CWE-276: CWE-276
Yearly Trend
Top Affected Vendors
All CWE-276 CVEs (426)
Energy Services solutions using G5DFR contain default credentials, allowing attackers to gain control of the G5DFR component and tamper with device ou...
Jun 10, 2025A vsftpd misconfiguration vulnerability in H3C wireless devices allows anonymous FTP uploads to be owned by the root user. Remote attackers can exploi...
Jan 6, 2026Apache DolphinScheduler versions before 3.2.2 have incorrect default permissions that could allow unauthorized access to sensitive functionality or da...
Sep 3, 2025CVE-2014-7210 is a privilege escalation vulnerability in pdns-backend-mysql where Debian maintainer scripts grant excessive database permissions to th...
Jun 26, 2025This vulnerability allows a local attacker on managed ChromeOS devices to bypass extension management controls, disable existing extensions, and acces...
Jun 16, 2025This vulnerability allows unauthenticated remote attackers to execute arbitrary code on Windows systems running the vulnerable SecureConnector agent. ...
May 13, 2025This CVE describes a permissions bypass vulnerability in Apple's Shortcuts app across multiple macOS and iPadOS versions. It allows malicious shortcut...
Mar 31, 2025This CVE describes a macOS permissions vulnerability where malicious applications can enable iCloud storage features without user consent. This affect...
Mar 31, 2025An integer overflow vulnerability in macOS allows local users to elevate privileges by exploiting improper input validation. This affects macOS Ventur...
Mar 31, 2025A sandbox escape vulnerability in Apple Mail allows malicious email content to bypass the 'Block All Remote Content' security setting. This could enab...
Mar 31, 2025CVE-2025-25535 is an HTTP response manipulation vulnerability in SCRIPT CASE v1.0.002 Build7 that allows remote attackers to escalate privileges by se...
Mar 26, 2025Insecure permissions in PipeCD v0.49 allow attackers to access the service account's authentication token, enabling privilege escalation within the Pi...
Mar 21, 2025CVE-2025-27682 is an insecure log permissions vulnerability in Vasion Print (formerly PrinterLogic) that allows local users to read sensitive log file...
Mar 5, 2025This vulnerability in Vasion Print (formerly PrinterLogic) allows unprivileged users to create symbolic links that can interact with files they should...
Mar 5, 2025Spotipy versions before 2.25.1 create cache files with overly permissive 644 permissions, exposing Spotify authentication tokens to other users or pro...
Feb 27, 2025A privilege escalation vulnerability in MaysWind ezBookkeeping 0.7.0 allows remote attackers to gain elevated privileges through manipulation of the t...
Feb 12, 2025An unauthenticated remote attacker can exploit the /auth/register initialization interface in Trojan versions 2.0.0 through 2.15.3 to escalate privile...
Feb 7, 2025This CVE describes a macOS permissions vulnerability where applications can access removable storage volumes without user consent. It affects macOS Ve...
Jan 27, 2025This vulnerability allows unauthenticated attackers to remotely configure the DMZ (Demilitarized Zone) service on affected D-Link routers via a crafte...
Jan 16, 2025CVE-2022-41572 is a privilege escalation vulnerability in EyesOfNetwork (EON) where nmap can be executed with root privileges, allowing attackers to g...
Jan 7, 2025COMFAST CF-WR630AX routers version 2.7.0.2 contain a hardcoded root password in /etc/shadow, allowing attackers to gain complete administrative contro...
Dec 10, 2024This vulnerability allows attackers to log in as root on affected WAVLINK routers using a hardcoded password stored in /etc/shadow. Anyone using WAVLI...
Dec 6, 2024OpenVidReview 1.0 has an authentication bypass vulnerability that allows unauthenticated users to upload files via the /upload route. This affects all...
Nov 27, 2024CVE-2018-9467 is an incorrect web origin determination vulnerability in Android's UriTest.java that allows attackers to bypass security decisions with...
Nov 20, 2024AVSCMS v8.2.0 uses weak default credentials for the Administrator account, allowing attackers to gain administrative access to the CMS. This affects a...
Nov 18, 2024CVE-2022-30355 is an account takeover vulnerability in OvalEdge data governance platform where authenticated users can modify other users' profiles vi...
Oct 25, 2024This vulnerability allows remote attackers to perform local file inclusion via the PassageAutoServer.php page in Automatic Systems Maintenance SlimLan...
Oct 14, 2024AWS Amplify CLI versions before 12.10.1 incorrectly configure IAM role trust policies when removing the Authentication component, leaving sts:AssumeRo...
Apr 15, 2024This CVE-2023-46773 is a permission management vulnerability in Huawei's PMS (Package Management Service) module that allows local attackers to escala...
Dec 6, 2023This vulnerability allows remote attackers to execute arbitrary code on GL.iNet AX1800 routers by exploiting insecure permissions in the file sharing ...
Nov 29, 2023Concrete CMS versions before 8.5.13 and 9.x before 9.2.2 create directories with insecure default permissions (0777), allowing unauthorized access. Th...
Nov 17, 2023This vulnerability allows unauthenticated attackers to bypass password reset controls in EMSigner v2.8.7, enabling them to access any user account inc...
Nov 14, 2023This vulnerability in TSplus Remote Access allows attackers to modify theme directories with 'Everyone' Full Control permissions, potentially enabling...
Sep 11, 2023This vulnerability in Samsung Exynos modem chips allows malicious applications to query RCS (Rich Communication Services) capabilities without proper ...
Jun 7, 2023SoLive Android app versions 1.6.14 through 1.6.20 have an exposed component that allows attackers to modify SharedPreference files. This can lead to v...
May 30, 2023CVE-2023-26918 is a privilege escalation vulnerability in Diasoft File Replication Pro 7.5.0 where the installation directory has overly permissive 'E...
Apr 14, 2023CVE-2021-34182 is a critical vulnerability in ttyd v1.6.3 that allows attackers to execute arbitrary code due to insecure default configuration permis...
Feb 17, 2023CVE-2022-28932 is a critical vulnerability in D-Link DSL-G2452DG routers where insecure permissions allow attackers to bypass authentication and gain ...
May 23, 2022CVE-2022-27919 is a critical remote code execution vulnerability in Gradle Enterprise that allows attackers to execute arbitrary code on affected syst...
Mar 25, 2022This vulnerability in debian-edu-config versions before 2.12.16 sets insecure permissions for user web shares (~/public_html), allowing local users to...
Feb 11, 2022eliteCMS v1.0 has an insecure permissions vulnerability in manage_uploads.php that allows attackers to bypass authentication and access administrative...
Feb 1, 2022Laundry Booking Management System 1.0 and previous versions contain a remote code execution vulnerability in profile.php via the 'image' parameter. At...
Jan 10, 2022A kernel crash vulnerability in Huawei smartphones allows local attackers to escalate privileges. This affects Huawei smartphone users running vulnera...
Oct 28, 2021Nagios XI versions before 5.8.5 have incorrect permissions on migrate.php, allowing unauthorized access. This vulnerability affects Nagios XI monitori...
Sep 28, 2021CVE-2021-36365 is a critical privilege escalation vulnerability in Nagios XI where the repairmysql.sh script has incorrect file permissions. This allo...
Sep 28, 2021CVE-2021-27193 is a critical vulnerability in Netop Vision Pro's API that allows remote unauthenticated attackers to read and write files with SYSTEM ...
Mar 25, 2021The SeTracker2 app for TK-Star Q90 Junior GPS watches requests excessive Android permissions (READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE, READ_CONT...
Feb 1, 2021CVE-2020-13452 is an insecure permissions vulnerability in Gotenberg where the tini process manager file is writable by the gotenberg user, allowing a...
Jan 7, 2021This vulnerability allows a local attacker to execute malicious code on Mitsubishi Electric FA engineering software when installed in non-default fold...
Sep 20, 2023CVE-2025-49084 allows attackers with administrative access to the Absolute Secure Access management console to overwrite policy rules without proper a...
Jul 31, 2025About CWE-276 (CWE-276)
Our database tracks 426 CVEs classified as CWE-276, with 59 rated critical and 273 rated high severity. The average CVSS score for CWE-276 vulnerabilities is 7.6.
External reference: View CWE-276 on MITRE CWE →
Monitor CWE-276 Vulnerabilities
Get alerted when new CWE-276 CVEs affect your infrastructure.
Start Monitoring Free