CWE-276: CWE-276

436
Total CVEs
59
Critical
283
High
7.6
Avg CVSS

Yearly Trend

2026
30
2025
139
2024
124
2023
57
2022
30

Top Affected Vendors

1 Google 38
2 Apple 25
3 Huawei 15
4 Intel 13
5 Dell 10
6 Amd 6
7 Advantech 6
8 Debian 5
9 Oracle 5
10 Ivanti 5

All CWE-276 CVEs (436)

CVE-2024-6122
5.5

This vulnerability allows local users to access sensitive information stored in the NI SystemLink Server KeyValueDatabase service due to incorrect dir...

Jul 22, 2024
CVE-2024-31312
5.5

This CVE describes an Android vulnerability where missing permission checks allow local information disclosure of played media. Any Android device run...

Jul 9, 2024
CVE-2024-22430
5.5

Dell PowerScale OneFS versions 8.2.x through 9.6.0.x have incorrect default permissions that allow local low-privileged users to cause denial of servi...

Feb 1, 2024
CVE-2025-55132
5.3

A vulnerability in Node.js's permission model allows attackers to modify file timestamps using the futimes() function even when they only have read pe...

Jan 20, 2026
CVE-2025-67813
5.3

Quest KACE Desktop Authority versions through 11.3.1 have insecure permissions on named pipes used for inter-process communication, allowing unauthori...

Jan 12, 2026
CVE-2025-54990
5.3

This vulnerability allows non-admin users to access the AdminTools.SpammedPages page in XWiki AdminTools, though no sensitive data is visible. It affe...

Nov 18, 2025
CVE-2025-35062
5.3

Newforma Info Exchange (NIX) before version 2023.1 has a default configuration that allows anonymous authentication. This enables unauthenticated atta...

Oct 9, 2025
CVE-2025-24140
5.3

This macOS vulnerability allows downloaded files to bypass the quarantine flag, which normally triggers security warnings before execution. This affec...

Jan 27, 2025
CVE-2024-48533
5.3

This vulnerability allows attackers to determine which email addresses have valid user accounts in eSoft Planner by observing different responses from...

Nov 20, 2024
CVE-2024-48572
5.3

An unauthenticated user enumeration vulnerability in AquilaCMS allows attackers to discover valid email addresses through the 'Add a user' feature. Th...

Oct 29, 2024
CVE-2020-29582
5.3

This vulnerability in JetBrains Kotlin before version 1.4.21 uses an insecure Java API for temporary file creation, allowing attackers to read sensiti...

Feb 3, 2021
CVE-2025-22425
5.1

This Android vulnerability allows local privilege escalation through improper input validation in the InstallStart.java onCreate method. An attacker c...

Sep 4, 2025
CVE-2024-52783
5.1

This vulnerability allows attackers to modify the configuration file of XINJE XDPPro software due to insecure file permissions, potentially leading to...

Jan 15, 2025
CVE-2024-34616
5.1

This vulnerability in Samsung Knox DualDAR policy allows local attackers to bypass permission checks and access sensitive data stored on affected devi...

Aug 7, 2024
CVE-2026-28717
5.0

This vulnerability allows local attackers to escalate privileges on Windows systems running Acronis Cyber Protect 17 due to improper directory permiss...

Mar 6, 2026
CVE-2025-24788
5.0

The Snowflake Connector for .NET versions 2.0.12 through 4.2.0 on Linux and macOS temporarily store downloaded stage files in world-readable directori...

Jan 29, 2025
CVE-2024-39544
5.0

A local privilege escalation vulnerability in Juniper Junos OS Evolved allows low-privileged local users to read NETCONF traceoptions files containing...

Oct 11, 2024
CVE-2025-64723
4.4

Arduino IDE for macOS versions before 2.3.7 had overly permissive security entitlements that bypass macOS Hardened Runtime protections. This allows at...

Dec 18, 2025
CVE-2025-54059
4.4

Melange versions 0.23.0 through 0.29.4 generate APK SBOM files with overly permissive 666 file permissions, allowing unprivileged users to modify thes...

Jul 18, 2025
CVE-2025-24790
4.4

The Snowflake JDBC Driver vulnerability allows local users on Linux systems to read cached temporary credentials from a world-readable file when tempo...

Jan 29, 2025
CVE-2024-46695
4.4

A Linux kernel vulnerability allows root users on NFS clients to bypass security label restrictions on NFS filesystems exported with root squashing en...

Sep 13, 2024
CVE-2025-15333
4.3

CVE-2025-15333 is an information disclosure vulnerability in Tanium Threat Response that allows unauthorized access to sensitive data. Organizations u...

Feb 5, 2026
CVE-2025-15334
4.3

An information disclosure vulnerability in Tanium Threat Response could allow authenticated attackers to access sensitive data they shouldn't have per...

Feb 5, 2026
CVE-2025-15335
4.3

An information disclosure vulnerability in Tanium Threat Response could allow authenticated attackers to access sensitive data they shouldn't have per...

Feb 5, 2026
CVE-2025-27926
4.3

This vulnerability exposes passwords stored in configuration files within the K2 SmartForms Designer folder, making them readable by unauthorized user...

Mar 10, 2025
CVE-2024-47593
4.3

CVE-2024-47593 is an information disclosure vulnerability in SAP NetWeaver Application Server ABAP that allows unauthenticated attackers with network ...

Nov 12, 2024
CVE-2024-34661
4.3

Samsung Assistant versions before 9.1.00.7 have a permission handling flaw that allows remote attackers to access location data when user interaction ...

Sep 4, 2024
CVE-2024-47825
4.0

Cilium versions 1.14.0 through 1.14.15 and 1.15.0 through 1.15.9 have a policy bypass vulnerability where certain CIDR-based deny rules may be ignored...

Oct 21, 2024
CVE-2025-59485
3.3

This vulnerability allows local authenticated users on Windows systems running MaLion Security Point versions before 5.3.4 to place arbitrary files in...

Nov 25, 2025
CVE-2025-12792
3.2

The Canva for Mac desktop app distributed through the Mac App Store was built without Apple's Hardened Runtime security feature. This allows a local a...

Nov 18, 2025
CVE-2025-43350
2.4

This CVE describes a lock screen bypass vulnerability in Apple iOS/iPadOS where an attacker with physical access to a locked device could view restric...

Nov 4, 2025
CVE-2026-24414
N/A

This vulnerability exposes the private key of Icinga certificates due to overly permissive directory permissions. Any user on affected Windows systems...

Jan 29, 2026
CVE-2025-13905
N/A

A local privilege escalation vulnerability exists where normal users can modify executable service binaries in the installation folder. When the servi...

Jan 29, 2026
CVE-2025-15523
N/A

The macOS version of Inkscape bundles a Python interpreter that inherits the application's TCC permissions. Attackers with local access can execute ar...

Jan 22, 2026
CVE-2025-61667
N/A

A local privilege escalation vulnerability in Datadog Linux Host Agent versions 7.65.0 through 7.70.2 allows attackers with local access and low-privi...

Nov 12, 2025
CVE-2025-11567
N/A

This CVE describes an Incorrect Default Permissions vulnerability in Schneider Electric software where installation folders have insecure default perm...

Nov 12, 2025

About CWE-276 (CWE-276)

Our database tracks 436 CVEs classified as CWE-276, with 59 rated critical and 283 rated high severity. The average CVSS score for CWE-276 vulnerabilities is 7.6.

External reference: View CWE-276 on MITRE CWE →

Monitor CWE-276 Vulnerabilities

Get alerted when new CWE-276 CVEs affect your infrastructure.

Start Monitoring Free