CWE-276: CWE-276

433
Total CVEs
59
Critical
280
High
7.6
Avg CVSS

Yearly Trend

2026
30
2025
139
2024
124
2023
57
2022
30

Top Affected Vendors

1 Google 38
2 Apple 25
3 Huawei 15
4 Intel 13
5 Dell 10
6 Amd 6
7 Advantech 6
8 Oracle 5
9 Ivanti 5
10 Juniper 5

All CWE-276 CVEs (433)

CVE-2023-38410
7.8

This is a privilege escalation vulnerability in Apple operating systems that allows a local user to gain elevated privileges. It affects iOS, iPadOS, ...

Jul 27, 2023
CVE-2023-26077
7.8

The Atera Agent on Windows creates temporary files in directories with insecure permissions, allowing local attackers to write arbitrary files. This a...

Jul 24, 2023
CVE-2023-32183
7.8

This vulnerability allows users with hacluster group access on openSUSE Tumbleweed systems to escalate privileges to root due to incorrect default per...

Jul 7, 2023
CVE-2023-21187
7.8

This vulnerability allows an attacker to bypass the Android Setup Wizard through a logic error in USB accessory handling, potentially gaining elevated...

Jun 28, 2023
CVE-2023-20178
7.8

This vulnerability allows a low-privileged local attacker on Windows systems with Cisco AnyConnect or Secure Client to elevate privileges to SYSTEM le...

Jun 28, 2023
CVE-2023-32405
7.8

This CVE describes a privilege escalation vulnerability in macOS where a malicious application could exploit a logic flaw to gain root privileges. It ...

Jun 23, 2023
CVE-2023-32351
7.8

This CVE describes a privilege escalation vulnerability in iTunes for Windows where a malicious application could exploit a logic flaw to gain elevate...

Jun 23, 2023
CVE-2023-30905
7.8

This vulnerability affects HPE MC990 X and UV300 RMC components with inadequate default configurations, allowing attackers to escalate privileges on a...

Jun 16, 2023
CVE-2023-21129
7.8

This Android vulnerability allows malicious apps to launch activities while in the background, bypassing normal restrictions. It enables local privile...

Jun 15, 2023
CVE-2023-33240
7.8

This vulnerability allows unprivileged local users to escalate their privileges to SYSTEM level on Windows systems. It affects Foxit PDF Reader and Ed...

May 19, 2023
CVE-2022-38583
7.8

This vulnerability allows low-privileged Sage 300 workstation users to access and modify credentials stored in the SharedData folder on connected serv...

Apr 28, 2023
CVE-2021-41614
7.8

CVE-2021-41614 is a privilege escalation vulnerability in the OpenRISC mor1kx processor controller unit where user programs from unauthorized privileg...

Apr 18, 2023
CVE-2023-28966
7.8

This vulnerability allows a local attacker with shell access and low privileges to modify system files or execute commands as root due to improper fil...

Apr 17, 2023
CVE-2023-25941
7.8

Dell PowerScale OneFS versions 8.2.x through 9.5.0.x contain a local privilege escalation vulnerability. A low-privileged local attacker could exploit...

Apr 4, 2023
CVE-2022-31254
7.8

This vulnerability allows local attackers with access to the _rmt user account to escalate privileges to root due to incorrect default permissions in ...

Feb 7, 2023
CVE-2022-23454
7.8

CVE-2022-23454 is a set of vulnerabilities in HP Support Assistant that could allow attackers to escalate privileges, compromise system integrity, com...

Feb 1, 2023
CVE-2021-39794
7.8

This vulnerability allows malicious apps to execute code with shell user privileges when wireless debugging is enabled on Android devices, due to a mi...

Apr 12, 2022
CVE-2021-39780
7.8

CVE-2021-39780 allows attackers to bypass developer settings requirements for capturing system traces in Android 12L due to a missing permission check...

Mar 30, 2022
CVE-2021-1000
7.8

This vulnerability allows local attackers to bypass Bluetooth permission checks on Android devices, potentially gaining elevated privileges without us...

Mar 30, 2022
CVE-2022-21204
7.8

This vulnerability in Intel Quartus Prime Pro Edition allows authenticated local users to escalate privileges due to improper file permissions. Attack...

Feb 9, 2022
CVE-2021-33129
7.8

This vulnerability in Intel Advisor installer versions before 2021.4.0 sets incorrect default file permissions during installation, allowing authentic...

Feb 9, 2022
CVE-2021-22817
7.8

This vulnerability allows local attackers to escalate privileges by exploiting incorrect default permissions on the base installation directory. It af...

Feb 9, 2022
CVE-2021-21911
7.8

This vulnerability allows local attackers to escalate privileges to SYSTEM authority on Windows systems running Advantech R-SeeNet 2.4.15 by replacing...

Dec 22, 2021
CVE-2021-43326
7.8

This vulnerability in the Automox Agent on Windows allows local privilege escalation due to incorrect permissions on a temporary directory. An attacke...

Dec 15, 2021
CVE-2021-42711
7.8

CVE-2021-42711 is a local privilege escalation vulnerability in Barracuda Network Access Client where an unprivileged user can create a temporary file...

Dec 1, 2021
CVE-2021-33062
7.8

This vulnerability allows authenticated local users to escalate privileges due to incorrect default permissions in Intel VTune Profiler installer. It ...

Nov 17, 2021
CVE-2021-33071
7.8

This vulnerability allows authenticated local users to escalate privileges due to incorrect default permissions in the Intel oneAPI Rendering Toolkit ...

Nov 17, 2021
CVE-2020-8741
7.8

This vulnerability in Intel Thunderbolt non-DCH driver installer for Windows allows authenticated local users to escalate privileges due to improper p...

Nov 17, 2021
CVE-2021-33088
7.8

This vulnerability allows authenticated local users to escalate privileges on Intel NUC M15 Laptop Kit systems due to incorrect default permissions in...

Nov 17, 2021
CVE-2021-33090
7.8

This vulnerability allows authenticated local users to escalate privileges on affected Intel NUC systems due to incorrect default permissions in the H...

Nov 17, 2021
CVE-2021-33092
7.8

This vulnerability allows authenticated local users to escalate privileges on Intel NUC M15 Laptop Kit systems due to incorrect default permissions in...

Nov 17, 2021
CVE-2021-3579
7.8

This vulnerability allows a local attacker to escalate privileges to SYSTEM level on Windows systems by exploiting incorrect default permissions in Bi...

Oct 28, 2021
CVE-2021-36795
7.8

A permission issue in the Cohesity Linux agent allows local privilege escalation. An underprivileged Linux user can gain additional privileges if cert...

Aug 6, 2021
CVE-2021-32464
7.8

This vulnerability allows local privilege escalation in Trend Micro security products. An attacker with low-privileged code execution can modify scrip...

Aug 4, 2021
CVE-2021-0106
7.8

This vulnerability in Intel Optane DC Persistent Memory for Windows software allows authenticated local users to escalate privileges due to incorrect ...

Jun 9, 2021
CVE-2020-27384
7.8

This CVE describes a local privilege escalation vulnerability in the Guild Wars 2 game launcher where an authenticated user can replace the executable...

Jun 9, 2021
CVE-2021-27032
7.8

CVE-2021-27032 is a privilege escalation vulnerability in Autodesk Licensing Installer where weak service permissions allow any local user to modify s...

May 28, 2021
CVE-2021-25319
7.8

This vulnerability allows local attackers in the vboxusers group on openSUSE systems to escalate privileges to root due to incorrect default permissio...

May 5, 2021
CVE-2021-20532
7.8

This vulnerability in IBM Spectrum Protect Client allows a local user to escalate privileges to SYSTEM/root level due to insecure directory permission...

Apr 26, 2021
CVE-2020-13532
7.8

This CVE describes a local privilege escalation vulnerability in Dream Report 5 R20-2 where attackers can replace the Syncfusion Dashboard Service bin...

Apr 9, 2021
CVE-2020-13534
7.8

This CVE describes a privilege escalation vulnerability in Dream Report 5 R20-2 where weak permissions on COM Class Identifiers allow attackers to exe...

Apr 9, 2021
CVE-2020-13554
7.8

This vulnerability allows local attackers to escalate privileges to NT SYSTEM level by exploiting insecure file permissions in Advantech WebAccess/SCA...

Mar 3, 2021
CVE-2020-13549
7.8

This vulnerability allows local attackers to escalate privileges on systems running Sytech XL Reporter v14.0.1 by exploiting weak file system permissi...

Feb 19, 2021
CVE-2020-36233
7.8

This vulnerability allows local attackers to escalate privileges on systems running vulnerable versions of Atlassian Bitbucket Server and Data Center ...

Feb 18, 2021
CVE-2020-13539
7.8

This vulnerability allows local attackers to escalate privileges on systems running Win-911 Enterprise V4.20.13 by exploiting weak file system permiss...

Jan 5, 2021
CVE-2025-53947
7.7

A local privilege escalation vulnerability in Windows software allows low-privileged users to corrupt sensitive data. The vulnerability exists because...

Sep 18, 2025
CVE-2024-36495
7.7

Faronics WINSelect stores its encrypted configuration file with overly permissive 'Everyone' read/write permissions, allowing any local user to modify...

Jun 24, 2024
CVE-2024-27155
7.7

This CVE describes a local privilege escalation vulnerability in Toshiba printers that allows attackers to replace legitimate programs with malicious ...

Jun 14, 2024
CVE-2023-25645
7.7

This vulnerability in ZTE AndroidTV set-top boxes allows non-privileged applications to bypass permission controls and execute protected functions. At...

Jun 16, 2023
CVE-2024-49202
7.6

Keyfactor Command versions before 12.5.0 have an incorrect access control vulnerability where access tokens are over-permissioned, allowing users to p...

Dec 18, 2024

About CWE-276 (CWE-276)

Our database tracks 433 CVEs classified as CWE-276, with 59 rated critical and 280 rated high severity. The average CVSS score for CWE-276 vulnerabilities is 7.6.

External reference: View CWE-276 on MITRE CWE →

Monitor CWE-276 Vulnerabilities

Get alerted when new CWE-276 CVEs affect your infrastructure.

Start Monitoring Free