Skip to main content

CWE archive

CWE-732 CVEs

Programmatic archive

1,716 CVEs tagged with CWE-732143 Critical, 845 High, 631 Medium, 97 Low, 0 Unrated.

CVE-2024-47808

Published Nov 12, 2024

A vulnerability has been identified in SINEC NMS (All versions < V3.0 SP1). The affected application contains a database function, that does not properly restrict the permissions…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47783

Published Nov 12, 2024

A vulnerability has been identified in SIPORT (All versions < V3.4.0). The affected application improperly assigns file permissions to installation folders. This could allow a…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50590

Published Nov 8, 2024

Attackers with local access to the medical office computer can escalate their Windows user privileges to "NT AUTHORITY\SYSTEM" by overwriting one of two Elefant service binaries…

CVSS 7.8 · High

CVE-2024-10526

Published Nov 7, 2024

Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation directory with WRITE_DACL permission to the BUILTIN\\Users…

CVSS 8.6 · High

CVE-2024-10228

Published Oct 29, 2024

The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified by an unprivileged user, introducing potential for unautho…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-0128

Published Oct 26, 2024

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager that allows a user of the guest OS to access global resources. A successful exploit of this vulnerability…

CVSS 7.1 · High

CVE-2022-30354

Published Oct 25, 2024

OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserWithTeam. Authentication is required. The information disclos…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46897

Published Oct 18, 2024

Incorrect permission assignment for critical resource issue exists in Exment v6.1.4 and earlier and Exment v5.0.11 and earlier. A logged-in user with the permission of table manag…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-6729

Published Oct 17, 2024

Nokia SR OS routers allow read-write access to the entire file system via SFTP or SCP for users configured with "access console." Consequently, a low privilege authenticated user…

CVSS 7.3 · High

CVE-2024-22029

Published Oct 16, 2024

Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root

CVSS 7.8 · High

CVE-2024-10018

Published Oct 16, 2024

Improper permission control in the mobile application (com.transsion.aivoiceassistant) can lead to the launch of any unexported component.

CVSS 9.8 · Critical

CVE-2024-44729

Published Oct 11, 2024

Incorrect access control in the component app/src/server.js of Mirotalk before commit 9de226 allows unauthenticated attackers without presenter privileges to arbitrarily eject use…

CVSS 7.5 · High

CVE-2024-47833

Published Oct 9, 2024

Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are se…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6360

Published Oct 2, 2024

Incorrect Permission Assignment for Critical Resource vulnerability in OpenText™ Vertica could allow Privilege Abuse and result in unauthorized access or privileges to Vertica age…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7594

Published Sep 26, 2024

Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH secrets engine confi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9142

Published Sep 25, 2024

External Control of File Name or Path, : Incorrect Permission Assignment for Critical Resource vulnerability in Olgu Computer Systems e-Belediye allows Manipulating Web Input to F…

CVSS 9.4 · Critical

CVE-2024-8900

Published Sep 17, 2024

An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129, Firefo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8039

Published Sep 14, 2024

Improper permission configurationDomain configuration vulnerability of the mobile application (com.afmobi.boomplayer) can lead to account takeover risks.

CVSS 9.8 · Critical

CVE-2024-41171

Published Sep 10, 2024

A vulnerability has been identified in SINUMERIK 828D V4 (All versions), SINUMERIK 828D V5 (All versions < V5.24), SINUMERIK 840D sl V4 (All versions), SINUMERIK ONE (All versions…

CVSS 9.3 · Critical
Showing 401-425 of 1,716 CVEsPage 17 of 69