Skip to main content

CWE archive

CWE-732 CVEs

Programmatic archive

1,701 CVEs tagged with CWE-732140 Critical, 838 High, 623 Medium, 86 Low, 14 Unrated.

CVE-2025-21585

Published Apr 15, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Eas…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-21584

Published Apr 15, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily ex…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-21583

Published Apr 15, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.4.0 and 9.0.0. Easily exploitable vulnerability al…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-21581

Published Apr 15, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Eas…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-21580

Published Apr 15, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily ex…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-21579

Published Apr 15, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easil…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-21578

Published Apr 15, 2025

Vulnerability in Oracle Secure Backup (component: General). Supported versions that are affected are 12.1.0.1, 12.1.0.2, 12.1.0.3, 18.1.0.0, 18.1.0.1 and 18.1.0.2. Easily exploi…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-25041

Published Apr 1, 2025

A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM (root). A successf…

CVSS 5.5 · Medium

CVE-2025-20233

Published Mar 26, 2025

In the Splunk App for Lookup File Editing versions below 4.0.5, a script in the app used the `chmod` and `makedirs` Python functions in a way that resulted in overly broad read an…

CVSS 2.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-2098

Published Mar 26, 2025

Fast CAD Reader application on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS security practices, where appl…

CVSS 8.4 · High

CVE-2025-25373

Published Mar 25, 2025

The Memory Management Module of NASA cFS (Core Flight System) Aquila has insecure permissions, which can be exploited to gain an RCE on the platform.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-10209

Published Mar 25, 2025

An Incorrect Permission Assignment for Critical Resource vulnerability in the file system used in B&R APROL <4.4-01 may allow an authenticated local attacker to read and alter the…

CVSS 8.5 · High

CVE-2025-27688

Published Mar 18, 2025

Dell ThinOS 2408 and prior, contains an improper permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to El…

CVSS 7.8 · High

CVE-2025-27591

Published Mar 11, 2025

A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed loca…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-22454

Published Mar 11, 2025

Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-1413

Published Feb 28, 2025

DaVinci Resolve on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS security practices, where applications sho…

CVSS 8.4 · High

CVE-2025-1067

Published Feb 25, 2025

There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the local file system to introduce…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-27141

Published Feb 24, 2025

Metabase Enterprise Edition is the enterprise version of Metabase business intelligence and data analytics software. Starting in version 1.47.0 and prior to versions 1.50.36, 1.51…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13813

Published Feb 11, 2025

Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to delete arbitrary files.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-23403

Published Feb 11, 2025

A vulnerability has been identified in SIMATIC IPC DiagBase (All versions), SIMATIC IPC DiagMonitor (All versions). The affected device do not properly restrict the user permissio…

CVSS 7.3 · High

CVE-2025-0064

Published Feb 11, 2025

Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a…

CVSS 8.7 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2024-57520

Published Feb 5, 2025

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-57068

Published Feb 5, 2025

A prototype pollution in the lib.mutateMergeDeep function of @tanstack/form-core v0.35.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

CVSS 7.5 · High
Showing 301-325 of 1,701 CVEsPage 13 of 69