CWE-276 · 1,435 records
Incorrect Default Permissions
CVEs in this class
1,435 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
97Now | CVE-2013-0632Weaponized | administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitradobe · coldfusion · CWE-276 | Critical9.8 | KEV | 93.6% | Jan 16, 2013 |
61This week | CVE-2017-11610Weaponized | The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated ussupervisord · supervisor · CWE-276 | High8.8 | — | 87.4% | Aug 23, 2017 |
61This week | CVE-2026-87886Weaponized | Local privilege escalation due to insecure file permissions.acronis · acronis backup · CWE-276 | High7.8 | KEV | 0.2% | Sep 17, 2026 |
60This week | CVE-2022-22948Weaponized | The vCenter Server contains an information disclosure vulnerability due to improper permission of files.vmware · cloud foundation · CWE-276 | Medium6.5 | KEV | 13.3% | Mar 29, 2022 |
54Plan | CVE-2023-29919Proof of concept | SolarView Compact <= 6.0 is vulnerable to Insecure Permissions.contec · solarview compact firmware · CWE-276 | Critical9.1 | — | 60.2% | May 22, 2023 |
46Plan | CVE-2019-17124Proof of concept | Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.kramerav · viaware · CWE-276 | Critical9.8 | — | 22.5% | Oct 9, 2019 |
44Plan | CVE-2021-3437No exploit | Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of privilege and/or denhp · omen gaming hub · CWE-276 | Critical9.8 | — | 15.6% | Dec 12, 2022 |
43Plan | CVE-2024-57684No exploit | An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the Ddlink · dir-816 firmware · CWE-276 | Critical9.8 | — | 14.4% | Jan 16, 2025 |
42Plan | CVE-2020-12834No exploit | eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.rueq-3 · homematic ccu2 firmware · CWE-276 | Critical9.8 | — | 11.1% | May 15, 2020 |
42Plan | CVE-1999-0426Proof of concept | The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.suse · suse linux · CWE-276 | Critical9.8 | — | 10.8% | Mar 1, 1999 |
41Plan | CVE-2023-26918Proof of concept | Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be efilereplicationpro · file replication pro · CWE-276 | Critical9.8 | — | 6.1% | Apr 13, 2023 |
41Plan | CVE-2023-31067Proof of concept | An issue was discovered in TSplus Remote Access through 16.0.2.14.tsplus · tsplus remote access · CWE-276 | Critical9.8 | — | 5.5% | Sep 11, 2023 |
41Plan | CVE-2023-31068Proof of concept | An issue was discovered in TSplus Remote Access through 16.0.2.14.tsplus · tsplus remote work · CWE-276 | Critical9.8 | — | 5.4% | Sep 11, 2023 |
41Plan | CVE-2020-29492No exploit | Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability.dell · wyse thinos · CWE-276 | Critical10.0 | — | 1.7% | Jan 4, 2021 |
40Plan | CVE-2017-8625Proof of concept | Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to bypass Device Guard User Mode Code Intmicrosoft · internet explorer · CWE-276 | High8.8 | — | 15.3% | Aug 8, 2017 |
40Plan | CVE-2020-9039Proof of concept | Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the procouchbase · couchbase server · CWE-276 | Critical9.8 | — | 3.9% | Feb 21, 2020 |
40Plan | CVE-2021-36363No exploit | Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.nagios · nagios xi · CWE-276 | Critical9.8 | — | 3.8% | Sep 28, 2021 |
40Plan | CVE-2021-36365No exploit | Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.nagios · nagios xi · CWE-276 | Critical9.8 | — | 3.8% | Sep 28, 2021 |
40Plan | CVE-2020-9409No exploit | TIBCO JasperReports Server Fails To Enforce Access Restrictionstibco · jasperreports server · CWE-276 | Critical9.8 | — | 3.4% | May 20, 2020 |
40Plan | CVE-2021-39274No exploit | In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing an unprivileged user xerosecurity · sn1per · CWE-276 | Critical9.8 | — | 3.1% | Aug 19, 2021 |
40Plan | CVE-2019-19896No exploit | In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share.ixpdata · easyinstall · CWE-276 | Critical9.9 | — | 3.0% | Jan 23, 2020 |
40Plan | CVE-2021-45003No exploit | Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.nikhil-bhalerao · laundry booking management system · CWE-276 | Critical9.8 | — | 3.0% | Jan 10, 2022 |
40Plan | CVE-2020-13452No exploit | In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, thecodingmachine · gotenberg · CWE-276 | Critical9.8 | — | 2.7% | Jan 7, 2021 |
40Plan | CVE-2022-27773No exploit | A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elevivanti · endpoint manager · CWE-276 | Critical9.8 | — | 2.7% | Dec 5, 2022 |
40Plan | CVE-2019-12450No exploit | file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is gnome · glib · CWE-276 | Critical9.8 | — | 2.6% | May 29, 2019 |
- CVE-2013-063297Now
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitr
CriticalCVSS 9.8KEVWeaponizedEPSS 94%adobe · coldfusionJan 16, 2013
- CVE-2017-1161061This week
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated us
HighCVSS 8.8WeaponizedEPSS 87%supervisord · supervisorAug 23, 2017
- CVE-2026-8788661This week
Local privilege escalation due to insecure file permissions.
HighCVSS 7.8KEVWeaponizedEPSS 0%acronis · acronis backupSep 17, 2026
- CVE-2022-2294860This week
The vCenter Server contains an information disclosure vulnerability due to improper permission of files.
MediumCVSS 6.5KEVWeaponizedEPSS 13%vmware · cloud foundationMar 29, 2022
- CVE-2023-2991954Plan
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions.
CriticalCVSS 9.1Proof of conceptEPSS 60%contec · solarview compact firmwareMay 22, 2023
- CVE-2019-1712446Plan
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.
CriticalCVSS 9.8Proof of conceptEPSS 23%kramerav · viawareOct 9, 2019
- CVE-2021-343744Plan
Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of privilege and/or den
CriticalCVSS 9.8No exploitEPSS 16%hp · omen gaming hubDec 12, 2022
- CVE-2024-5768443Plan
An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the D
CriticalCVSS 9.8No exploitEPSS 14%dlink · dir-816 firmwareJan 16, 2025
- CVE-2020-1283442Plan
eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.ru
CriticalCVSS 9.8No exploitEPSS 11%eq-3 · homematic ccu2 firmwareMay 15, 2020
- CVE-1999-042642Plan
The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.
CriticalCVSS 9.8Proof of conceptEPSS 11%suse · suse linuxMar 1, 1999
- CVE-2023-2691841Plan
Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be e
CriticalCVSS 9.8Proof of conceptEPSS 6%filereplicationpro · file replication proApr 13, 2023
- CVE-2023-3106741Plan
An issue was discovered in TSplus Remote Access through 16.0.2.14.
CriticalCVSS 9.8Proof of conceptEPSS 5%tsplus · tsplus remote accessSep 11, 2023
- CVE-2023-3106841Plan
An issue was discovered in TSplus Remote Access through 16.0.2.14.
CriticalCVSS 9.8Proof of conceptEPSS 5%tsplus · tsplus remote workSep 11, 2023
- CVE-2020-2949241Plan
Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability.
CriticalCVSS 10.0No exploitEPSS 2%dell · wyse thinosJan 4, 2021
- CVE-2017-862540Plan
Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to bypass Device Guard User Mode Code Int
HighCVSS 8.8Proof of conceptEPSS 15%microsoft · internet explorerAug 8, 2017
- CVE-2020-903940Plan
Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the pro
CriticalCVSS 9.8Proof of conceptEPSS 4%couchbase · couchbase serverFeb 21, 2020
- CVE-2021-3636340Plan
Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.
CriticalCVSS 9.8No exploitEPSS 4%nagios · nagios xiSep 28, 2021
- CVE-2021-3636540Plan
Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.
CriticalCVSS 9.8No exploitEPSS 4%nagios · nagios xiSep 28, 2021
- CVE-2020-940940Plan
TIBCO JasperReports Server Fails To Enforce Access Restrictions
CriticalCVSS 9.8No exploitEPSS 3%tibco · jasperreports serverMay 20, 2020
- CVE-2021-3927440Plan
In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing an unprivileged user
CriticalCVSS 9.8No exploitEPSS 3%xerosecurity · sn1perAug 19, 2021
- CVE-2019-1989640Plan
In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share.
CriticalCVSS 9.9No exploitEPSS 3%ixpdata · easyinstallJan 23, 2020
- CVE-2021-4500340Plan
Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.
CriticalCVSS 9.8No exploitEPSS 3%nikhil-bhalerao · laundry booking management systemJan 10, 2022
- CVE-2020-1345240Plan
In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file,
CriticalCVSS 9.8No exploitEPSS 3%thecodingmachine · gotenbergJan 7, 2021
- CVE-2022-2777340Plan
A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elev
CriticalCVSS 9.8No exploitEPSS 3%ivanti · endpoint managerDec 5, 2022
- CVE-2019-1245040Plan
file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is
CriticalCVSS 9.8No exploitEPSS 3%gnome · glibMay 29, 2019