Skip to main content

CWE archive

CWE-276 CVEs

Programmatic archive

1,530 CVEs tagged with CWE-276118 Critical, 735 High, 616 Medium, 61 Low, 0 Unrated.

CVE-2025-13193

Published Nov 17, 2025

A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the gues…

CVSS 5.5 · Medium

CVE-2025-13131

Published Nov 13, 2025

A vulnerability was found in Sonarr 4.0.15.2940. The impacted element is an unknown function of the file C:\ProgramData\Sonarr\bin\Sonarr.Console.exe of the component Service. Per…

CVSS 8.5 · High

CVE-2025-13130

Published Nov 13, 2025

A vulnerability has been found in Radarr 5.28.0.10274. The affected element is an unknown function of the file C:\ProgramData\Radarr\bin\Radarr.Console.exe of the component Servic…

CVSS 8.5 · High

CVE-2025-8485

Published Nov 12, 2025

An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to execute code with elevated privileges during installation of…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-8421

Published Nov 12, 2025

An improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during installation, could allow an authenticated local user to red…

CVSS 5.2 · Medium

CVE-2025-61667

Published Nov 12, 2025

The Datadog Agent collects events and metrics from hosts and sends them to Datadog. A vulnerability within the Datadog Linux Host Agent versions 7.65.0 through 7.70.2 exists due t…

CVSS 7.0 · High

CVE-2025-11567

Published Nov 12, 2025

CWE-276: Incorrect Default Permissions vulnerability exists that could cause elevated system access when the target installation folder is not properly secured.

CVSS 7.3 · High

CVE-2025-32091

Published Nov 11, 2025

Incorrect default permissions in some firmware for the Intel(R) Arc(TM) B-series GPUs within Ring 1: Device Drivers may allow an escalation of privilege. System software adversary…

CVSS 8.4 · High

CVE-2025-31940

Published Nov 11, 2025

Incorrect default permissions for some Intel(R) Thread Director Visualizer software before version 1.1.1 within Ring 3: User Applications may allow an escalation of privilege. Unp…

CVSS 5.4 · Medium

CVE-2025-30518

Published Nov 11, 2025

Incorrect default permissions for some Intel(R) PresentMon before version 2.3.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software advers…

CVSS 5.4 · Medium

CVE-2025-27711

Published Nov 11, 2025

Incorrect default permissions for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within Ring 3: User Applications may allow an escalation of pr…

CVSS 5.4 · Medium

CVE-2025-27246

Published Nov 11, 2025

Incorrect default permissions for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may allow an escalation of privilege. System…

CVSS 5.4 · Medium

CVE-2025-13025

Published Nov 11, 2025

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-10918

Published Nov 11, 2025

Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary files anywhere on disk

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-64436

Published Nov 7, 2025

KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, such as the ability to update VM…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-43442

Published Nov 4, 2025

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app may be able to identify what…

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-43350

Published Nov 4, 2025

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker may be able to view restricted content from the lock s…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-8432

Published Oct 27, 2025

Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by CentreonBI user account on the MBI server This is…

CVSS 8.4 · High

CVE-2025-46185

Published Oct 24, 2025

An Insecure Permission vulnerability in pgcodekeeper 10.12.0 allows a local attacker to obtain sensitive information via the plaintext storage of passwords and usernames.

CVSS 6.2 · Medium

CVE-2025-12100

Published Oct 23, 2025

Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation.This issue affects BI Connector ODBC driver: from 1.0.0 through 1.4.6.

CVSS 8.8 · High

CVE-2025-57848

Published Oct 23, 2025

A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from the /etc/passwd file being created with group-writable per…

CVSS 6.4 · Medium

CVE-2025-23347

Published Oct 23, 2025

NVIDIA Project G-Assist contains a vulnerability where an attacker might be able to escalate permissions. A successful exploit of this vulnerability might lead to code execution,…

CVSS 7.8 · High

CVE-2025-11575

Published Oct 23, 2025

Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation.This issue affects MongoDB Atlas SQL ODBC driver: from 1.0.0 th…

CVSS 8.8 · High
Showing 126-150 of 1,530 CVEsPage 6 of 62