CWE-732: CWE-732

313
Total CVEs
41
Critical
209
High
7.7
Avg CVSS

Yearly Trend

2026
19
2025
111
2024
57
2023
40
2022
26

Top Affected Vendors

1 Google 11
2 Oracle 11
3 Siemens 9
4 Apple 7
5 Nagios 7
6 Ibm 7
7 Intel 7
8 Sap 5
9 Dell 5
10 Trendmicro 4

All CWE-732 CVEs (313)

CVE-2024-30413
7.5

This CVE describes an improper permission control vulnerability in the window management module of Huawei/HarmonyOS devices. Successful exploitation c...

Apr 7, 2024
CVE-2023-34437
7.5

This vulnerability in Baker Hughes Bently Nevada 3500 System TDI firmware allows attackers to retrieve stored passwords from the device. Affected syst...

Oct 19, 2023
CVE-2023-39003
7.5

This CVE involves insecure permissions in the /tmp directory of OPNsense firewall appliances, allowing local attackers to potentially escalate privile...

Aug 9, 2023
CVE-2022-44719
7.5

CVE-2022-44719 is an insecure permissions vulnerability in the SSH server component of Weblib Ucopia software. This allows unauthorized users to acces...

Jun 29, 2023
CVE-2023-29860
7.5

This vulnerability in DTStack Taier 1.3.0 allows attackers to view sensitive information through insecure permissions in the /Taier/API/tenant/listTen...

Jun 23, 2023
CVE-2023-31453
7.5

This vulnerability in Apache InLong allows attackers to delete other users' subscriptions without proper authorization. It affects Apache InLong versi...

May 22, 2023
CVE-2023-1692
7.5

CVE-2023-1692 is an improper permission verification vulnerability in Huawei/HarmonyOS window management modules that allows unauthorized access to se...

May 20, 2023
CVE-2022-43946
7.5

This CVE describes two vulnerabilities in Fortinet FortiClient for Windows: an incorrect permission assignment (CWE-732) and a TOCTOU race condition (...

Apr 11, 2023
CVE-2021-37304
7.5

CVE-2021-37304 is an insecure permissions vulnerability in jeecg-boot 2.4.5 that allows unauthenticated remote attackers to access the httptrace inter...

Feb 3, 2023
CVE-2021-37306
7.5

CVE-2021-37306 is an insecure permissions vulnerability in jeecg-boot that allows remote attackers to check if a username exists without authenticatio...

Feb 3, 2023
CVE-2022-20234
7.5

This vulnerability in Android's Car Settings app allows malicious apps to trick users into granting notification access permissions. By exploiting an ...

Jul 13, 2022
CVE-2022-32155
7.5

Splunk Universal Forwarder versions before 9.0 have remote management services enabled by default, exposing management ports to network access. This c...

Jun 15, 2022
CVE-2022-1412
7.5

The Log WP_Mail WordPress plugin through version 0.1 saves sent emails in a publicly accessible directory with predictable filenames, allowing any una...

Jun 13, 2022
CVE-2022-0247
7.5

This vulnerability in Fuchsia allows local attackers to modify Virtual Memory Object (VMO) data through copy-on-write snapshots, bypassing permission ...

Feb 25, 2022
CVE-2021-20874
7.5

This vulnerability allows remote unauthenticated attackers to access arbitrary files on GroupSession servers, potentially exposing sensitive informati...

Dec 24, 2021
CVE-2020-27568
7.5

CVE-2020-27568 involves insecure file permissions in Aviatrix Controller 5.3.1516 where multiple files and directories are world-writable. This allows...

Apr 21, 2021
CVE-2025-33088
7.4

This vulnerability allows local users with knowledge of IBM Concert's system architecture to escalate privileges by exploiting incorrect file permissi...

Feb 17, 2026
CVE-2024-1486
7.4

This vulnerability allows attackers to gain elevated privileges on GE HealthCare ultrasound devices due to misconfigured access control lists. It affe...

May 14, 2024
CVE-2025-23258
7.3

This vulnerability in NVIDIA DOCA's collectx-dpeserver package for ARM64 systems allows local attackers with low privileges to escalate to root privil...

Sep 4, 2025
CVE-2025-55524
7.3

Agent-Zero v0.8.* has insecure permissions that allow attackers to trigger arbitrary system resets. This vulnerability affects all systems running vul...

Aug 21, 2025
CVE-2025-30661
7.3

A local privilege escalation vulnerability in Juniper Junos OS allows low-privileged users to place scripts that execute as root during system boot on...

Jul 11, 2025
CVE-2025-48961
7.3

This CVE describes a local privilege escalation vulnerability in Acronis Cyber Protect 16 for Windows due to insecure folder permissions. An attacker ...

Jun 4, 2025
CVE-2025-1067
7.3

An untrusted search path vulnerability in Esri ArcGIS Pro allows attackers with local file system write access to plant malicious executables that exe...

Feb 25, 2025
CVE-2025-21571
7.3

This vulnerability in Oracle VM VirtualBox allows a high-privileged attacker with local access to compromise the virtualization software, potentially ...

Jan 21, 2025
CVE-2023-6729
7.3

CVE-2023-6729 allows authenticated users with 'access console' privileges on Nokia SR OS routers to gain read-write access to the entire file system v...

Oct 17, 2024
CVE-2024-24910
7.3

This vulnerability allows a local attacker with existing privileged code execution to escalate privileges on affected Check Point security products. I...

Apr 18, 2024
CVE-2024-29187
7.3

This vulnerability in WiX toolset allows standard users to hijack binaries dropped in C:\Windows\Temp when bundles run as SYSTEM, leading to privilege...

Mar 24, 2024
CVE-2023-49580
7.3

This vulnerability in SAP GUI for Windows and Java allows unauthenticated attackers to access restricted information and create ABAP List Viewer layou...

Dec 12, 2023
CVE-2022-22521
7.3

CVE-2022-22521 is a privilege escalation vulnerability in Miele Benchmark Programming Tool where attackers can manipulate executable files to trick us...

Apr 27, 2022
CVE-2021-44466
7.3

CVE-2021-44466 is a local privilege escalation vulnerability in Bitmask Riseup VPN 0.21.6. When installed in a non-default directory, improper ACLs al...

Dec 30, 2021
CVE-2021-27070
7.3

CVE-2021-27070 is an elevation of privilege vulnerability in the Windows 10 Update Assistant that allows authenticated attackers to execute arbitrary ...

Mar 11, 2021
CVE-2025-3944
7.2

This vulnerability allows attackers to manipulate files on systems running vulnerable versions of Tridium Niagara Framework or Niagara Enterprise Secu...

May 22, 2025
CVE-2023-20254
7.2

This vulnerability allows authenticated remote attackers to access other tenants' data and configurations in Cisco Catalyst SD-WAN Manager when multi-...

Sep 27, 2023
CVE-2021-40101
7.2

This vulnerability allows authenticated users in Concrete CMS to change their own or potentially other users' passwords without providing the current ...

Nov 30, 2021
CVE-2025-62688
7.1

A privilege escalation vulnerability in Productivity Suite software allows authenticated low-privileged users to modify their own role assignments, gr...

Oct 23, 2025
CVE-2025-2503
7.1

A local privilege escalation vulnerability in Lenovo PC Manager allows attackers with local access to delete arbitrary files with elevated system perm...

May 30, 2025
CVE-2024-13813
7.1

CVE-2024-13813 is an insufficient permissions vulnerability in Ivanti Secure Access Client that allows local authenticated attackers to delete arbitra...

Feb 11, 2025
CVE-2024-46881
7.1

This vulnerability in Develocity (formerly Gradle Enterprise) allows unauthorized access to project information due to incorrect access control during...

Jan 26, 2025
CVE-2024-7572
7.1

This vulnerability in Ivanti DSM allows local authenticated users to delete arbitrary files due to insufficient permissions. It affects organizations ...

Dec 10, 2024
CVE-2024-42449
7.1

This vulnerability allows an authorized Veeam Service Provider Console (VSPC) management agent to delete arbitrary files on the VSPC server. It affect...

Dec 4, 2024
CVE-2023-33695
7.1

Hutool versions 5.8.17 and below contain an information disclosure vulnerability where the File.createTempFile() function in FileUtil.java creates tem...

Jun 13, 2023
CVE-2021-36133
7.1

This vulnerability allows attackers to bypass TrustZone security on affected NXP i.MX SoC devices by exploiting a DMA-capable peripheral to read/write...

Dec 7, 2021
CVE-2021-31540
7.1

This vulnerability in Wowza Streaming Engine allows local users to read and modify configuration files due to overly permissive file permissions. This...

Apr 23, 2021
CVE-2021-25276
7.1

This vulnerability allows unprivileged Windows users with filesystem access to add FTP users by copying profile files to a world-readable/writable dir...

Feb 3, 2021
CVE-2026-0775
7.0

This CVE describes a local privilege escalation vulnerability in npm CLI where incorrect permission assignment allows loading modules from unsecured l...

Jan 23, 2026
CVE-2025-53396
7.0

This CVE describes an incorrect permission assignment vulnerability in SS1 software that allows authenticated users to escalate privileges to root. It...

Aug 28, 2025
CVE-2025-36537
7.0

This vulnerability allows a local unprivileged user on Windows systems to delete arbitrary files with SYSTEM privileges by exploiting the MSI rollback...

Jun 24, 2025
CVE-2023-3322
7.0

This vulnerability allows low-privileged users to read and modify data in Zenon system directories, potentially enabling unauthorized access and manip...

Jul 24, 2023
CVE-2023-0834
7.0

This vulnerability allows local attackers on macOS systems to escalate privileges by exploiting incorrect permission assignments in HYPR Workforce Acc...

Apr 28, 2023
CVE-2021-44512
7.0

This vulnerability in tmate-ssh-server allows local attackers to manipulate session files due to insecure directory permissions. Attackers can comprom...

Dec 7, 2021

About CWE-732 (CWE-732)

Our database tracks 313 CVEs classified as CWE-732, with 41 rated critical and 209 rated high severity. The average CVSS score for CWE-732 vulnerabilities is 7.7.

External reference: View CWE-732 on MITRE CWE →

Monitor CWE-732 Vulnerabilities

Get alerted when new CWE-732 CVEs affect your infrastructure.

Start Monitoring Free