CWE-732: CWE-732

313
Total CVEs
41
Critical
209
High
7.7
Avg CVSS

Yearly Trend

2026
19
2025
111
2024
57
2023
40
2022
26

Top Affected Vendors

1 Google 11
2 Oracle 11
3 Siemens 9
4 Apple 7
5 Nagios 7
6 Ibm 7
7 Intel 7
8 Sap 5
9 Dell 5
10 Trendmicro 4

All CWE-732 CVEs (313)

CVE-2025-64699
7.8

This vulnerability allows local attackers to perform unauthorized raw disk operations due to an incorrect NULL DACL in SevenCs ORCA G2's regService pr...

Dec 31, 2025
CVE-2025-13703
7.8

This vulnerability allows local attackers with initial low-privileged access to escalate privileges to SYSTEM level by exploiting incorrect folder per...

Dec 23, 2025
CVE-2025-13733
7.8

BuhoNTFS version 1.3.2 contains an insecure XPC service that allows local, unprivileged users to execute arbitrary code with root privileges. This aff...

Dec 12, 2025
CVE-2025-34323
7.8

This CVE describes a local privilege escalation vulnerability in Nagios Log Server where the 'www-data' user can replace root-owned scripts in a writa...

Nov 17, 2025
CVE-2024-32010
7.8

This vulnerability in Siemens Spectrum Power 4 allows attackers to read database credentials from a world-readable file. With these credentials, attac...

Nov 11, 2025
CVE-2025-34287
7.8

This vulnerability allows attackers with web server privileges (www-data user) to modify a Nagios XI script, leading to arbitrary code execution as th...

Oct 30, 2025
CVE-2025-10751
7.8

MacForge 1.2.0 Beta 1 contains an insecure XPC service that allows local, unprivileged users to escalate privileges to root. This vulnerability enable...

Oct 4, 2025
CVE-2025-10541
7.8

This vulnerability allows local users to escalate privileges to SYSTEM level by placing malicious files in an insecure directory. Any local user on sy...

Sep 25, 2025
CVE-2025-43268
7.8

A permissions vulnerability in macOS allows malicious applications to escalate privileges to root access. This affects macOS systems running versions ...

Aug 29, 2025
CVE-2025-9578
7.8

This CVE describes a local privilege escalation vulnerability in Acronis Cyber Protect Cloud Agent for Windows due to insecure folder permissions. Att...

Aug 28, 2025
CVE-2025-50675
7.8

GPMAW 14 has insecure file permissions in its installation directory, allowing any user with local access to replace the uninstaller executable. When ...

Aug 7, 2025
CVE-2025-27446
7.8

This vulnerability allows a local attacker to exploit incorrect file permissions in Apache APISIX's Java plugin runner to elevate privileges. It affec...

Jul 6, 2025
CVE-2025-2759
7.8

This CVE-2025-2759 vulnerability in GStreamer's installer allows local attackers to escalate privileges by exploiting incorrect folder permissions. At...

May 22, 2025
CVE-2025-40574
7.8

A local privilege escalation vulnerability in Siemens SCALANCE LPE9403 industrial routers allows non-privileged local attackers to interact with the b...

May 13, 2025
CVE-2025-1731
7.8

An incorrect permission assignment vulnerability in PostgreSQL commands in Zyxel USG FLEX H series firewalls allows authenticated local attackers with...

Apr 22, 2025
CVE-2024-13861
7.8

A local privilege escalation vulnerability in Taegis Endpoint Agent on Debian-based Linux systems allows local users to execute arbitrary code with ro...

Apr 11, 2025
CVE-2025-27688
7.8

Dell ThinOS 2408 and earlier versions have an improper permissions vulnerability that allows local low-privileged attackers to elevate their privilege...

Mar 18, 2025
CVE-2025-22454
7.8

This CVE describes a local privilege escalation vulnerability in Ivanti Secure Access Client where insufficient permissions allow authenticated local ...

Mar 11, 2025
CVE-2025-21325
7.8

This vulnerability allows an authenticated attacker to execute arbitrary code with kernel privileges on Windows systems. It affects Windows 10, 11, an...

Jan 17, 2025
CVE-2024-9244
7.8

This vulnerability in Foxit PDF Reader's Update Service allows local attackers to escalate privileges from a low-privileged user to SYSTEM by exploiti...

Nov 22, 2024
CVE-2024-7245
7.8

This vulnerability in Panda Security Dome VPN allows local attackers to escalate privileges from a low-privileged user account to SYSTEM level by expl...

Nov 22, 2024
CVE-2024-47783
7.8

A local privilege escalation vulnerability exists in SIPORT software where improper file permissions allow unprivileged local users to modify service ...

Nov 12, 2024
CVE-2024-22029
7.8

This CVE describes a local privilege escalation vulnerability in Tomcat packaging where insecure file permissions during installation allow local user...

Oct 16, 2024
CVE-2024-38456
7.8

This vulnerability allows non-admin users to exploit weak file and folder permissions in Vivavis HIGH-LEIT software to escalate privileges and execute...

Sep 3, 2024
CVE-2024-5930
7.8

This vulnerability allows local attackers with low-privileged access to escalate privileges to SYSTEM level by exploiting incorrect file permissions i...

Aug 21, 2024
CVE-2024-43199
7.8

This CVE describes a local privilege escalation vulnerability in Nagios NDOUtils where certain executable files are owned by the nagios user instead o...

Aug 7, 2024
CVE-2024-31202
7.8

This vulnerability allows a local attacker to escalate privileges by exploiting incorrect permissions in the ThermoscanIP installation folder. Attacke...

Jul 31, 2024
CVE-2023-5936
7.8

This CVE describes a local privilege escalation vulnerability in Arc software on Unix systems where temporary files are created with unsafe permission...

May 15, 2024
CVE-2023-35841
7.8

This vulnerability in the Phoenix WinFlash Driver allows attackers with local access to escalate privileges by exploiting an exposed IOCTL interface w...

May 14, 2024
CVE-2023-47712
7.8

This vulnerability in IBM Security Guardium allows a local user to gain elevated privileges on the system due to improper permissions control. It affe...

May 14, 2024
CVE-2024-21431
7.8

This vulnerability allows attackers to bypass Hypervisor-Protected Code Integrity (HVCI) security features on Windows systems, potentially enabling th...

Mar 12, 2024
CVE-2024-22016
7.8

This vulnerability allows authorized users in Rapid SCADA to write directly to the Scada directory, potentially enabling privilege escalation. It affe...

Feb 2, 2024
CVE-2023-28134
7.8

CVE-2023-28134 is a local privilege escalation vulnerability in Check Point Harmony Endpoint and ZoneAlarm Extreme Security. An attacker with low-priv...

Nov 12, 2023
CVE-2023-40361
7.8

CVE-2023-40361 is an insecure permissions vulnerability in SECUDOS Qiata (DOMOS OS) where the previewRm.sh cronjob has world-writable permissions. Thi...

Oct 20, 2023
CVE-2022-30527
7.8

CVE-2022-30527 is an improper access control vulnerability in Siemens SINEC NMS where specific folders containing executables and libraries have overl...

Oct 10, 2023
CVE-2023-32162
7.8

This vulnerability allows local attackers with low-privileged access to escalate to SYSTEM privileges by exploiting incorrect file permissions on Waco...

Sep 6, 2023
CVE-2023-28133
7.8

CVE-2023-28133 allows local attackers to escalate privileges on Windows systems running Check Point Endpoint Security Client E87.30 by crafting a mali...

Jul 23, 2023
CVE-2023-30897
7.8

This vulnerability in SIMATIC WinCC allows authenticated local attackers to inject arbitrary code and escalate privileges when the software is install...

Jun 13, 2023
CVE-2023-31871
7.8

CVE-2023-31871 is a privilege escalation vulnerability in OpenText Documentum Content Server where a non-privileged user can exploit the dm_secure_wri...

May 18, 2023
CVE-2023-1135
7.8

This vulnerability in Delta Electronics InfraSuite Device Master allows attackers to set incorrect directory permissions, potentially leading to local...

Mar 27, 2023
CVE-2022-42972
7.8

This vulnerability allows local attackers to escalate privileges by modifying the webroot directory due to incorrect permissions. It affects APC and S...

Feb 1, 2023
CVE-2022-34891
7.8

CVE-2022-34891 is a local privilege escalation vulnerability in Parallels Desktop where incorrect file permissions allow attackers to escalate to root...

Jul 18, 2022
CVE-2021-45492
7.8

This vulnerability allows unprivileged users to escalate privileges to SYSTEM via DLL search-order hijacking in Sage 300 ERP. The installer places a w...

Jul 14, 2022
CVE-2022-20218
7.8

This vulnerability in Android's PermissionController allows malicious apps to obtain and retain permissions without user consent due to a logic error....

Jul 13, 2022
CVE-2022-31464
7.8

This vulnerability in Adaware Protect v1.2.439.4251 allows local attackers to escalate privileges by modifying the service binary path due to insecure...

Jun 16, 2022
CVE-2022-30700
7.8

This vulnerability allows a local attacker with existing low-privileged access to escalate privileges by loading a malicious DLL with incorrect permis...

May 27, 2022
CVE-2022-22960
7.8

This vulnerability allows a malicious actor with local access to VMware Workspace ONE Access, Identity Manager, or vRealize Automation systems to esca...

Apr 13, 2022
CVE-2022-23448
7.8

This vulnerability allows local unprivileged attackers to achieve privilege escalation in Siemens SIMATIC Energy Manager software. By exploiting impro...

Apr 12, 2022
CVE-2022-22516
7.8

The SysDrv3S driver in CODESYS Control runtime system on Windows allows any system user to read and write restricted memory space. This vulnerability ...

Apr 7, 2022
CVE-2022-26250
7.8

Synaman v5.1 and below contains weak file permissions that allow authenticated attackers to escalate privileges. This vulnerability affects organizati...

Apr 6, 2022

About CWE-732 (CWE-732)

Our database tracks 313 CVEs classified as CWE-732, with 41 rated critical and 209 rated high severity. The average CVSS score for CWE-732 vulnerabilities is 7.7.

External reference: View CWE-732 on MITRE CWE →

Monitor CWE-732 Vulnerabilities

Get alerted when new CWE-732 CVEs affect your infrastructure.

Start Monitoring Free