CWE-276: CWE-276

430
Total CVEs
59
Critical
277
High
7.6
Avg CVSS

Yearly Trend

2026
30
2025
139
2024
124
2023
57
2022
30

Top Affected Vendors

1 Google 38
2 Apple 25
3 Huawei 15
4 Intel 13
5 Dell 10
6 Amd 6
7 Advantech 6
8 Oracle 5
9 Ivanti 5
10 Juniper 5

All CWE-276 CVEs (430)

CVE-2025-24107
7.8

A permissions vulnerability in Apple operating systems allows malicious applications to escalate privileges to root access. This affects macOS, tvOS, ...

Jan 27, 2025
CVE-2025-0543
7.8

CVE-2025-0543 is a local privilege escalation vulnerability in G DATA Security Client where incorrect directory permissions allow unprivileged local u...

Jan 25, 2025
CVE-2024-55957
7.8

This CVE describes a local privilege escalation vulnerability in Thermo Fisher Scientific Xcalibur and Foundation Instrument Control Software on Windo...

Jan 22, 2025
CVE-2024-49732
7.8

This vulnerability in Android's CompanionDeviceManagerService allows local attackers to grant permissions without user consent due to missing permissi...

Jan 21, 2025
CVE-2024-49735
7.8

This Android vulnerability allows local privilege escalation without user interaction due to resource exhaustion preventing permission persistence. At...

Jan 21, 2025
CVE-2024-49737
7.8

This vulnerability allows local attackers to launch arbitrary activities with system-level privileges on Android devices due to a logic error in the W...

Jan 21, 2025
CVE-2024-49744
7.8

This vulnerability in Android's AccountManagerService allows local attackers to bypass parcel mismatch mitigations through unsafe deserialization, pot...

Jan 21, 2025
CVE-2024-34730
7.8

This vulnerability allows attackers to bypass user consent requirements when pairing new Bluetooth HID devices, enabling local privilege escalation wi...

Jan 21, 2025
CVE-2024-43765
7.8

CVE-2024-43765 is a tapjacking/overlay vulnerability in Android that allows attackers to trick users into granting folder access permissions through d...

Jan 21, 2025
CVE-2023-40132
7.8

This vulnerability allows malicious apps to bypass Android's content provider permission checks, potentially accessing sensitive ringtone data without...

Jan 21, 2025
CVE-2025-21532
7.8

This vulnerability in Oracle Analytics Desktop allows local attackers with low privileges to completely compromise the application, potentially gainin...

Jan 21, 2025
CVE-2018-9401
7.8

CVE-2018-9401 is a kernel memory access vulnerability in Android that allows user-space applications to read kernel memory due to incorrect bounds che...

Jan 18, 2025
CVE-2018-9434
7.8

CVE-2018-9434 is an Android Parcel component vulnerability that allows bypassing address space layout randomization (ASLR), enabling local privilege e...

Jan 17, 2025
CVE-2024-11624
7.8

This vulnerability allows malicious apps to bypass VPN restrictions on affected Android devices by exploiting an undeclared permission. It enables loc...

Jan 3, 2025
CVE-2024-53835
7.8

This vulnerability allows an attacker with physical access to bypass biometric authentication on affected Android devices, potentially gaining unautho...

Jan 3, 2025
CVE-2024-53840
7.8

CVE-2024-53840 is a biometric bypass vulnerability in Android that allows local attackers to escalate privileges without user interaction. This could ...

Jan 3, 2025
CVE-2024-53841
7.8

This CVE describes a permission bypass vulnerability in Android's device state change listening mechanism that allows local privilege escalation witho...

Jan 3, 2025
CVE-2024-43769
7.8

This vulnerability in Android's PackageManagerService allows local privilege escalation by preventing the uninstallation of CloudDpc (Device Policy Co...

Jan 3, 2025
CVE-2024-44224
7.8

This CVE describes a macOS permissions vulnerability that allows malicious applications to escalate privileges to root access. It affects macOS Ventur...

Dec 12, 2024
CVE-2024-9845
7.8

This vulnerability allows a local authenticated attacker to escalate privileges on systems running vulnerable versions of Ivanti Automation. Attackers...

Dec 11, 2024
CVE-2024-11597
7.8

This vulnerability allows a local authenticated attacker to escalate privileges on Ivanti Performance Manager systems due to insecure permissions. Att...

Dec 11, 2024
CVE-2018-9431
7.8

CVE-2018-9431 is a local privilege escalation vulnerability in Android's OSUInfo component due to improper input validation. It allows attackers to ga...

Dec 2, 2024
CVE-2018-9432
7.8

This vulnerability allows local attackers to bypass Bluetooth permission dialogs in Android, enabling unauthorized access to contacts without user con...

Nov 19, 2024
CVE-2017-13310
7.8

CVE-2017-13310 is a serialization vulnerability in Android's ViewPager component that allows malicious apps to bypass permission checks and start acti...

Nov 15, 2024
CVE-2017-13312
7.8

CVE-2017-13312 is an Android privilege escalation vulnerability in the MediaCas component where improper input validation allows malicious apps to exe...

Nov 15, 2024
CVE-2024-46465
7.8

CRYHOD for Windows up to version 2024.3 has insecure default folder permissions that allow other users on the same system to access technical files. T...

Nov 15, 2024
CVE-2024-46467
7.8

ZONEPOINT for Windows has insecure default folder permissions that allow other users to access technical files. This could enable privilege escalation...

Nov 15, 2024
CVE-2024-46462
7.8

This vulnerability allows unauthorized users to access dedicated ZEDMAIL folders on Windows systems, potentially enabling privilege escalation by misu...

Nov 15, 2024
CVE-2024-43085
7.8

This vulnerability allows an attacker with physical USB access to an Android device to bypass the lock screen and access device contents without authe...

Nov 13, 2024
CVE-2024-47016
7.8

CVE-2024-47016 is a local privilege escalation vulnerability in Android Pixel devices caused by an insecure default configuration. This allows attacke...

Oct 25, 2024
CVE-2024-49389
7.8

This vulnerability allows local attackers to escalate privileges on Windows systems by exploiting insecure folder permissions in Acronis Cyber Files. ...

Oct 17, 2024
CVE-2024-9858
7.8

Google Cloud Migrate to containers versions 1.1.0 to 1.2.2 on Windows create a local 'm2cuser' account with administrator privileges by default. If th...

Oct 16, 2024
CVE-2024-40654
7.8

This CVE describes a confused deputy vulnerability in Android Settings that allows local privilege escalation. An attacker could bypass permission che...

Sep 11, 2024
CVE-2024-43791
7.8

CVE-2024-43791 is a local privilege escalation vulnerability in request_store gem version 1.3.2 where world-writable file permissions (0666) allow loc...

Aug 23, 2024
CVE-2024-4763
7.8

This vulnerability in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) allows a local attacker to exploit an ins...

Aug 16, 2024
CVE-2024-42053
7.8

This vulnerability allows local users on Windows systems to escalate privileges to SYSTEM by exploiting weak permissions in a temporary folder used du...

Jul 28, 2024
CVE-2024-32861
7.8

The Cβ€’CURE 9000 installer uses overly permissive file permissions during installation, potentially allowing local attackers to modify critical files...

Jul 16, 2024
CVE-2024-38459
7.8

This vulnerability in langchain_experimental (LangChain Experimental) allows arbitrary Python code execution via REPL access without requiring explici...

Jun 16, 2024
CVE-2023-43629
7.8

This vulnerability allows authenticated users with local access to systems running vulnerable Intel GPA software to escalate privileges due to incorre...

May 16, 2024
CVE-2023-38295
7.8

This vulnerability allows third-party apps to perform arbitrary file read/write operations with system privileges on affected TCL Android devices. The...

Apr 22, 2024
CVE-2024-21116
7.8

This vulnerability in Oracle VM VirtualBox allows a low-privileged attacker with local access to a Linux host system to completely compromise the Virt...

Apr 16, 2024
CVE-2024-30977
7.8

This vulnerability in Secnet Security Network Intelligent AC Management System allows a local attacker to escalate privileges via the password compone...

Apr 5, 2024
CVE-2024-27674
7.8

CVE-2024-27674 is a privilege escalation vulnerability in Macro Expert software where unprivileged users can replace the MacroService.exe binary due t...

Apr 3, 2024
CVE-2023-42928
7.8

This CVE describes a privilege escalation vulnerability in iOS and iPadOS where an app could bypass security boundaries and gain elevated privileges. ...

Feb 21, 2024
CVE-2024-1156
7.8

This vulnerability involves incorrect directory permissions for the shared NI RabbitMQ service, allowing local authenticated users to read RabbitMQ co...

Feb 20, 2024
CVE-2023-41718
7.8

This vulnerability in Ivanti Secure Access Client allows attackers with control over a specific file to escalate privileges on affected systems. It af...

Nov 15, 2023
CVE-2023-41726
7.8

CVE-2023-41726 is a local privilege escalation vulnerability in Ivanti Avalanche caused by incorrect default permissions. An authenticated local attac...

Nov 3, 2023
CVE-2023-3112
7.8

A local privilege escalation vulnerability in Elliptic Labs Virtual Lock Sensor for Lenovo ThinkPad T14 Gen 3 allows attackers with physical or remote...

Oct 25, 2023
CVE-2023-31468
7.8

This vulnerability allows local attackers to escalate privileges to SYSTEM by exploiting weak folder permissions in Inosoft VisiWin 7 software. It aff...

Sep 11, 2023
CVE-2023-38410
7.8

This is a privilege escalation vulnerability in Apple operating systems that allows a local user to gain elevated privileges. It affects iOS, iPadOS, ...

Jul 27, 2023

About CWE-276 (CWE-276)

Our database tracks 430 CVEs classified as CWE-276, with 59 rated critical and 277 rated high severity. The average CVSS score for CWE-276 vulnerabilities is 7.6.

External reference: View CWE-276 on MITRE CWE →

Monitor CWE-276 Vulnerabilities

Get alerted when new CWE-276 CVEs affect your infrastructure.

Start Monitoring Free