Skip to main content

CWE archive

CWE-732 CVEs

Programmatic archive

1,704 CVEs tagged with CWE-732142 Critical, 839 High, 625 Medium, 96 Low, 2 Unrated.

CVE-2024-57520

Published Feb 5, 2025

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-57068

Published Feb 5, 2025

A prototype pollution in the lib.mutateMergeDeep function of @tanstack/form-core v0.35.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

CVSS 7.5 · High

CVE-2025-0374

Published Jan 30, 2025

When etcupdate encounters conflicts while merging files, it saves a version containing conflict markers in /var/db/etcupdate/conflicts. This version does not preserve the mode of…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2025-24527

Published Jan 29, 2025

An issue was discovered in Akamai Enterprise Application Access (EAA) before 2025-01-17. If an admin knows another tenant's 128-bit connector GUID, they can execute debug commands…

CVSS 8.0 · High

CVE-2024-29869

Published Jan 28, 2025

Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set explicitly. Any unauthorized user…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24481

Published Jan 28, 2025

An Incorrect Permission Assignment Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect permissions being assigned to the remote deb…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2024-57547

Published Jan 27, 2025

Insecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the Functionality of downloading php backup…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46881

Published Jan 26, 2025

Develocity (formerly Gradle Enterprise) before 2024.1.8 has Incorrect Access Control. Project-level access control configuration was introduced in Enterprise Config schema version…

CVSS 7.1 · High

CVE-2025-21571

Published Jan 21, 2025

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.24 and prior to 7.1.6. Easily…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-21566

Published Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.1.0 and prior. Easily exploitable vulnerabili…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-21564

Published Jan 21, 2025

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily e…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-21551

Published Jan 21, 2025

Vulnerability in the Oracle Solaris product of Oracle Systems (component: File system). The supported version that is affected is 11. Easily exploitable vulnerability allows hig…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-21523

Published Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Ea…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0590

Published Jan 20, 2025

Improper permission settings for mobile applications (com.transsion.carlcare) may lead to information leakage risk.

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2024-51448

Published Jan 18, 2025

IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files in the install inherit the file…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39967

Published Jan 15, 2025

Insecure permissions in Aginode GigaSwitch v5 allows attackers to access sensitive information via using the SCP command.

CVSS 6.5 · Medium

CVE-2024-11497

Published Jan 14, 2025

An authenticated attacker can use this vulnerability to perform a privilege escalation to gain root access.

CVSS 8.8 · High

CVE-2025-0066

Published Jan 14, 2025

Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due to weak access cont…

CVSS 9.9 · Critical
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2024-54910

Published Jan 10, 2025

Hasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File recovery function.

CVSS 4.7 · Medium

CVE-2023-38037

Published Jan 9, 2025

ActiveSupport::EncryptedFile writes contents that will be encrypted to a temporary file. The temporary file's permissions are defaulted to the user's current `umask` settings,…

CVSS 5.5 · Medium
Showing 326-350 of 1,704 CVEsPage 14 of 69