Skip to main content

CWE archive

CWE-732 CVEs

Programmatic archive

1,724 CVEs tagged with CWE-732143 Critical, 849 High, 634 Medium, 98 Low, 0 Unrated.

CVE-2024-7594

Published Sep 26, 2024

Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH secrets engine confi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9142

Published Sep 25, 2024

External Control of File Name or Path, : Incorrect Permission Assignment for Critical Resource vulnerability in Olgu Computer Systems e-Belediye allows Manipulating Web Input to F…

CVSS 9.4 · Critical

CVE-2024-8900

Published Sep 17, 2024

An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129, Firefo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8039

Published Sep 14, 2024

Improper permission configurationDomain configuration vulnerability of the mobile application (com.afmobi.boomplayer) can lead to account takeover risks.

CVSS 9.8 · Critical

CVE-2024-41171

Published Sep 10, 2024

A vulnerability has been identified in SINUMERIK 828D V4 (All versions), SINUMERIK 828D V5 (All versions < V5.24), SINUMERIK 840D sl V4 (All versions), SINUMERIK ONE (All versions…

CVSS 9.3 · Critical

CVE-2024-38456

Published Sep 3, 2024

HIGH-LEIT V05.08.01.03 and HIGH-LEIT V04.25.00.00 to 4.25.01.01 for Windows from Vivavis contain an insecure file and folder permissions vulnerability in prunsrv.exe. A regular us…

CVSS 7.8 · High

CVE-2023-49582

Published Aug 26, 2024

Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7986

Published Aug 23, 2024

A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerabili…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5930

Published Aug 21, 2024

VIPRE Advanced Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected inst…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7513

Published Aug 14, 2024

CVE-2024-7513 IMPACT A code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permissions allowing any user to edit or…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5915

Published Aug 14, 2024

A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges.

CVSS 5.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-6619

Published Aug 13, 2024

In Ocean Data Systems Dream Report, an incorrect permission vulnerability could allow a local unprivileged attacker to escalate their privileges and could cause a denial-of-servic…

CVSS 8.5 · High

CVE-2024-43199

Published Aug 7, 2024

Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned by the nagios user.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-41820

Published Aug 5, 2024

Kubean is a cluster lifecycle management toolchain based on kubespray and other cluster LCM engine. The ClusterRole has `*` verbs of `*` resources. If a malicious user can access…

CVSS 6.0 · Medium

CVE-2024-41954

Published Jul 31, 2024

FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account credentials in the "/opt/fog/.fogsettings" file. This file is b…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31202

Published Jul 31, 2024

A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perform a Local Privilege Escalation.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 426-450 of 1,724 CVEsPage 18 of 69