CWE-732: CWE-732
Yearly Trend
Top Affected Vendors
All CWE-732 CVEs (313)
This CVE describes an improper permission control vulnerability in the window management module of Huawei/HarmonyOS devices. Successful exploitation c...
Apr 7, 2024This vulnerability in Baker Hughes Bently Nevada 3500 System TDI firmware allows attackers to retrieve stored passwords from the device. Affected syst...
Oct 19, 2023This CVE involves insecure permissions in the /tmp directory of OPNsense firewall appliances, allowing local attackers to potentially escalate privile...
Aug 9, 2023CVE-2022-44719 is an insecure permissions vulnerability in the SSH server component of Weblib Ucopia software. This allows unauthorized users to acces...
Jun 29, 2023This vulnerability in DTStack Taier 1.3.0 allows attackers to view sensitive information through insecure permissions in the /Taier/API/tenant/listTen...
Jun 23, 2023This vulnerability in Apache InLong allows attackers to delete other users' subscriptions without proper authorization. It affects Apache InLong versi...
May 22, 2023CVE-2023-1692 is an improper permission verification vulnerability in Huawei/HarmonyOS window management modules that allows unauthorized access to se...
May 20, 2023This CVE describes two vulnerabilities in Fortinet FortiClient for Windows: an incorrect permission assignment (CWE-732) and a TOCTOU race condition (...
Apr 11, 2023CVE-2021-37304 is an insecure permissions vulnerability in jeecg-boot 2.4.5 that allows unauthenticated remote attackers to access the httptrace inter...
Feb 3, 2023CVE-2021-37306 is an insecure permissions vulnerability in jeecg-boot that allows remote attackers to check if a username exists without authenticatio...
Feb 3, 2023This vulnerability in Android's Car Settings app allows malicious apps to trick users into granting notification access permissions. By exploiting an ...
Jul 13, 2022Splunk Universal Forwarder versions before 9.0 have remote management services enabled by default, exposing management ports to network access. This c...
Jun 15, 2022The Log WP_Mail WordPress plugin through version 0.1 saves sent emails in a publicly accessible directory with predictable filenames, allowing any una...
Jun 13, 2022This vulnerability in Fuchsia allows local attackers to modify Virtual Memory Object (VMO) data through copy-on-write snapshots, bypassing permission ...
Feb 25, 2022This vulnerability allows remote unauthenticated attackers to access arbitrary files on GroupSession servers, potentially exposing sensitive informati...
Dec 24, 2021CVE-2020-27568 involves insecure file permissions in Aviatrix Controller 5.3.1516 where multiple files and directories are world-writable. This allows...
Apr 21, 2021This vulnerability allows local users with knowledge of IBM Concert's system architecture to escalate privileges by exploiting incorrect file permissi...
Feb 17, 2026This vulnerability allows attackers to gain elevated privileges on GE HealthCare ultrasound devices due to misconfigured access control lists. It affe...
May 14, 2024This vulnerability in NVIDIA DOCA's collectx-dpeserver package for ARM64 systems allows local attackers with low privileges to escalate to root privil...
Sep 4, 2025Agent-Zero v0.8.* has insecure permissions that allow attackers to trigger arbitrary system resets. This vulnerability affects all systems running vul...
Aug 21, 2025A local privilege escalation vulnerability in Juniper Junos OS allows low-privileged users to place scripts that execute as root during system boot on...
Jul 11, 2025This CVE describes a local privilege escalation vulnerability in Acronis Cyber Protect 16 for Windows due to insecure folder permissions. An attacker ...
Jun 4, 2025An untrusted search path vulnerability in Esri ArcGIS Pro allows attackers with local file system write access to plant malicious executables that exe...
Feb 25, 2025This vulnerability in Oracle VM VirtualBox allows a high-privileged attacker with local access to compromise the virtualization software, potentially ...
Jan 21, 2025CVE-2023-6729 allows authenticated users with 'access console' privileges on Nokia SR OS routers to gain read-write access to the entire file system v...
Oct 17, 2024This vulnerability allows a local attacker with existing privileged code execution to escalate privileges on affected Check Point security products. I...
Apr 18, 2024This vulnerability in WiX toolset allows standard users to hijack binaries dropped in C:\Windows\Temp when bundles run as SYSTEM, leading to privilege...
Mar 24, 2024This vulnerability in SAP GUI for Windows and Java allows unauthenticated attackers to access restricted information and create ABAP List Viewer layou...
Dec 12, 2023CVE-2022-22521 is a privilege escalation vulnerability in Miele Benchmark Programming Tool where attackers can manipulate executable files to trick us...
Apr 27, 2022CVE-2021-44466 is a local privilege escalation vulnerability in Bitmask Riseup VPN 0.21.6. When installed in a non-default directory, improper ACLs al...
Dec 30, 2021CVE-2021-27070 is an elevation of privilege vulnerability in the Windows 10 Update Assistant that allows authenticated attackers to execute arbitrary ...
Mar 11, 2021This vulnerability allows attackers to manipulate files on systems running vulnerable versions of Tridium Niagara Framework or Niagara Enterprise Secu...
May 22, 2025This vulnerability allows authenticated remote attackers to access other tenants' data and configurations in Cisco Catalyst SD-WAN Manager when multi-...
Sep 27, 2023This vulnerability allows authenticated users in Concrete CMS to change their own or potentially other users' passwords without providing the current ...
Nov 30, 2021A privilege escalation vulnerability in Productivity Suite software allows authenticated low-privileged users to modify their own role assignments, gr...
Oct 23, 2025A local privilege escalation vulnerability in Lenovo PC Manager allows attackers with local access to delete arbitrary files with elevated system perm...
May 30, 2025CVE-2024-13813 is an insufficient permissions vulnerability in Ivanti Secure Access Client that allows local authenticated attackers to delete arbitra...
Feb 11, 2025This vulnerability in Develocity (formerly Gradle Enterprise) allows unauthorized access to project information due to incorrect access control during...
Jan 26, 2025This vulnerability in Ivanti DSM allows local authenticated users to delete arbitrary files due to insufficient permissions. It affects organizations ...
Dec 10, 2024This vulnerability allows an authorized Veeam Service Provider Console (VSPC) management agent to delete arbitrary files on the VSPC server. It affect...
Dec 4, 2024Hutool versions 5.8.17 and below contain an information disclosure vulnerability where the File.createTempFile() function in FileUtil.java creates tem...
Jun 13, 2023This vulnerability allows attackers to bypass TrustZone security on affected NXP i.MX SoC devices by exploiting a DMA-capable peripheral to read/write...
Dec 7, 2021This vulnerability in Wowza Streaming Engine allows local users to read and modify configuration files due to overly permissive file permissions. This...
Apr 23, 2021This vulnerability allows unprivileged Windows users with filesystem access to add FTP users by copying profile files to a world-readable/writable dir...
Feb 3, 2021This CVE describes a local privilege escalation vulnerability in npm CLI where incorrect permission assignment allows loading modules from unsecured l...
Jan 23, 2026This CVE describes an incorrect permission assignment vulnerability in SS1 software that allows authenticated users to escalate privileges to root. It...
Aug 28, 2025This vulnerability allows a local unprivileged user on Windows systems to delete arbitrary files with SYSTEM privileges by exploiting the MSI rollback...
Jun 24, 2025This vulnerability allows low-privileged users to read and modify data in Zenon system directories, potentially enabling unauthorized access and manip...
Jul 24, 2023This vulnerability allows local attackers on macOS systems to escalate privileges by exploiting incorrect permission assignments in HYPR Workforce Acc...
Apr 28, 2023This vulnerability in tmate-ssh-server allows local attackers to manipulate session files due to insecure directory permissions. Attackers can comprom...
Dec 7, 2021About CWE-732 (CWE-732)
Our database tracks 313 CVEs classified as CWE-732, with 41 rated critical and 209 rated high severity. The average CVSS score for CWE-732 vulnerabilities is 7.7.
External reference: View CWE-732 on MITRE CWE →
Monitor CWE-732 Vulnerabilities
Get alerted when new CWE-732 CVEs affect your infrastructure.
Start Monitoring Free