CWE-732: CWE-732

313
Total CVEs
41
Critical
209
High
7.7
Avg CVSS

Yearly Trend

2026
19
2025
111
2024
57
2023
40
2022
26

Top Affected Vendors

1 Google 11
2 Oracle 11
3 Siemens 9
4 Apple 7
5 Nagios 7
6 Ibm 7
7 Intel 7
8 Sap 5
9 Dell 5
10 Trendmicro 4

All CWE-732 CVEs (313)

CVE-2022-26526
7.8

This vulnerability allows local users to escalate privileges by placing malicious executable files in a world-writable directory that gets added to th...

Mar 17, 2022
CVE-2022-22141
7.8

This vulnerability in Yokogawa's Long-term Data Archive Package service creates named pipes with improper access control lists (ACLs), allowing unauth...

Mar 11, 2022
CVE-2022-22148
7.8

This vulnerability in Yokogawa's 'Root Service' allows attackers to exploit improperly configured named pipe ACLs, potentially enabling privilege esca...

Mar 11, 2022
CVE-2021-4199
7.8

This vulnerability allows a local attacker to escalate privileges to SYSTEM by exploiting incorrect permissions in BDReinit.exe, Bitdefender's crash h...

Mar 7, 2022
CVE-2021-39992
7.8

CVE-2021-39992 is an improper security permission configuration vulnerability in Huawei ACPU that allows attackers to bypass intended security restric...

Feb 9, 2022
CVE-2021-39621
7.8

This Android vulnerability allows local privilege escalation through a permissions bypass in the voicemail notification system. Attackers can exploit ...

Jan 14, 2022
CVE-2021-20172
7.8

This CVE describes a local privilege escalation vulnerability in Netgear Genie Installer for macOS. An attacker with local access can overwrite specif...

Dec 30, 2021
CVE-2021-43065
7.8

This vulnerability in Fortinet FortiNAC allows attackers to gain elevated privileges by accessing sensitive system data due to incorrect permission as...

Dec 9, 2021
CVE-2021-43019
7.8

This CVE describes a privilege escalation vulnerability in Adobe Creative Cloud installer versions 5.5 and earlier. An attacker with initial low-privi...

Nov 23, 2021
CVE-2021-0064
7.8

This vulnerability allows an authenticated user on a Windows system with vulnerable Intel PROSet/Wireless WiFi software to escalate privileges via loc...

Nov 17, 2021
CVE-2021-33094
7.8

This vulnerability allows authenticated local users to escalate privileges on Intel NUC M15 Laptop Kit systems due to insecure inherited permissions i...

Nov 17, 2021
CVE-2021-42954
7.8

This vulnerability allows non-admin users on Windows systems to modify files in Zoho Remote Access Plus installation directory due to overly permissiv...

Nov 17, 2021
CVE-2021-37364
7.8

OpenClinic GA 5.194.18 has insecure file permissions that allow authenticated low-privilege users to replace critical service executables with malicio...

Oct 26, 2021
CVE-2021-40343
7.8

CVE-2021-40343 is a privilege escalation vulnerability in Nagios XI where insecure file permissions on nagios_unbundler.py allow the nagios user to ex...

Oct 26, 2021
CVE-2021-0692
7.8

This vulnerability allows local attackers to escalate privileges on Android devices by exploiting an unsafe PendingIntent in the FirstScreenBroadcast ...

Oct 6, 2021
CVE-2021-34409
7.8

This vulnerability allows a malicious actor with local access to a macOS system to exploit improper permissions on installation scripts, potentially e...

Sep 27, 2021
CVE-2021-26434
7.8

This CVE describes an elevation of privilege vulnerability in Visual Studio where an attacker could exploit a flaw in the installer to gain SYSTEM pri...

Sep 15, 2021
CVE-2021-36280
7.8

Dell EMC PowerScale OneFS versions 8.2.x through 9.2.x contain an incorrect permission assignment vulnerability that allows users with SSH or console ...

Aug 16, 2021
CVE-2021-37841
7.8

CVE-2021-37841 is an access control vulnerability in Docker Desktop for Windows that allows low-privileged users to compromise containers. Attackers c...

Aug 12, 2021
CVE-2021-21567
7.8

This vulnerability allows authenticated users with SSH or console login privileges on Dell PowerScale OneFS systems to elevate their privileges beyond...

Aug 10, 2021
CVE-2021-32577
7.8

CVE-2021-32577 is a local privilege escalation vulnerability in Acronis True Image for Windows where insecure folder permissions allow authenticated l...

Aug 5, 2021
CVE-2021-30577
7.8

This vulnerability in Google Chrome's installer allows an attacker to escalate local privileges by tricking a user into opening a malicious file. It a...

Aug 3, 2021
CVE-2021-32463
7.8

This vulnerability allows a local attacker with low-privileged access to escalate privileges and delete files with system-level permissions on Trend M...

Jul 20, 2021
CVE-2021-35449
7.8

This vulnerability allows low-privileged users to escalate privileges to SYSTEM level by exploiting Lexmark printer drivers during the add printer pro...

Jul 19, 2021
CVE-2021-31859
7.8

This vulnerability allows local users on systems running YSoft SafeQ 6 to escalate privileges by overwriting the MU55 FlexiSpooler service executable ...

Jul 14, 2021
CVE-2020-0417
7.8

This vulnerability allows local privilege escalation on Android devices by bypassing permissions through an empty mutable PendingIntent in the GPS net...

Jul 14, 2021
CVE-2021-22921
7.8

This vulnerability allows local attackers on Windows systems to escalate privileges through PATH and DLL hijacking attacks. It affects Node.js install...

Jul 12, 2021
CVE-2021-0570
7.8

This vulnerability allows local privilege escalation on Android 11 devices through an unsafe PendingIntent in the bug reporting service. Attackers can...

Jun 22, 2021
CVE-2021-23022
7.8

This vulnerability involves weak file and folder permissions in the temporary folder of the BIG-IP Edge Client Windows Installer Service, allowing att...

Jun 10, 2021
CVE-2021-0055
7.8

This vulnerability affects Intel NUC 9 Extreme Laptop Kit LAN drivers with insecure inherited permissions. An authenticated attacker could exploit thi...

Jun 9, 2021
CVE-2021-0077
7.8

This vulnerability in Intel VTune Profiler installer allows authenticated local users to escalate privileges due to insecure inherited permissions. It...

Jun 9, 2021
CVE-2021-0102
7.8

This vulnerability in Intel Unite Client for Windows allows authenticated local users to escalate privileges due to insecure inherited permissions. At...

Jun 9, 2021
CVE-2021-32460
7.8

CVE-2021-32460 is a local privilege escalation vulnerability in Trend Micro Maximum Security 2021 installer that allows attackers with existing local ...

Jun 3, 2021
CVE-2021-25253
7.8

This vulnerability allows a local attacker with low-privileged access to escalate privileges on Trend Micro Apex One and OfficeScan XG SP1 installatio...

Apr 13, 2021
CVE-2021-0109
7.8

This vulnerability in Intel SOC driver packages allows authenticated local users to escalate privileges due to insecure inherited permissions. It affe...

Feb 17, 2021
CVE-2021-0336
7.8

This vulnerability allows local attackers to bypass Bluetooth permission checks on Android devices by exploiting a mutable PendingIntent in the Blueto...

Feb 10, 2021
CVE-2024-25646
7.7

CVE-2024-25646 is an information disclosure vulnerability in SAP BusinessObjects Business Intelligence Launch Pad where improper validation allows aut...

Apr 9, 2024
CVE-2022-21819
7.6

This vulnerability in NVIDIA Jetson Linux allows an unprivileged attacker with physical access to bypass IOMMU protections and gain direct read/write ...

Mar 11, 2022
CVE-2025-66723
7.5

CVE-2025-66723 is an insecure permissions vulnerability in inMusic Brands Engine DJ software where the Remote Library's exposed HTTP service allows at...

Dec 30, 2025
CVE-2025-41664
7.5

This vulnerability allows low-privileged remote attackers to access critical system resources like firmware and certificates due to improper permissio...

Sep 8, 2025
CVE-2025-0093
7.5

This vulnerability in Android's Bluetooth stack allows unauthorized access to Bluetooth bonding state information without proper permission checks. It...

Aug 26, 2025
CVE-2025-30708
7.5

This vulnerability in Oracle E-Business Suite's User Management component allows unauthenticated attackers to access sensitive user data via HTTP. It ...

Apr 15, 2025
CVE-2024-57068
7.5

This CVE describes a prototype pollution vulnerability in the @tanstack/form-core library that allows attackers to cause Denial of Service (DoS) by su...

Feb 5, 2025
CVE-2024-57547
7.5

CMSimple v5.16 has an insecure permissions vulnerability that allows remote attackers to download PHP backup files containing sensitive information. T...

Jan 27, 2025
CVE-2025-0590
7.5

This vulnerability in the CarlCare mobile application allows unauthorized access to sensitive information due to improper permission settings. It affe...

Jan 20, 2025
CVE-2022-30354
7.5

OvalEdge versions 5.2.8.0 and earlier expose sensitive user ID data through an authenticated GET request to /user/getUserWithTeam. This vulnerability ...

Oct 25, 2024
CVE-2024-8900
7.5

This vulnerability allows attackers to write arbitrary data to a user's clipboard without user consent during specific navigational sequences. It affe...

Sep 17, 2024
CVE-2024-7986
7.5

This vulnerability in Rockwell Automation ThinManager ThinServer allows attackers to read arbitrary files by exploiting directory junction points. It ...

Aug 23, 2024
CVE-2024-29078
7.5

This vulnerability allows remote unauthenticated attackers to alter MosP kintai kanri settings by exploiting incorrect permission assignments for crit...

May 28, 2024
CVE-2023-52715
7.5

This CVE describes a permission management vulnerability in the SystemUI module of Huawei/HarmonyOS devices. Successful exploitation could allow attac...

Apr 7, 2024

About CWE-732 (CWE-732)

Our database tracks 313 CVEs classified as CWE-732, with 41 rated critical and 209 rated high severity. The average CVSS score for CWE-732 vulnerabilities is 7.7.

External reference: View CWE-732 on MITRE CWE →

Monitor CWE-732 Vulnerabilities

Get alerted when new CWE-732 CVEs affect your infrastructure.

Start Monitoring Free