Skip to main content

CWE archive

CWE-732 CVEs

Programmatic archive

1,701 CVEs tagged with CWE-732140 Critical, 838 High, 623 Medium, 86 Low, 14 Unrated.

CVE-2025-14604

Published Mar 3, 2026

IBM Storage Scale IBM S through rage Scale 5.2.3.0 - 5.2.3.5, and IBM S through rage Scale 6.0.0.0 - 6.0.0.1 could allow a local user to unintentionally trigger additional permiss…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-2637

Published Mar 3, 2026

iBoysoft NTFS for Mac contains a local privilege escalation vulnerability in its privileged helper daemon ntfshelperd. The daemon exposes an NSConnection service that runs as root…

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-24834

Published Feb 19, 2026

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.27.0, an…

CVSS 9.3 · Critical
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2025-33088

Published Feb 17, 2026

IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to escalate their privileges due to incorrect file permissions for…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2026-23648

Published Feb 17, 2026

Glory RBG-100 recycler systems using the ISPK-08 software component contain multiple system binaries with overly permissive file permissions. Several binaries executed by the root…

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2019-25344

Published Feb 12, 2026

Wondershare MobileGo 8.5.0 contains an insecure file permissions vulnerability that allows local users to modify executable files in the application directory. Attackers can repla…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-25343

Published Feb 12, 2026

NextVPN 4.10 contains an insecure file permissions vulnerability that allows local users to modify executable files with full access rights. Attackers can replace system executabl…

CVSS 8.5 · High

CVE-2025-61969

Published Feb 11, 2026

Incorrect permission assignment in AMD µProf may allow a local user-privileged attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

CVSS 7.0 · High

CVE-2025-35999

Published Feb 10, 2026

Incorrect permission assignment for critical resource for some System Firmware Update Utility (SysFwUpdt) for Intel(R) Server Boards and Intel(R) Server Systems Based before versi…

CVSS 5.4 · Medium

CVE-2025-14740

Published Feb 4, 2026

Docker Desktop for Windows contains multiple incorrect permission assignment vulnerabilities in the installer's handling of the C:\ProgramData\DockerDesktop directory. The install…

CVSS 6.7 · Medium

CVE-2025-52627

Published Feb 3, 2026

Root File System Not Mounted as Read-Only configuration vulnerability. This can allow unintended modifications to critical system files, potentially increasing the risk of system…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-14988

Published Jan 27, 2026

A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain conditions. This may impact the confidentiality, integrity, o…

CVSS 10.0 · Critical

CVE-2020-36938

Published Jan 27, 2026

WinAVR version 20100110 contains an insecure permissions vulnerability that allows authenticated users to modify system files and executables. Attackers can leverage the overly pe…

CVSS 7.0 · High

CVE-2026-24131

Published Jan 26, 2026

pnpm is a package manager. Prior to version 10.28.2, when pnpm processes a package's `directories.bin` field, it uses `path.join()` without validating the result stays within the…

CVSS 6.7 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-0775

Published Jan 23, 2026

npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of npm…

CVSS 7.0 · High
evidence mentions
5
Buzz score
35.9

CVE-2026-22280

Published Jan 22, 2026

Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.10.1.3, versions starting from 9.11.0.0 and prior to 9.13.0.…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24049

Published Jan 22, 2026

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission mo…

CVSS 7.1 · High
evidence mentions
48
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2026-20092

Published Jan 21, 2026

A vulnerability in the read-only maintenance shell of Cisco Intersight Virtual Appliance could allow an authenticated, local attacker with administrative privileges to elevate pri…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Showing 126-150 of 1,701 CVEsPage 6 of 69