CWE-732: CWE-732

313
Total CVEs
41
Critical
209
High
7.7
Avg CVSS

Yearly Trend

2026
19
2025
111
2024
57
2023
40
2022
26

Top Affected Vendors

1 Google 11
2 Oracle 11
3 Siemens 9
4 Apple 7
5 Nagios 7
6 Ibm 7
7 Intel 7
8 Sap 5
9 Dell 5
10 Trendmicro 4

All CWE-732 CVEs (313)

CVE-2025-31702
6.8

This vulnerability in certain Dahua embedded products allows attackers with normal user credentials to access admin-restricted data through specific H...

Oct 15, 2025
CVE-2024-47104
6.8

This vulnerability allows authenticated IBM i users with view authority to modify security attributes of underlying physical files without proper obje...

Dec 18, 2024
CVE-2022-43915
6.8

This vulnerability in IBM App Connect Enterprise Certified Container allows users with privileged access to running Pods to elevate their privileges b...

Aug 24, 2024
CVE-2025-14740
6.7

Docker Desktop for Windows installer has permission assignment vulnerabilities allowing low-privileged attackers to gain code execution. Attackers can...

Feb 4, 2026
CVE-2025-34288
6.7

This CVE describes a local privilege escalation vulnerability in Nagios XI where a maintenance script can be executed as root via sudo but includes a ...

Dec 16, 2025
CVE-2025-8108
6.7

This CVE describes a privilege escalation vulnerability in Axis devices where improper permissions and lack of input validation in ACAP configuration ...

Nov 11, 2025
CVE-2025-6779
6.7

CVE-2025-6779 is an improper permissions vulnerability in ACAP configuration files on Axis devices that could allow command injection and privilege es...

Nov 11, 2025
CVE-2025-30408
6.7

This CVE describes a local privilege escalation vulnerability in Acronis Cyber Protect products on Windows. Attackers with local access can exploit in...

Apr 24, 2025
CVE-2024-20456
6.7

This vulnerability allows authenticated local attackers with root-system privileges on Cisco IOS XR devices to bypass Secure Boot functionality and lo...

Jul 10, 2024
CVE-2024-24912
6.7

This CVE describes a local privilege escalation vulnerability in Check Point Harmony Endpoint Security Client for Windows. An attacker with existing l...

May 1, 2024
CVE-2026-1344
6.5

CVE-2026-1344 is an insecure file permissions vulnerability in Tanium's Enforce Recovery Key Portal that could allow unauthorized users to access sens...

Feb 18, 2026
CVE-2025-10059
6.5

An improper handling of the lsid field in sharded queries can cause MongoDB routers to crash when this field is provided in contexts where it's not ap...

Sep 5, 2025
CVE-2025-30688
6.5

This vulnerability in MySQL Server's optimizer component allows authenticated attackers with low privileges to cause a denial of service by crashing o...

Apr 15, 2025
CVE-2025-30682
6.5

A vulnerability in MySQL Server's optimizer component allows authenticated attackers with low privileges to cause denial of service by crashing or han...

Apr 15, 2025
CVE-2025-27141
6.5

In Metabase Enterprise Edition, users with impersonation permissions can access cached query results from other users, potentially viewing data they s...

Feb 24, 2025
CVE-2025-21566
6.5

This vulnerability in Oracle MySQL Server's optimizer component allows attackers with low-privileged network access to cause a denial of service (DoS)...

Jan 21, 2025
CVE-2024-39967
6.5

CVE-2024-39967 is an insecure permissions vulnerability in Aginode GigaSwitch v5 that allows attackers to access sensitive information via SCP command...

Jan 15, 2025
CVE-2024-45841
6.5

This vulnerability allows attackers with guest account access to read sensitive credential information from a specific file in UD-LT1 and UD-LT1/EX fi...

Dec 5, 2024
CVE-2025-49131
6.3

CVE-2025-49131 is a sandbox escape vulnerability in FastGPT's sandbox container that allows attackers to break out of the isolated execution environme...

Jun 9, 2025
CVE-2024-1724
6.3

This vulnerability in snapd versions before 2.62 allows malicious snaps with 'home' plug permissions to write arbitrary scripts to the user's $HOME/bi...

Jul 25, 2024
CVE-2025-67794
6.1

DriveLock agent versions 24.1-24.2.7 and 25.1-25.1.5 create directories and files with overly permissive access control lists (ACLs). This allows loca...

Dec 17, 2025
CVE-2025-0758
6.1

Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.2, including 9.3.x and 8.3.x, have Karaf JMX beans enabled by default with in...

Apr 16, 2025
CVE-2026-20092
6.0

This vulnerability allows authenticated local administrators with read-only access in Cisco Intersight Virtual Appliance to escalate privileges to roo...

Jan 21, 2026
CVE-2025-46802
6.0

This vulnerability in screen allows any local user to connect to another user's screen session during a brief window when the PTY device has overly pe...

May 26, 2025
CVE-2024-11584
5.9

CVE-2024-11584 is a privilege escalation vulnerability in cloud-init where the default world-writable permissions on a systemd socket allow unprivileg...

Jun 26, 2025
CVE-2025-0926
5.9

A non-admin user can delete critical system files by exploiting a file deletion redirection vulnerability during video recording in Axis Camera Statio...

Apr 23, 2025
CVE-2024-41970
5.7

This vulnerability allows low-privileged remote attackers to access diagnostic data they shouldn't have permission to view due to incorrect permission...

Nov 18, 2024
CVE-2026-26095
5.5

CVE-2026-26095 is an incorrect permission assignment vulnerability in Owl opds 2.2.0.4 that allows attackers to manipulate files through crafted netwo...

Feb 20, 2026
CVE-2025-52627
5.5

This vulnerability in AION 2.0 allows attackers to modify critical system files because the root file system is not mounted as read-only. This affects...

Feb 3, 2026
CVE-2025-59961
5.5

A local privilege escalation vulnerability in Juniper's DHCP daemon allows any authenticated user, regardless of privileges, to connect to the managem...

Jan 15, 2026
CVE-2025-43470
5.5

This CVE describes a permissions bypass vulnerability in macOS where a standard user can view files from a disk image belonging to an administrator. T...

Dec 12, 2025
CVE-2025-43247
5.5

A macOS permissions vulnerability allows malicious applications with root privileges to modify system files. This affects macOS Ventura, Sonoma, and S...

Jul 30, 2025
CVE-2025-48382
5.5

This vulnerability in Fess Enterprise Search Server allows unauthorized local users to access sensitive temporary files due to insufficient file permi...

May 27, 2025
CVE-2025-32915
5.5

This vulnerability allows local attackers on Linux and Solaris systems to read sensitive data from Checkmk agent update packages due to incorrect file...

May 22, 2025
CVE-2025-31262
5.5

This CVE describes a permissions vulnerability in Apple operating systems that allows applications to modify protected areas of the file system. The i...

May 19, 2025
CVE-2025-40572
5.5

A local privilege escalation vulnerability in Siemens SCALANCE LPE9403 industrial routers allows non-privileged local attackers to access sensitive in...

May 13, 2025
CVE-2025-25041
5.5

A privilege escalation vulnerability in HPE Aruba Networking VIA client allows authenticated Windows users to overwrite arbitrary files with SYSTEM pr...

Apr 1, 2025
CVE-2024-49385
5.5

This vulnerability allows local attackers to access sensitive information due to insecure folder permissions in Acronis True Image for Windows. Users ...

Jan 2, 2025
CVE-2023-49582
5.5

This CVE allows local users on Unix systems to read Apache Portable Runtime (APR) named shared memory segments due to overly permissive permissions. T...

Aug 26, 2024
CVE-2025-64319
5.3

This vulnerability allows attackers to manipulate writeable configuration files in Salesforce Mulesoft Anypoint Code Builder due to incorrect permissi...

Nov 4, 2025
CVE-2025-64322
5.3

This vulnerability allows attackers to manipulate configuration files due to incorrect permission assignments in Salesforce Agentforce Vibes Extension...

Nov 4, 2025
CVE-2025-43808
5.3

This vulnerability allows remote attackers to access and download virtual products for free in Liferay Commerce by exploiting incorrect permission set...

Sep 19, 2025
CVE-2024-41954
5.3

CVE-2024-41954 is an information disclosure vulnerability in FOG Project where plaintext service account credentials are stored in a world-readable co...

Jul 31, 2024
CVE-2025-43266
5.1

A sandbox escape vulnerability in macOS allows malicious applications to bypass security restrictions and access system resources outside their design...

Jul 30, 2025
CVE-2026-22280
5.0

Dell PowerScale OneFS contains an incorrect permission assignment vulnerability that allows low-privileged local attackers to cause denial of service....

Jan 22, 2026
CVE-2024-47475
5.0

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.x have incorrect permissions on critical system resources. A local authenticated attacker could e...

Jan 6, 2025
CVE-2025-30684
4.9

This vulnerability in MySQL Server's replication component allows high-privileged attackers with network access to cause a denial of service by crashi...

Apr 15, 2025
CVE-2025-21585
4.9

This vulnerability in MySQL Server's optimizer component allows high-privileged attackers with network access to cause a denial of service (DoS) by cr...

Apr 15, 2025
CVE-2025-21579
4.9

This vulnerability in MySQL Server allows high-privileged attackers with network access to cause a denial of service (DoS) by crashing or hanging the ...

Apr 15, 2025
CVE-2025-21581
4.9

This vulnerability in MySQL Server's optimizer component allows high-privileged attackers with network access to cause a denial of service by crashing...

Apr 15, 2025

About CWE-732 (CWE-732)

Our database tracks 313 CVEs classified as CWE-732, with 41 rated critical and 209 rated high severity. The average CVSS score for CWE-732 vulnerabilities is 7.7.

External reference: View CWE-732 on MITRE CWE →

Monitor CWE-732 Vulnerabilities

Get alerted when new CWE-732 CVEs affect your infrastructure.

Start Monitoring Free