Skip to main content

CWE archive

CWE-732 CVEs

Programmatic archive

1,701 CVEs tagged with CWE-732140 Critical, 838 High, 623 Medium, 86 Low, 14 Unrated.

CVE-2025-12985

Published Jan 20, 2026

IBM Licensing Operator incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the IBM Licensing Operator im…

CVSS 8.4 · High

CVE-2021-47756

Published Jan 16, 2026

Laravel Valet versions 1.1.4 to 2.0.3 contain a local privilege escalation vulnerability that allows users to modify the valet command with root privileges. Attackers can edit the…

CVSS 8.4 · High

CVE-2025-59961

Published Jan 15, 2026

An Incorrect Permission Assignment for Critical Resource vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-pr…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-67246

Published Jan 15, 2026

A local information disclosure vulnerability exists in the Ludashi driver before 5.1025 due to a lack of access control in the IOCTL handler. This driver exposes a device interfac…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-50931

Published Jan 13, 2026

TeamSpeak 3.5.6 contains an insecure file permissions vulnerability that allows local attackers to replace executable files with malicious binaries. Attackers can replace system e…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-69426

Published Jan 9, 2026

The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user account within an initialization script. The SSH…

CVSS 10.0 · Critical

CVE-2025-14979

Published Jan 6, 2026

AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.This issue affects Eddie: 2.24.6.

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36916

Published Jan 6, 2026

TDM Digital Signage PC Player 4.1.0.4 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files. Attackers can leverage the 'Mod…

CVSS 8.5 · High

CVE-2021-47742

Published Dec 31, 2025

Epic Games Psyonix Rocket League <=1.95 contains an insecure permissions vulnerability that allows authenticated users to modify executable files with full access permissions. Att…

CVSS 8.5 · High

CVE-2025-64699

Published Dec 31, 2025

An incorrect NULL DACL issue exists in SevenCs ORCA G2 2.0.1.35 (EC2007 Kernel v5.22). The regService process, which runs with SYSTEM privileges, applies a Security Descriptor to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-25245

Published Dec 24, 2025

Ross Video DashBoard 8.5.1 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files due to improper permission settings. Attack…

CVSS 8.5 · High

CVE-2025-13703

Published Dec 23, 2025

VIPRE Advanced Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected inst…

CVSS 7.8 · High

CVE-2022-50690

Published Dec 22, 2025

Wondershare MirrorGo 2.0.11.346 contains a local privilege escalation vulnerability due to incorrect file permissions on executable files. Unprivileged local users can replace the…

CVSS 8.5 · High

CVE-2023-53949

Published Dec 19, 2025

AspEmail 5.6.0.2 contains a binary permission vulnerability that allows local users to escalate privileges through the Persits Software EmailAgent service. Attackers can exploit f…

CVSS 8.5 · High

CVE-2025-68462

Published Dec 18, 2025

Freedombox before 25.17.1 does not set proper permissions for the backups-data directory, allowing the reading of dump files of databases.

CVSS 3.2 · Low

CVE-2025-67794

Published Dec 17, 2025

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 before 24.2.8, and 25.1 before 25.1.6. Directories and files created by the agent are created with overly permissive…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-46062

Published Dec 17, 2025

Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writab…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46060

Published Dec 17, 2025

Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writabl…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-34288

Published Dec 16, 2025

Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and application file permissions. A user‑ac…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-43470

Published Dec 12, 2025

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. A standard user may be able to view files made from a disk image belonging…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-13733

Published Dec 12, 2025

BuhoNTFS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via insecure functions.This issue affects BuhoNTFS: 1.3.2.

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-40818

Published Dec 9, 2025

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications contain private SSL/TLS keys on the server that are not proper…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort
Showing 151-175 of 1,701 CVEsPage 7 of 69