Skip to content
Noroxi

CWE-281 · 321 records

Improper Preservation of Permissions

CVEs in this class

325 records

  • Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Win

    CriticalCVSS 9.8KEVWeaponizedEPSS 74%

    microsoft · windows 10 1507Jun 14, 2017

  • An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.

    HighCVSS 7.5No exploitEPSS 68%

    apache · strutsSep 14, 2020

  • Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 15

    CriticalCVSS 9.8No exploitEPSS 26%

    microsoft · windows 10Jul 11, 2017

  • Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists.

    CriticalCVSS 9.8Proof of conceptEPSS 12%

    liferay · liferay portalApr 16, 2023

  • Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Sp

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    vmware · spring securityJul 19, 2023

  • An issue was discovered in certain Apple products.

    CriticalCVSS 9.8No exploitEPSS 2%

    apple · iphone osApr 3, 2018

  • Insecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's t

    CriticalCVSS 10.0No exploitEPSS 0%

    Jun 21, 2024

  • Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via

    CriticalCVSS 9.8No exploitEPSS 2%

    puppycms · puppycmsMay 6, 2021

  • Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a cra

    CriticalCVSS 9.8No exploitEPSS 1%

    gl-inet · gl-ax1800 firmwareNov 30, 2023

  • Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code via a crafted .php fi

    CriticalCVSS 9.8No exploitEPSS 1%

    thecontrolgroup · voyagerApr 26, 2023

  • If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port

    CriticalCVSS 9.8No exploitEPSS 1%

    mozilla · firefoxAug 5, 2021

  • A logic issue was addressed with improved state management.

    CriticalCVSS 9.8No exploitEPSS 1%

    apple · macosDec 11, 2024

  • Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitrary

    CriticalCVSS 9.8No exploitEPSS 1%

    Feb 14, 2025

  • Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled.

    CriticalCVSS 9.8No exploitEPSS 1%

    jenkins · role-based authorization strategyApr 2, 2023

  • Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit

    CriticalCVSS 9.8No exploitEPSS 1%

    openrobotics · robot operating systemDec 6, 2024

  • Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit

    CriticalCVSS 9.8No exploitEPSS 1%

    openrobotics · robot operating systemDec 6, 2024

  • Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit

    CriticalCVSS 9.8No exploitEPSS 1%

    openrobotics · robot operating systemDec 6, 2024

  • Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit

    CriticalCVSS 9.8No exploitEPSS 1%

    openrobotics · robot operating systemDec 6, 2024

  • An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.

    CriticalCVSS 9.8No exploitEPSS 1%

    codeastro · complaint management systemJan 3, 2025

  • An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software 7.0.x before 7.0.38, 7.1.x before 7.1.11, 8

    CriticalCVSS 9.8No exploitEPSS 1%

    Jan 6, 2025

  • Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit

    CriticalCVSS 9.8No exploitEPSS 0%

    openrobotics · robot operating systemDec 6, 2024

  • Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit

    CriticalCVSS 9.8No exploitEPSS 0%

    openrobotics · robot operating systemDec 6, 2024

  • Object state limitation has no effect

    CriticalCVSS 9.5No exploit

    Packagist · ibexa/coreApr 29, 2022

  • Object state limitation has no effect

    CriticalCVSS 9.5No exploit

    Packagist · ezsystems/ezplatform-kernelApr 29, 2022

  • Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via expose

    CriticalCVSS 9.1Proof of conceptEPSS 2%

    Jan 13, 2025

All vulnerability classes