Skip to main content

CWE archive

CWE-732 CVEs

Programmatic archive

1,707 CVEs tagged with CWE-732142 Critical, 842 High, 626 Medium, 96 Low, 1 Unrated.

CVE-2026-61892

Published Jul 24, 2026

Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.

CVSS 8.7 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-16157

Published Jul 22, 2026

Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. Installing the software outside of the Program Files director…

CVSS 7.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-62519

Published Jul 21, 2026

Vulnerability in the Oracle Succession planning product of Oracle E-Business Suite (component: Succession plan). Supported versions that are affected are 12.2.3-12.2.15. Easily e…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-61155

Published Jul 21, 2026

Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily expl…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-60659

Published Jul 21, 2026

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Easily exploitable vulnerability allows l…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-63358

Published Jul 21, 2026

FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' function through 'octdec()' conversio…

CVSS 8.4 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-44878

Published Jul 21, 2026

A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the device's filesystem. Successfu…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-65069

Published Jul 21, 2026

Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in dsu.h with o…

CVSS 4.0 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-65068

Published Jul 21, 2026

Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sphash.h wit…

CVSS 3.8 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-65067

Published Jul 21, 2026

Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in intern.h with ope…

CVSS 3.8 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-65066

Published Jul 21, 2026

Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ring.h with o…

CVSS 3.8 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-65065

Published Jul 21, 2026

Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in roaring.h…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-65064

Published Jul 21, 2026

Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in shm_generic.h wi…

CVSS 3.8 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-65063

Published Jul 21, 2026

Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in radix.h with o…

CVSS 3.8 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-65062

Published Jul 21, 2026

Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sortedset.h wi…

CVSS 3.8 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-65061

Published Jul 21, 2026

Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in reqrep.h with ope…

CVSS 3.8 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-64617

Published Jul 21, 2026

Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in pubsub.h with ope…

CVSS 3.8 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-64616

Published Jul 21, 2026

Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ndarray.h with o…

CVSS N/A · Unrated
evidence mentions
2
Buzz score
16.0

CVE-2026-64615

Published Jul 21, 2026

Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in graph.h with open(…

CVSS 3.3 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-64614

Published Jul 21, 2026

Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in deque.h with open(…

CVSS 3.8 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-64613

Published Jul 21, 2026

Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOLLOW. The segment is created in buf_generic.h with open(pat…

CVSS 6.2 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-47134

Published Jul 20, 2026

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. The ECDSA private key used to sign the on-disk policy database (`/Library/Appl…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-59866

Published Jul 17, 2026

The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Escalation’ vulnerability, which enables any logged-in non-ad…

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-49445

Published Jul 15, 2026

Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envoy insta…

CVSS 9.2 · Critical
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort
Showing 1-25 of 1,707 CVEsPage 1 of 69