CWE-276: CWE-276

436
Total CVEs
59
Critical
283
High
7.6
Avg CVSS

Yearly Trend

2026
30
2025
139
2024
124
2023
57
2022
30

Top Affected Vendors

1 Google 38
2 Apple 25
3 Huawei 15
4 Intel 13
5 Dell 10
6 Advantech 6
7 Amd 6
8 Debian 5
9 Oracle 5
10 Ivanti 5

All CWE-276 CVEs (436)

CVE-2023-31360
7.3

This vulnerability allows local attackers to escalate privileges on systems with AMD Integrated Management Technology (AIM-T) Manageability Service in...

Feb 11, 2025
CVE-2018-9369
7.3

CVE-2018-9369 is a bootloader vulnerability in Android devices that allows attackers to specify kernel command line arguments via fastboot. This enabl...

Nov 19, 2024
CVE-2024-21957
7.3

This vulnerability allows local attackers to escalate privileges by exploiting incorrect default permissions in the AMD Management Console installatio...

Nov 12, 2024
CVE-2024-21939
7.3

This vulnerability allows local attackers to escalate privileges by exploiting incorrect default permissions in the AMD Cloud Manageability Service (A...

Nov 12, 2024
CVE-2024-21946
7.3

This vulnerability allows local attackers to escalate privileges by exploiting incorrect default permissions in the AMD Ryzen Master Utility installat...

Nov 12, 2024
CVE-2024-21937
7.3

This vulnerability involves incorrect default permissions in the AMD HIP SDK installation directory, allowing local attackers to modify files and pote...

Nov 12, 2024
CVE-2023-31349
7.3

Incorrect default permissions in AMD ΞΌProf installation directory allow local attackers to modify files, potentially leading to privilege escalation ...

Aug 13, 2024
CVE-2023-46870
7.3

This vulnerability allows attackers to execute arbitrary code on systems running vulnerable versions of Nordic Semiconductor's nRF Sniffer for Bluetoo...

May 14, 2024
CVE-2024-32368
7.3

This vulnerability allows a local attacker to cause denial of service on the Agasta Sanketlife 2.0 ECG monitor by exploiting insecure permissions in t...

Apr 22, 2024
CVE-2024-0259
7.3

This vulnerability allows low-privileged Windows users to overwrite the Robot Schedule Enterprise Agent service executable. When the service restarts,...

Mar 28, 2024
CVE-2023-38960
7.3

This vulnerability allows a local attacker to escalate privileges and execute arbitrary code on systems running RaidenFTPD v2.4 build 4005 due to inse...

Feb 13, 2024
CVE-2023-3116
7.3

This vulnerability in OpenHarmony allows a local attacker to access confidential information or modify sensitive files due to incorrect default permis...

Nov 20, 2023
CVE-2023-46743
7.3

This vulnerability in XWiki's Collabora Online integration allows users with view-only permissions to gain edit access to documents when they open att...

Nov 9, 2023
CVE-2023-29057
7.3

This vulnerability allows authenticated users to bypass intended Active Directory permission restrictions when specific LDAP configuration is used. It...

Apr 28, 2023
CVE-2022-36397
7.3

This vulnerability allows authenticated users on Linux systems with affected Intel QAT drivers to escalate privileges via local access due to incorrec...

Feb 16, 2023
CVE-2021-21957
7.3

CVE-2021-21957 is a privilege escalation vulnerability in Dream Report ODS Remote Connector that allows attackers to execute arbitrary commands with e...

Dec 8, 2021
CVE-2021-0441
7.3

This vulnerability allows local privilege escalation on Android 11 devices through a confusing UI element in permission dialogs. Attackers can trick u...

Jul 14, 2021
CVE-2021-28649
7.3

This vulnerability in Trend Micro HouseCall for Home Networks installer allows local privilege escalation. An attacker with low-privileged access can ...

May 12, 2021
CVE-2021-0246
7.3

This CVE allows tenant system administrators on affected Juniper SRX devices to inadvertently send their network traffic to other tenants while modify...

Apr 22, 2021
CVE-2021-0235
7.3

This CVE-2021-0235 is a privilege escalation vulnerability in Juniper Junos OS on SRX and vSRX devices with tenant services. It allows tenant administ...

Apr 22, 2021
CVE-2024-21820
7.2

This vulnerability involves incorrect default permissions in Intel Xeon processor memory controller configurations when using Intel SGX (Software Guar...

Nov 13, 2024
CVE-2021-21736
7.2

This vulnerability in ZTE smart cameras allows users whose sharing permissions have been revoked to still control the camera remotely through the clou...

Jun 10, 2021
CVE-2021-22311
7.2

This CVE describes an improper privilege assignment vulnerability in Huawei ManageOne management software where processes can run with higher privileg...

Mar 22, 2021
CVE-2025-67230
7.1

This vulnerability in ToDesktop Builder v0.33.0 allows attackers with renderer-context access to bypass validation and invoke external protocol handle...

Jan 23, 2026
CVE-2025-10918
7.1

This vulnerability allows local authenticated attackers to write arbitrary files anywhere on disk due to insecure default permissions in Ivanti Endpoi...

Nov 11, 2025
CVE-2025-45467
7.1

This vulnerability allows attackers to upload malicious firmware to Unitree Go1 robots by exploiting insecure MD5 checksum verification. Attackers can...

Jul 25, 2025
CVE-2025-24176
7.1

This CVE describes a local privilege escalation vulnerability in macOS where improper permission validation allows a local attacker to gain elevated p...

Jan 27, 2025
CVE-2024-9191
7.1

This vulnerability allows attackers with access to a compromised Windows device to retrieve passwords associated with Desktop MFA passwordless logins ...

Nov 1, 2024
CVE-2023-45896
7.1

CVE-2023-45896 is an out-of-bounds read vulnerability in the Linux kernel's ntfs3 filesystem driver. It allows a physically proximate attacker with lo...

Aug 28, 2024
CVE-2024-40805
7.1

This CVE describes a permissions issue in Apple operating systems that allows applications to bypass Privacy preferences. It affects users of watchOS,...

Jul 29, 2024
CVE-2023-38291
7.1

This vulnerability allows any local app on affected Android devices to access the Wi-Fi MAC address without permissions, bypassing Android 10+ restric...

Apr 22, 2024
CVE-2023-27647
7.1

This vulnerability in DUALSPACE Lock Master v2.2.4 allows local attackers to cause denial of service or access sensitive information through improper ...

Apr 14, 2023
CVE-2021-41637
7.1

MELAG FTP Server 2.2.0.4 has weak file permissions that allow any user (including unauthenticated 'Everyone' group) to read the FTP configuration file...

Jun 24, 2022
CVE-2021-45083
7.1

CVE-2021-45083 is a privilege escalation vulnerability in Cobbler where sensitive files containing password hashes and configuration secrets are world...

Feb 20, 2022
CVE-2021-1056
7.1

This vulnerability in NVIDIA GPU Display Driver for Linux allows attackers to bypass file system permissions on GPU devices, potentially leading to de...

Jan 8, 2021
CVE-2025-43887
7.0

Dell PowerProtect Data Manager versions 19.19 and 19.20 on Hyper-V have incorrect default permissions that allow local low-privileged attackers to ele...

Sep 10, 2025
CVE-2024-49724
7.0

This vulnerability allows attackers to bypass Android permission checks through a race condition in AccountManagerService, enabling unauthorized acces...

Jan 21, 2025
CVE-2024-27134
7.0

This vulnerability allows local attackers to escalate privileges on systems running MLflow when the spark_udf() API is called. Attackers can exploit i...

Nov 25, 2024
CVE-2022-33877
7.0

This vulnerability allows a local authenticated attacker to modify files in the FortiClient or FortiConverter installation folder when installed in an...

Jun 13, 2023
CVE-2023-28079
7.0

CVE-2023-28079 is an insecure file and folder permissions vulnerability in Dell PowerPath for Windows that allows non-admin users to escalate privileg...

May 30, 2023
CVE-2022-4568
7.0

A directory permissions vulnerability in Lenovo System Update allows local authenticated users to write arbitrary files to protected directories, pote...

May 1, 2023
CVE-2023-25542
7.0

Dell Trusted Device Agent versions before 5.3.0 have improper installation permissions that allow an unauthenticated local attacker to escalate privil...

Apr 6, 2023
CVE-2026-21423
6.7

Dell PowerScale OneFS has an incorrect default permissions vulnerability that allows high-privileged local attackers to execute arbitrary code, cause ...

Mar 4, 2026
CVE-2026-0705
6.7

This vulnerability allows local attackers to escalate privileges on Windows systems running vulnerable versions of Acronis Cloud Manager. Attackers ca...

Jan 27, 2026
CVE-2025-31940
6.7

This vulnerability in Intel Thread Director Visualizer software allows local authenticated attackers to escalate privileges through incorrect default ...

Nov 11, 2025
CVE-2025-30518
6.7

This vulnerability in Intel PresentMon before version 2.3.1 involves incorrect default permissions that could allow local authenticated attackers to e...

Nov 11, 2025
CVE-2025-27246
6.7

The Intel Processor Identification Utility before version 8.0.43 has incorrect default permissions that could allow a local authenticated attacker to ...

Nov 11, 2025
CVE-2025-27711
6.7

This vulnerability in Intel One Boot Flash Update software allows local authenticated users to escalate privileges through incorrect default permissio...

Nov 11, 2025
CVE-2025-27559
6.7

This vulnerability in AI Playground software allows authenticated users with local access to escalate privileges due to incorrect default permissions....

Aug 12, 2025
CVE-2025-26470
6.7

This vulnerability in Intel Distribution for Python installers allows authenticated local users to escalate privileges due to incorrect default permis...

Aug 12, 2025

About CWE-276 (CWE-276)

Our database tracks 436 CVEs classified as CWE-276, with 59 rated critical and 283 rated high severity. The average CVSS score for CWE-276 vulnerabilities is 7.6.

External reference: View CWE-276 on MITRE CWE →

Monitor CWE-276 Vulnerabilities

Get alerted when new CWE-276 CVEs affect your infrastructure.

Start Monitoring Free