CWE-732: CWE-732
Yearly Trend
Top Affected Vendors
All CWE-732 CVEs (313)
This vulnerability allows local attackers to perform unauthorized raw disk operations due to an incorrect NULL DACL in SevenCs ORCA G2's regService pr...
Dec 31, 2025This vulnerability allows local attackers with initial low-privileged access to escalate privileges to SYSTEM level by exploiting incorrect folder per...
Dec 23, 2025BuhoNTFS version 1.3.2 contains an insecure XPC service that allows local, unprivileged users to execute arbitrary code with root privileges. This aff...
Dec 12, 2025This CVE describes a local privilege escalation vulnerability in Nagios Log Server where the 'www-data' user can replace root-owned scripts in a writa...
Nov 17, 2025This vulnerability in Siemens Spectrum Power 4 allows attackers to read database credentials from a world-readable file. With these credentials, attac...
Nov 11, 2025This vulnerability allows attackers with web server privileges (www-data user) to modify a Nagios XI script, leading to arbitrary code execution as th...
Oct 30, 2025MacForge 1.2.0 Beta 1 contains an insecure XPC service that allows local, unprivileged users to escalate privileges to root. This vulnerability enable...
Oct 4, 2025This vulnerability allows local users to escalate privileges to SYSTEM level by placing malicious files in an insecure directory. Any local user on sy...
Sep 25, 2025A permissions vulnerability in macOS allows malicious applications to escalate privileges to root access. This affects macOS systems running versions ...
Aug 29, 2025This CVE describes a local privilege escalation vulnerability in Acronis Cyber Protect Cloud Agent for Windows due to insecure folder permissions. Att...
Aug 28, 2025GPMAW 14 has insecure file permissions in its installation directory, allowing any user with local access to replace the uninstaller executable. When ...
Aug 7, 2025This vulnerability allows a local attacker to exploit incorrect file permissions in Apache APISIX's Java plugin runner to elevate privileges. It affec...
Jul 6, 2025This CVE-2025-2759 vulnerability in GStreamer's installer allows local attackers to escalate privileges by exploiting incorrect folder permissions. At...
May 22, 2025A local privilege escalation vulnerability in Siemens SCALANCE LPE9403 industrial routers allows non-privileged local attackers to interact with the b...
May 13, 2025An incorrect permission assignment vulnerability in PostgreSQL commands in Zyxel USG FLEX H series firewalls allows authenticated local attackers with...
Apr 22, 2025A local privilege escalation vulnerability in Taegis Endpoint Agent on Debian-based Linux systems allows local users to execute arbitrary code with ro...
Apr 11, 2025Dell ThinOS 2408 and earlier versions have an improper permissions vulnerability that allows local low-privileged attackers to elevate their privilege...
Mar 18, 2025This CVE describes a local privilege escalation vulnerability in Ivanti Secure Access Client where insufficient permissions allow authenticated local ...
Mar 11, 2025This vulnerability allows an authenticated attacker to execute arbitrary code with kernel privileges on Windows systems. It affects Windows 10, 11, an...
Jan 17, 2025This vulnerability in Foxit PDF Reader's Update Service allows local attackers to escalate privileges from a low-privileged user to SYSTEM by exploiti...
Nov 22, 2024This vulnerability in Panda Security Dome VPN allows local attackers to escalate privileges from a low-privileged user account to SYSTEM level by expl...
Nov 22, 2024A local privilege escalation vulnerability exists in SIPORT software where improper file permissions allow unprivileged local users to modify service ...
Nov 12, 2024This CVE describes a local privilege escalation vulnerability in Tomcat packaging where insecure file permissions during installation allow local user...
Oct 16, 2024This vulnerability allows non-admin users to exploit weak file and folder permissions in Vivavis HIGH-LEIT software to escalate privileges and execute...
Sep 3, 2024This vulnerability allows local attackers with low-privileged access to escalate privileges to SYSTEM level by exploiting incorrect file permissions i...
Aug 21, 2024This CVE describes a local privilege escalation vulnerability in Nagios NDOUtils where certain executable files are owned by the nagios user instead o...
Aug 7, 2024This vulnerability allows a local attacker to escalate privileges by exploiting incorrect permissions in the ThermoscanIP installation folder. Attacke...
Jul 31, 2024This CVE describes a local privilege escalation vulnerability in Arc software on Unix systems where temporary files are created with unsafe permission...
May 15, 2024This vulnerability in the Phoenix WinFlash Driver allows attackers with local access to escalate privileges by exploiting an exposed IOCTL interface w...
May 14, 2024This vulnerability in IBM Security Guardium allows a local user to gain elevated privileges on the system due to improper permissions control. It affe...
May 14, 2024This vulnerability allows attackers to bypass Hypervisor-Protected Code Integrity (HVCI) security features on Windows systems, potentially enabling th...
Mar 12, 2024This vulnerability allows authorized users in Rapid SCADA to write directly to the Scada directory, potentially enabling privilege escalation. It affe...
Feb 2, 2024CVE-2023-28134 is a local privilege escalation vulnerability in Check Point Harmony Endpoint and ZoneAlarm Extreme Security. An attacker with low-priv...
Nov 12, 2023CVE-2023-40361 is an insecure permissions vulnerability in SECUDOS Qiata (DOMOS OS) where the previewRm.sh cronjob has world-writable permissions. Thi...
Oct 20, 2023CVE-2022-30527 is an improper access control vulnerability in Siemens SINEC NMS where specific folders containing executables and libraries have overl...
Oct 10, 2023This vulnerability allows local attackers with low-privileged access to escalate to SYSTEM privileges by exploiting incorrect file permissions on Waco...
Sep 6, 2023CVE-2023-28133 allows local attackers to escalate privileges on Windows systems running Check Point Endpoint Security Client E87.30 by crafting a mali...
Jul 23, 2023This vulnerability in SIMATIC WinCC allows authenticated local attackers to inject arbitrary code and escalate privileges when the software is install...
Jun 13, 2023CVE-2023-31871 is a privilege escalation vulnerability in OpenText Documentum Content Server where a non-privileged user can exploit the dm_secure_wri...
May 18, 2023This vulnerability in Delta Electronics InfraSuite Device Master allows attackers to set incorrect directory permissions, potentially leading to local...
Mar 27, 2023This vulnerability allows local attackers to escalate privileges by modifying the webroot directory due to incorrect permissions. It affects APC and S...
Feb 1, 2023CVE-2022-34891 is a local privilege escalation vulnerability in Parallels Desktop where incorrect file permissions allow attackers to escalate to root...
Jul 18, 2022This vulnerability allows unprivileged users to escalate privileges to SYSTEM via DLL search-order hijacking in Sage 300 ERP. The installer places a w...
Jul 14, 2022This vulnerability in Android's PermissionController allows malicious apps to obtain and retain permissions without user consent due to a logic error....
Jul 13, 2022This vulnerability in Adaware Protect v1.2.439.4251 allows local attackers to escalate privileges by modifying the service binary path due to insecure...
Jun 16, 2022This vulnerability allows a local attacker with existing low-privileged access to escalate privileges by loading a malicious DLL with incorrect permis...
May 27, 2022This vulnerability allows a malicious actor with local access to VMware Workspace ONE Access, Identity Manager, or vRealize Automation systems to esca...
Apr 13, 2022This vulnerability allows local unprivileged attackers to achieve privilege escalation in Siemens SIMATIC Energy Manager software. By exploiting impro...
Apr 12, 2022The SysDrv3S driver in CODESYS Control runtime system on Windows allows any system user to read and write restricted memory space. This vulnerability ...
Apr 7, 2022Synaman v5.1 and below contains weak file permissions that allow authenticated attackers to escalate privileges. This vulnerability affects organizati...
Apr 6, 2022About CWE-732 (CWE-732)
Our database tracks 313 CVEs classified as CWE-732, with 41 rated critical and 209 rated high severity. The average CVSS score for CWE-732 vulnerabilities is 7.7.
External reference: View CWE-732 on MITRE CWE →
Monitor CWE-732 Vulnerabilities
Get alerted when new CWE-732 CVEs affect your infrastructure.
Start Monitoring Free