Aug 11, 2026

Incorrect directory permissions could allow a local user to escalate their privileges, potentially resulting in arbitrary code execution.

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-63522

Published Aug 11, 2026

Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
5
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-61970

Published Aug 11, 2026

Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to create arbitrary code, potentially resulting in binary hija…

CVSS 1.0 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-69108

Published Aug 11, 2026

A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is vulnerable to a local privilege escalation due to an insecur…

CVSS 8.3 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-4757

Published Aug 11, 2026

A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can only be exploited after authenti…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-63623

Published Aug 10, 2026

A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` util…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-15430

Published Aug 3, 2026

Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local priv…

CVSS 6.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-68563

Published Jul 30, 2026

A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data` option is selected, a Postgre…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-48499

Published Jul 30, 2026

Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an authenticated flow author reach r…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-61892

Published Jul 24, 2026

Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.

CVSS 8.7 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-16157

Published Jul 22, 2026

Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. Installing the software outside of the Program Files director…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-62519

Published Jul 21, 2026

Vulnerability in the Oracle Succession planning product of Oracle E-Business Suite (component: Succession plan). Supported versions that are affected are 12.2.3-12.2.15. Easily e…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-60659

Published Jul 21, 2026

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Easily exploitable vulnerability allows l…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-63358

Published Jul 21, 2026

FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' function through 'octdec()' conversio…

CVSS 8.4 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-44878

Published Jul 21, 2026

A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the device's filesystem. Successfu…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 1,724 CVEsPage 1 of 69