Skip to main content

CWE archive

CWE-732 CVEs

Programmatic archive

1,701 CVEs tagged with CWE-732140 Critical, 838 High, 623 Medium, 86 Low, 14 Unrated.

CVE-2025-2759

Published May 22, 2025

GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-34025

Published May 21, 2025

The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escape vulnerability caused by unsafe default mounting of host binary path…

CVSS 8.6 · High

CVE-2025-24009

Published May 13, 2025

A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). The affected devices do not require authen…

CVSS 8.2 · High

CVE-2025-42997

Published May 13, 2025

Under certain conditions, SAP Gateway Client allows a high-privileged user to access restricted information beyond the scope of the application. Due to the possibility of influenc…

CVSS 6.6 · Medium

CVE-2025-26169

Published May 7, 2025

IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there is code execution from a configuration file that can be controlled by a low-privi…

CVSS 8.1 · High

CVE-2025-26168

Published May 7, 2025

IXON VPN Client before 1.4.4 on Linux and macOS allows Local Privilege Escalation to root because there is code execution from a configuration file that can be controlled by a low…

CVSS 8.1 · High

CVE-2025-23245

Published May 1, 2025

NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows a guest to access global resources. A successful expl…

CVSS 5.5 · Medium

CVE-2025-3395

Published Apr 30, 2025

Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder.This issue affects Automation Builder: th…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-3394

Published Apr 30, 2025

Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-30408

Published Apr 24, 2025

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39904, Acronis Cyber P…

CVSS 6.7 · Medium

CVE-2025-0926

Published Apr 23, 2025

Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to remove system files causing a boot loop by redirecting a fi…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-0758

Published Apr 16, 2025

Overview  The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. (CWE-732)  Descr…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-30708

Published Apr 15, 2025

Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Search and Register Users). Supported versions that are affected are 12.2.4-12.2.14. Ea…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-30688

Published Apr 15, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Eas…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-30687

Published Apr 15, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Eas…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-30685

Published Apr 15, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. E…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-30684

Published Apr 15, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. E…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-30683

Published Apr 15, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. E…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-30682

Published Apr 15, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Eas…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 1,701 CVEsPage 12 of 69