CWE-276: CWE-276

434
Total CVEs
59
Critical
281
High
7.6
Avg CVSS

Yearly Trend

2026
30
2025
139
2024
124
2023
57
2022
30

Top Affected Vendors

1 Google 38
2 Apple 25
3 Huawei 15
4 Intel 13
5 Dell 10
6 Amd 6
7 Advantech 6
8 Debian 5
9 Oracle 5
10 Ivanti 5

All CWE-276 CVEs (434)

CVE-2025-59030
7.5

This vulnerability in PowerDNS Recursor allows attackers to trigger removal of cached DNS records by sending NOTIFY queries over TCP. This enables DNS...

Dec 9, 2025
CVE-2025-13025
7.5

This vulnerability involves incorrect boundary conditions in Firefox and Thunderbird's WebGPU component, allowing memory corruption. Attackers could e...

Nov 11, 2025
CVE-2025-54530
7.5

This vulnerability in JetBrains TeamCity allows attackers to escalate privileges due to incorrect directory permissions. It affects all TeamCity insta...

Jul 28, 2025
CVE-2025-30706
7.5

This vulnerability in Oracle MySQL Connector/J allows attackers with low privileges and network access to potentially take over the connector software...

Apr 15, 2025
CVE-2024-45690
7.5

This vulnerability in Moodle allows users to delete OAuth2-linked accounts without proper authorization checks. It affects Moodle instances with OAuth...

Nov 20, 2024
CVE-2024-28058
7.5

This vulnerability in RSA NetWitness Platform allows an internal threat actor to impersonate a user whose access has been revoked but who still has an...

Nov 18, 2024
CVE-2024-36063
7.5

This vulnerability allows any Android application without permissions to place phone calls without user interaction by sending a crafted intent to the...

Nov 7, 2024
CVE-2024-44228
7.5

This CVE describes an improper permissions vulnerability in Xcode where applications could inherit Xcode's elevated permissions and access user data. ...

Oct 28, 2024
CVE-2024-44100
7.5

This vulnerability in the modem component of Google Pixel devices allows unauthorized access to sensitive information. It affects Pixel devices runnin...

Oct 25, 2024
CVE-2024-44760
7.5

This vulnerability allows attackers to bypass access controls in the Shenzhou News Union Enterprise Management System's SnoopServlet component, exposi...

Aug 28, 2024
CVE-2024-43114
7.5

This vulnerability in JetBrains TeamCity allows attackers to escalate privileges due to incorrect directory permissions. It affects all TeamCity insta...

Aug 6, 2024
CVE-2023-38370
7.5

IBM Security Access Manager Docker containers (versions 10.0.0.0 through 10.0.7.1) with certain configurations allow network users to install maliciou...

Jun 27, 2024
CVE-2024-37038
7.5

This vulnerability allows authenticated users with web interface access to perform unauthorized file and firmware uploads by crafting custom web reque...

Jun 12, 2024
CVE-2024-34455
7.5

This vulnerability in Buildroot allows attackers to manipulate the /dev/shm directory due to missing sticky bit permissions. It affects systems using ...

May 3, 2024
CVE-2023-23976
7.5

This vulnerability in the RegistrationMagic WordPress plugin allows attackers to bypass access controls and modify arbitrary prices in forms. It affec...

Apr 24, 2024
CVE-2023-52545
7.5

This vulnerability in Huawei's Calendar app involves undefined permissions that could allow attackers to disrupt the app's functionality, affecting av...

Apr 8, 2024
CVE-2024-22889
7.5

CVE-2024-22889 is an access control vulnerability in Plone v6.0.9 that allows remote attackers to view and list all files hosted on the website via cr...

Mar 6, 2024
CVE-2023-49338
7.5

Couchbase Server 7.1.x and 7.2.x before 7.2.4 exposes sensitive admin statistics and vitals endpoints without authentication on localhost port 8093. T...

Feb 28, 2024
CVE-2023-52362
7.5

A permission management vulnerability in the lock screen module of Huawei/HarmonyOS devices allows attackers to bypass lock screen protections. Succes...

Feb 18, 2024
CVE-2023-37572
7.5

Softing OPC Suite versions 5.25 and earlier have an incorrect access control vulnerability in the OSF_discovery service that allows attackers to obtai...

Dec 5, 2023
CVE-2023-42261
7.5

Mobile Security Framework (MobSF) versions up to v3.7.8 Beta have insecure default permissions that allow unauthorized access to the application. This...

Sep 21, 2023
CVE-2023-5042
7.5

This vulnerability allows local attackers to access sensitive information due to insecure folder permissions in Acronis Cyber Protect Home Office for ...

Sep 20, 2023
CVE-2023-29731
7.5

SoLive Android app versions 1.6.14 through 1.6.20 have an exposed component that allows attackers to inject excessive data into SharedPreference files...

May 30, 2023
CVE-2023-1809
7.5

The Download Manager WordPress plugin before version 6.3.0 exposes master key information without authentication, allowing attackers to bypass passwor...

May 2, 2023
CVE-2022-48360
7.5

This vulnerability in Huawei's facial recognition module involves improper file permission controls that could allow unauthorized access to sensitive ...

Mar 27, 2023
CVE-2022-29585
7.5

This vulnerability in Mahara's Isolated Institutions feature allows users to see groups from other institutions beyond the first page of group results...

Apr 28, 2022
CVE-2022-29547
7.5

The CreateRedirect extension for MediaWiki before April 14, 2022 fails to properly verify user permissions when creating redirects, allowing unauthori...

Apr 21, 2022
CVE-2022-27649
7.5

This vulnerability in Podman and Moby (Docker Engine) allows containers to start with non-empty inheritable Linux process capabilities. An attacker wi...

Apr 4, 2022
CVE-2021-40049
7.5

This CVE-2021-40049 is a permission control vulnerability in Huawei's PMS (Package Manager Service) module that allows unauthorized access to sensitiv...

Mar 10, 2022
CVE-2021-46086
7.5

xzs-mysql online examination system versions t3.4.0 and above have an insecure permissions vulnerability in the exam paper submission function. Attack...

Jan 25, 2022
CVE-2021-40004
7.5

This CVE describes a permission management vulnerability in cellular modules that could allow unauthorized access to sensitive data. It affects device...

Jan 10, 2022
CVE-2021-39967
7.5

This vulnerability allows unauthorized access to broadcast information on affected Huawei smartphones due to improper permission settings. Attackers c...

Jan 3, 2022
CVE-2021-44858
7.5

This vulnerability allows unauthorized users to view private pages on MediaWiki installations configured as private wikis with whitelist read restrict...

Dec 20, 2021
CVE-2021-37030
7.5

This CVE describes an improper permission vulnerability in Huawei smartphones that allows attackers to bypass intended access controls. Successful exp...

Nov 23, 2021
CVE-2021-22368
7.5

This CVE describes a permission control vulnerability in Huawei smartphones where improper access controls allow unauthorized actions. The vulnerabili...

Jun 30, 2021
CVE-2021-22371
7.5

This CVE describes an improper permission management vulnerability in Huawei smartphones that allows unauthorized access to sensitive services. Succes...

Jun 30, 2021
CVE-2021-33506
7.5

CVE-2021-33506 is a configuration vulnerability in Jitsi Meet where the 'restrict_room_creation' setting is not enforced by default, allowing attacker...

May 26, 2021
CVE-2021-33038
7.5

This vulnerability in HyperKitty exposes private mailing list archives to public access during import operations. When migrating from Mailman 2 to Mai...

May 26, 2021
CVE-2024-27151
7.4

This CVE describes a local privilege escalation vulnerability in Toshiba printers that allows attackers to replace legitimate programs with malicious ...

Jun 14, 2024
CVE-2024-27153
7.4

CVE-2024-27153 is a local privilege escalation vulnerability in Toshiba printers that allows attackers to gain elevated privileges on affected devices...

Jun 14, 2024
CVE-2024-27149
7.4

This CVE describes a local privilege escalation vulnerability in Toshiba printers that allows attackers to gain elevated privileges on affected device...

Jun 14, 2024
CVE-2023-33291
7.4

This vulnerability in ebankIT 6 allows unauthenticated attackers to generate OTP (One-Time Password) messages to arbitrary email addresses or phone nu...

May 28, 2023
CVE-2025-64724
7.3

Arduino IDE for macOS versions before 2.3.7 installs with world-writable file permissions on sensitive application components. This allows any local u...

Dec 18, 2025
CVE-2025-8485
7.3

A local privilege escalation vulnerability in Lenovo App Store allows authenticated local users to execute arbitrary code with elevated privileges dur...

Nov 12, 2025
CVE-2025-46355
7.3

CVE-2025-46355 is an incorrect default permissions vulnerability in PC Time Tracer that allows local authenticated attackers to execute arbitrary code...

Jun 3, 2025
CVE-2024-13948
7.3

This vulnerability involves insecure Windows permissions for ASPECT configuration toolsets, allowing unauthorized access to configuration information....

May 22, 2025
CVE-2023-31359
7.3

This vulnerability involves incorrect default permissions in AMD Manageability API that could allow a local attacker to escalate privileges on affecte...

May 13, 2025
CVE-2025-30701
7.3

This vulnerability in Oracle Database's RAS Security component allows authenticated attackers with network access to compromise data confidentiality a...

Apr 15, 2025
CVE-2023-31360
7.3

This vulnerability allows local attackers to escalate privileges on systems with AMD Integrated Management Technology (AIM-T) Manageability Service in...

Feb 11, 2025
CVE-2018-9369
7.3

CVE-2018-9369 is a bootloader vulnerability in Android devices that allows attackers to specify kernel command line arguments via fastboot. This enabl...

Nov 19, 2024

About CWE-276 (CWE-276)

Our database tracks 434 CVEs classified as CWE-276, with 59 rated critical and 281 rated high severity. The average CVSS score for CWE-276 vulnerabilities is 7.6.

External reference: View CWE-276 on MITRE CWE →

Monitor CWE-276 Vulnerabilities

Get alerted when new CWE-276 CVEs affect your infrastructure.

Start Monitoring Free