CWE-732: CWE-732

313
Total CVEs
41
Critical
209
High
7.7
Avg CVSS

Yearly Trend

2026
19
2025
111
2024
57
2023
40
2022
26

Top Affected Vendors

1 Google 11
2 Oracle 11
3 Siemens 9
4 Apple 7
5 Nagios 7
6 Ibm 7
7 Intel 7
8 Sap 5
9 Dell 5
10 Trendmicro 4

All CWE-732 CVEs (313)

CVE-2025-21583
4.9

This vulnerability in Oracle MySQL Server allows high-privileged attackers with network access to cause a denial of service (DoS) by crashing or hangi...

Apr 15, 2025
CVE-2024-32014
4.7

This vulnerability in Siemens Spectrum Power 4 allows attackers to modify the local database containing application credentials, potentially gaining a...

Nov 11, 2025
CVE-2025-11790
4.4

Acronis Cyber Protect Cloud Agent fails to delete credentials after plan revocation, leaving authentication data accessible. This affects all platform...

Mar 6, 2026
CVE-2025-34135
4.4

Nagios XI versions before 2024R1.4.2 have overly permissive systemd unit file permissions, specifically on nagios.service. This allows local attackers...

Oct 30, 2025
CVE-2024-27883
4.4

This CVE describes a macOS permissions vulnerability where applications can bypass file system protections and modify restricted areas. It affects mac...

Jul 29, 2024
CVE-2025-8148
4.2

This vulnerability allows Web Users in Fortra's GoAnywhere MFT who are configured for password-only SFTP authentication to bypass this restriction and...

Dec 5, 2025
CVE-2024-54159
4.1

CVE-2024-54159 is a local privilege escalation vulnerability in stalld (Starving CPUs and Latency Daemon) that allows local users to overwrite arbitra...

Nov 29, 2024
CVE-2025-40818
3.3

SINEMA Remote Connect Server versions before V3.2 SP4 store SSL/TLS private keys with insufficient protection, allowing any authenticated user with se...

Dec 9, 2025
CVE-2025-68462
3.2

Freedombox versions before 25.17.1 have improper permissions on the backups-data directory, allowing unauthorized users to read database dump files. T...

Dec 18, 2025
CVE-2025-14988
N/A

This CVE describes an insecure permission vulnerability in ibaPDA software that could allow attackers to perform unauthorized file system operations. ...

Jan 27, 2026
CVE-2025-69426
N/A

CVE-2025-69426 allows attackers to exploit hardcoded SSH credentials in Ruckus vRIoT IoT Controller firmware to gain root access through Docker contai...

Jan 9, 2026
CVE-2025-14979
N/A

AirVPN Eddie on macOS contains an insecure XPC service that allows local, unprivileged users to escalate privileges to root. This affects Eddie versio...

Jan 6, 2026
CVE-2025-59373
N/A

A local privilege escalation vulnerability in ASUS System Control Interface allows unprivileged users to copy files into protected system paths withou...

Nov 25, 2025

About CWE-732 (CWE-732)

Our database tracks 313 CVEs classified as CWE-732, with 41 rated critical and 209 rated high severity. The average CVSS score for CWE-732 vulnerabilities is 7.7.

External reference: View CWE-732 on MITRE CWE →

Monitor CWE-732 Vulnerabilities

Get alerted when new CWE-732 CVEs affect your infrastructure.

Start Monitoring Free