CWE-277: CWE-277

23
Total CVEs
1
Critical
9
High
7.0
Avg CVSS

Yearly Trend

2026
2
2025
9
2024
11
2023
1

Top Affected Vendors

1 Apple 5
2 Intel 3
3 Ibm 2
4 Sap 1
5 Arubanetworks 1
6 Extplorer 1
7 Anaconda 1
8 Authzed 1
9 Django Helpdesk Project 1
10 Pulpproject 1

All CWE-277 CVEs (23)

CVE-2024-36539
9.8

This vulnerability in Contour v1.28.3 allows attackers to access Kubernetes service account tokens due to insecure permissions. Attackers can use thes...

Jul 24, 2024
CVE-2023-27842
8.8

This vulnerability allows remote attackers to execute arbitrary code on systems running eXtplorer File Manager version 2.1.15 due to insecure permissi...

Mar 21, 2023
CVE-2024-34329
8.4

This vulnerability allows unauthenticated attackers to execute arbitrary code with SYSTEM privileges on systems running vulnerable versions of the Ent...

Jul 22, 2024
CVE-2024-7143
8.3

This vulnerability in Pulp's role-based access control system incorrectly assigns object permissions when objects are created within tasks. Instead of...

Aug 7, 2024
CVE-2024-27822
7.8

This CVE describes a privilege escalation vulnerability in macOS where a malicious application could exploit a logic issue to gain root privileges. It...

May 14, 2024
CVE-2024-23233
7.8

This vulnerability in macOS allows malicious applications to abuse entitlements and privacy permissions granted to legitimate apps. Attackers could po...

Mar 8, 2024
CVE-2024-41601
7.5

This CVE describes an insecure permissions vulnerability in lin-CMS v0.2.0 and earlier that allows remote attackers to access sensitive information th...

Jul 19, 2024
CVE-2025-37174
7.2

This vulnerability allows authenticated attackers to write arbitrary files on mobility conductors running AOS-10 or AOS-8, potentially leading to remo...

Jan 13, 2026
CVE-2024-27825
7.1

This vulnerability allows malicious applications to bypass macOS Privacy preferences on Intel-based Mac computers by exploiting a downgrade issue in c...

May 14, 2024
CVE-2025-32797
7.0

CVE-2025-32797 is a local privilege escalation vulnerability in conda-build where the temporary build script conda_build.sh is created with overly per...

Jun 16, 2025
CVE-2025-24327
6.7

This vulnerability in Intel Rapid Storage Technology Application allows local authenticated attackers to escalate privileges through insecure inherite...

Nov 11, 2025
CVE-2025-3473
6.7

IBM Security Guardium 12.1 contains a local privilege escalation vulnerability where a user with existing local privileges can exploit insecure inheri...

Jun 11, 2025
CVE-2024-36294
6.7

This vulnerability in Intel DSA software allows authenticated local users to escalate privileges due to insecure inherited permissions. It affects sys...

Nov 13, 2024
CVE-2024-36276
6.7

This vulnerability in Intel CIP software allows authenticated local users to escalate privileges due to insecure inherited permissions. It affects sys...

Nov 13, 2024
CVE-2023-45736
6.7

Intel Power Gadget for Windows has insecure inherited permissions that allow authenticated local users to escalate privileges. This affects all versio...

May 16, 2024
CVE-2025-31332
6.6

This vulnerability allows attackers with local system access to modify files in SAP BusinessObjects Business Intelligence Platform due to insecure fil...

Apr 8, 2025
CVE-2025-36104
6.5

This vulnerability in IBM Storage Scale allows authenticated users to access sensitive files through insecure SMB protocol permissions. It affects IBM...

Jul 12, 2025
CVE-2025-22448
6.1

Insecure inherited permissions in Intel Simics Package Manager before version 1.12.0 allow authenticated local users to potentially cause denial of se...

May 13, 2025
CVE-2026-20630
5.5

A permissions vulnerability in macOS allows applications to bypass intended restrictions and access protected user data. This affects macOS systems ru...

Feb 11, 2026
CVE-2024-27847
5.5

This vulnerability allows an app to bypass privacy preferences on Apple devices, potentially accessing sensitive user data without proper consent. It ...

May 14, 2024
CVE-2025-65111
5.3

This vulnerability in SpiceDB causes missing LookupResources results when checking permissions defined with specific union relationships in schemas. I...

Nov 21, 2025
CVE-2018-25111
5.1

This vulnerability in django-helpdesk allows sensitive data exposure due to improper file permission settings. The os.umask(0) call in models.py creat...

May 31, 2025
CVE-2025-64185
N/A

Open OnDemand creates world-writable directories in the GEM_PATH environment variable, allowing any user on the system to modify Ruby gem files. This ...

Nov 20, 2025

About CWE-277 (CWE-277)

Our database tracks 23 CVEs classified as CWE-277, with 1 rated critical and 9 rated high severity. The average CVSS score for CWE-277 vulnerabilities is 7.0.

External reference: View CWE-277 on MITRE CWE →

Monitor CWE-277 Vulnerabilities

Get alerted when new CWE-277 CVEs affect your infrastructure.

Start Monitoring Free