Skip to content
Noroxi

CWE-276 · 1,435 records

Incorrect Default Permissions

CVEs in this class

1,435 records

  • administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitr

    CriticalCVSS 9.8KEVWeaponizedEPSS 94%

    adobe · coldfusionJan 16, 2013

  • CVE-2017-11610
    61This week

    The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated us

    HighCVSS 8.8WeaponizedEPSS 87%

    supervisord · supervisorAug 23, 2017

  • CVE-2026-87886
    61This week

    Local privilege escalation due to insecure file permissions.

    HighCVSS 7.8KEVWeaponizedEPSS 0%

    acronis · acronis backupSep 17, 2026

  • CVE-2022-22948
    60This week

    The vCenter Server contains an information disclosure vulnerability due to improper permission of files.

    MediumCVSS 6.5KEVWeaponizedEPSS 13%

    vmware · cloud foundationMar 29, 2022

  • SolarView Compact <= 6.0 is vulnerable to Insecure Permissions.

    CriticalCVSS 9.1Proof of conceptEPSS 60%

    contec · solarview compact firmwareMay 22, 2023

  • Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.

    CriticalCVSS 9.8Proof of conceptEPSS 23%

    kramerav · viawareOct 9, 2019

  • Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of privilege and/or den

    CriticalCVSS 9.8No exploitEPSS 16%

    hp · omen gaming hubDec 12, 2022

  • An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the D

    CriticalCVSS 9.8No exploitEPSS 14%

    dlink · dir-816 firmwareJan 16, 2025

  • eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.ru

    CriticalCVSS 9.8No exploitEPSS 11%

    eq-3 · homematic ccu2 firmwareMay 15, 2020

  • The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.

    CriticalCVSS 9.8Proof of conceptEPSS 11%

    suse · suse linuxMar 1, 1999

  • Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be e

    CriticalCVSS 9.8Proof of conceptEPSS 6%

    filereplicationpro · file replication proApr 13, 2023

  • An issue was discovered in TSplus Remote Access through 16.0.2.14.

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    tsplus · tsplus remote accessSep 11, 2023

  • An issue was discovered in TSplus Remote Access through 16.0.2.14.

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    tsplus · tsplus remote workSep 11, 2023

  • Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability.

    CriticalCVSS 10.0No exploitEPSS 2%

    dell · wyse thinosJan 4, 2021

  • Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to bypass Device Guard User Mode Code Int

    HighCVSS 8.8Proof of conceptEPSS 15%

    microsoft · internet explorerAug 8, 2017

  • Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the pro

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    couchbase · couchbase serverFeb 21, 2020

  • Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.

    CriticalCVSS 9.8No exploitEPSS 4%

    nagios · nagios xiSep 28, 2021

  • Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.

    CriticalCVSS 9.8No exploitEPSS 4%

    nagios · nagios xiSep 28, 2021

  • TIBCO JasperReports Server Fails To Enforce Access Restrictions

    CriticalCVSS 9.8No exploitEPSS 3%

    tibco · jasperreports serverMay 20, 2020

  • In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing an unprivileged user

    CriticalCVSS 9.8No exploitEPSS 3%

    xerosecurity · sn1perAug 19, 2021

  • In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share.

    CriticalCVSS 9.9No exploitEPSS 3%

    ixpdata · easyinstallJan 23, 2020

  • Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.

    CriticalCVSS 9.8No exploitEPSS 3%

    nikhil-bhalerao · laundry booking management systemJan 10, 2022

  • In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file,

    CriticalCVSS 9.8No exploitEPSS 3%

    thecodingmachine · gotenbergJan 7, 2021

  • A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elev

    CriticalCVSS 9.8No exploitEPSS 3%

    ivanti · endpoint managerDec 5, 2022

  • file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is

    CriticalCVSS 9.8No exploitEPSS 3%

    gnome · glibMay 29, 2019

All vulnerability classes