Skip to main content

CWE archive

CWE-732 CVEs

Programmatic archive

1,701 CVEs tagged with CWE-732140 Critical, 838 High, 623 Medium, 86 Low, 14 Unrated.

CVE-2025-26469

Published Jul 28, 2025

An incorrect default permissions vulnerability exists in the CServerSettings::SetRegistryValues functionality of MedDream PACS Premium 7.3.3.840. A specially crafted application…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-20198

Published Jul 23, 2025

The Marathon UI in DC/OS < 1.9.0 allows unauthenticated users to deploy arbitrary Docker containers. Due to improper restriction of volume mount configurations, attackers can depl…

CVSS 9.3 · Critical

CVE-2025-36104

Published Jul 12, 2025

IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive information from files due to the insecure permissions inherited through the SMB protoc…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39338

Published Jul 12, 2025

Enables an authenticated user (enrolled device) to access a service protected by Sentry even if they are not authorized according to the sentry policy to access that service. It d…

CVSS 6.8 · Medium

CVE-2025-27446

Published Jul 6, 2025

Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listening file permissions in APISIX plugin runner allow a local a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-6297

Published Jul 1, 2025

It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is documented as being a safe o…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-52992

Published Jun 27, 2025

The Nix, Lix, and Guix package managers fail to properly set permissions when a derivation build fails. This may allow arbitrary processes to modify the content of a store outside…

CVSS 3.2 · Low

CVE-2025-5995

Published Jun 26, 2025

Canon EOS Webcam Utility Pro for MAC OS version 2.3d (2.3.29) and earlier contains an improper directory permissions vulnerability. Exploitation of this vulnerability requires adm…

CVSS 4.6 · Medium

CVE-2024-11584

Published Jun 26, 2025

cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36537

Published Jun 24, 2025

Incorrect Permission Assignment for Critical Resource in the TeamViewer Client (Full and Host) of TeamViewer Remote and Tensor prior Version 15.67 on Windows allows a local unpriv…

CVSS 7.0 · High

CVE-2025-52923

Published Jun 22, 2025

Sangfor aTrust through 2.4.10 allows users to modify the ExecStartPre command.

CVSS 4.3 · Medium

CVE-2025-49131

Published Jun 9, 2025

FastGPT is an open-source project that provides a platform for building, deploying, and operating AI-driven workflows and conversational agents. The Sandbox container (fastgpt-san…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48961

Published Jun 4, 2025

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39938.

CVSS 7.3 · High

CVE-2024-45655

Published Jun 3, 2025

IBM Application Gateway 19.12 through 24.09 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2503

Published May 30, 2025

An improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to perform arbitrary file deletions as an elevated user.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48747

Published May 28, 2025

Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incorrect Permission Assignment for a Critical Resource.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48382

Published May 27, 2025

Fess is a deployable Enterprise Search Server. Prior to version 14.19.2, the createTempFile() method in org.codelibs.fess.helper.SystemHelper creates temporary files without expli…

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-46802

Published May 26, 2025

For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session.

CVSS 5.3 · Medium

CVE-2025-40672

Published May 26, 2025

A Privilege Escalation vulnerability has been found in Panloader component v3.24.0.0 by Espiral MS Group. This vulnerability allows any user to override the file panLoad.exe that…

CVSS 8.5 · High

CVE-2025-45472

Published May 22, 2025

Insecure permissions in autodeploy-layer v1.2.0 allows attackers to escalate privileges and compromise the customer cloud account.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-45468

Published May 22, 2025

Insecure permissions in fc-stable-diffusion-plus v1.0.18 allows attackers to escalate privileges and compromise the customer cloud account.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-45471

Published May 22, 2025

Insecure permissions in measure-cold-start v1.4.1 allows attackers to escalate privileges and compromise the customer cloud account.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 251-275 of 1,701 CVEsPage 11 of 69