CWE-281 · 321 records
Improper Preservation of Permissions
CVEs in this class
325 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
91Now | CVE-2017-8543Weaponized | Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Winmicrosoft · windows 10 1507 · CWE-281 | Critical9.8 | KEV | 74.2% | Jun 14, 2017 |
50Plan | CVE-2019-0233No exploit | An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.apache · struts · CWE-281 | High7.5 | — | 68.1% | Sep 14, 2020 |
47Plan | CVE-2017-8589No exploit | Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 15microsoft · windows 10 · CWE-281 | Critical9.8 | — | 26.2% | Jul 11, 2017 |
43Plan | CVE-2021-33990Proof of concept | Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists.liferay · liferay portal · CWE-281 | Critical9.8 | — | 11.9% | Apr 16, 2023 |
40Plan | CVE-2023-34034Proof of concept | Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spvmware · spring security · CWE-281 | Critical9.8 | — | 4.0% | Jul 19, 2023 |
40Plan | CVE-2018-4115No exploit | An issue was discovered in certain Apple products.apple · iphone os · CWE-281 | Critical9.8 | — | 2.2% | Apr 3, 2018 |
40Plan | CVE-2024-36532No exploit | Insecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's tCWE-281 | Critical10.0 | — | 0.5% | Jun 21, 2024 |
39Monitor | CVE-2020-18890No exploit | Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via puppycms · puppycms · CWE-281 | Critical9.8 | — | 1.5% | May 6, 2021 |
39Monitor | CVE-2023-47463No exploit | Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a cragl-inet · gl-ax1800 firmware · CWE-281 | Critical9.8 | — | 1.3% | Nov 30, 2023 |
39Monitor | CVE-2020-36070No exploit | Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code via a crafted .php fithecontrolgroup · voyager · CWE-281 | Critical9.8 | — | 1.1% | Apr 26, 2023 |
39Monitor | CVE-2021-29971No exploit | If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port mozilla · firefox · CWE-281 | Critical9.8 | — | 1.0% | Aug 5, 2021 |
39Monitor | CVE-2024-54465No exploit | A logic issue was addressed with improved state management.apple · macos · CWE-281 | Critical9.8 | — | 0.9% | Dec 11, 2024 |
39Monitor | CVE-2024-56973No exploit | Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitraryCWE-281 | Critical9.8 | — | 0.9% | Feb 14, 2025 |
39Monitor | CVE-2023-28668No exploit | Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled.jenkins · role-based authorization strategy · CWE-281 | Critical9.8 | — | 0.8% | Apr 2, 2023 |
39Monitor | CVE-2024-41646No exploit | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitopenrobotics · robot operating system · CWE-281 | Critical9.8 | — | 0.7% | Dec 6, 2024 |
39Monitor | CVE-2024-41649No exploit | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitopenrobotics · robot operating system · CWE-281 | Critical9.8 | — | 0.7% | Dec 6, 2024 |
39Monitor | CVE-2024-41645No exploit | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitopenrobotics · robot operating system · CWE-281 | Critical9.8 | — | 0.7% | Dec 6, 2024 |
39Monitor | CVE-2024-41644No exploit | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitopenrobotics · robot operating system · CWE-281 | Critical9.8 | — | 0.7% | Dec 6, 2024 |
39Monitor | CVE-2024-55507No exploit | An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.codeastro · complaint management system · CWE-281 | Critical9.8 | — | 0.6% | Jan 3, 2025 |
39Monitor | CVE-2024-46622No exploit | An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software 7.0.x before 7.0.38, 7.1.x before 7.1.11, 8CWE-281 | Critical9.8 | — | 0.6% | Jan 6, 2025 |
39Monitor | CVE-2024-41648No exploit | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitopenrobotics · robot operating system · CWE-281 | Critical9.8 | — | 0.5% | Dec 6, 2024 |
39Monitor | CVE-2024-41650No exploit | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitopenrobotics · robot operating system · CWE-281 | Critical9.8 | — | 0.5% | Dec 6, 2024 |
38Monitor | GHSA-gvj8-4cj4-h776No exploit | Object state limitation has no effectPackagist · ibexa/core · CWE-281 | Critical9.5 | — | — | Apr 29, 2022 |
38Monitor | GHSA-w8qp-hmh5-4v9vNo exploit | Object state limitation has no effectPackagist · ezsystems/ezplatform-kernel · CWE-281 | Critical9.5 | — | — | Apr 29, 2022 |
37Monitor | CVE-2024-46310Proof of concept | Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via exposeCWE-281 | Critical9.1 | — | 2.5% | Jan 13, 2025 |
- CVE-2017-854391Now
Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Win
CriticalCVSS 9.8KEVWeaponizedEPSS 74%microsoft · windows 10 1507Jun 14, 2017
- CVE-2019-023350Plan
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
HighCVSS 7.5No exploitEPSS 68%apache · strutsSep 14, 2020
- CVE-2017-858947Plan
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 15
CriticalCVSS 9.8No exploitEPSS 26%microsoft · windows 10Jul 11, 2017
- CVE-2021-3399043Plan
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists.
CriticalCVSS 9.8Proof of conceptEPSS 12%liferay · liferay portalApr 16, 2023
- CVE-2023-3403440Plan
Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Sp
CriticalCVSS 9.8Proof of conceptEPSS 4%vmware · spring securityJul 19, 2023
- CVE-2018-411540Plan
An issue was discovered in certain Apple products.
CriticalCVSS 9.8No exploitEPSS 2%apple · iphone osApr 3, 2018
- CVE-2024-3653240Plan
Insecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's t
CriticalCVSS 10.0No exploitEPSS 0%Jun 21, 2024
- CVE-2020-1889039Monitor
Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via
CriticalCVSS 9.8No exploitEPSS 2%puppycms · puppycmsMay 6, 2021
- CVE-2023-4746339Monitor
Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a cra
CriticalCVSS 9.8No exploitEPSS 1%gl-inet · gl-ax1800 firmwareNov 30, 2023
- CVE-2020-3607039Monitor
Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code via a crafted .php fi
CriticalCVSS 9.8No exploitEPSS 1%thecontrolgroup · voyagerApr 26, 2023
- CVE-2021-2997139Monitor
If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port
CriticalCVSS 9.8No exploitEPSS 1%mozilla · firefoxAug 5, 2021
- CVE-2024-5446539Monitor
A logic issue was addressed with improved state management.
CriticalCVSS 9.8No exploitEPSS 1%apple · macosDec 11, 2024
- CVE-2024-5697339Monitor
Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitrary
CriticalCVSS 9.8No exploitEPSS 1%Feb 14, 2025
- CVE-2023-2866839Monitor
Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled.
CriticalCVSS 9.8No exploitEPSS 1%jenkins · role-based authorization strategyApr 2, 2023
- CVE-2024-4164639Monitor
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit
CriticalCVSS 9.8No exploitEPSS 1%openrobotics · robot operating systemDec 6, 2024
- CVE-2024-4164939Monitor
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit
CriticalCVSS 9.8No exploitEPSS 1%openrobotics · robot operating systemDec 6, 2024
- CVE-2024-4164539Monitor
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit
CriticalCVSS 9.8No exploitEPSS 1%openrobotics · robot operating systemDec 6, 2024
- CVE-2024-4164439Monitor
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit
CriticalCVSS 9.8No exploitEPSS 1%openrobotics · robot operating systemDec 6, 2024
- CVE-2024-5550739Monitor
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.
CriticalCVSS 9.8No exploitEPSS 1%codeastro · complaint management systemJan 3, 2025
- CVE-2024-4662239Monitor
An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software 7.0.x before 7.0.38, 7.1.x before 7.1.11, 8
CriticalCVSS 9.8No exploitEPSS 1%Jan 6, 2025
- CVE-2024-4164839Monitor
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit
CriticalCVSS 9.8No exploitEPSS 0%openrobotics · robot operating systemDec 6, 2024
- CVE-2024-4165039Monitor
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit
CriticalCVSS 9.8No exploitEPSS 0%openrobotics · robot operating systemDec 6, 2024
- GHSA-gvj8-4cj4-h77638Monitor
Object state limitation has no effect
CriticalCVSS 9.5No exploitPackagist · ibexa/coreApr 29, 2022
- GHSA-w8qp-hmh5-4v9v38Monitor
Object state limitation has no effect
CriticalCVSS 9.5No exploitPackagist · ezsystems/ezplatform-kernelApr 29, 2022
- CVE-2024-4631037Monitor
Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via expose
CriticalCVSS 9.1Proof of conceptEPSS 2%Jan 13, 2025