Skip to content
Noroxi

CWE-732 · 1,473 records

Incorrect Permission Assignment for Critical Resource

CVEs in this class

1,476 records

  • CVE-2019-15752
    76This week

    Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.ex

    HighCVSS 7.8KEVWeaponizedEPSS 49%

    docker · dockerAug 28, 2019

  • CVE-2022-22960
    72This week

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissio

    HighCVSS 7.8KEVWeaponizedEPSS 36%

    vmware · cloud foundationApr 13, 2022

  • CVE-2011-3923
    66This week

    Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary

    CriticalCVSS 9.8WeaponizedEPSS 89%

    apache · strutsNov 1, 2019

  • A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obt

    MediumCVSS 4.3KEVWeaponizedEPSS 38%

    fortinet · fortiadcJan 22, 2019

  • Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File

    HighCVSS 8.8No exploitEPSS 61%

    jenkins · file parametersMay 16, 2023

  • Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Us

    CriticalCVSS 9.8Proof of conceptEPSS 33%

    fiberhome · lm53q1 firmwareJan 12, 2018

  • MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpt

    HighCVSS 7.2No exploitEPSS 64%

    modx · modx revolutionJul 13, 2018

  • An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink

    HighCVSS 8.8No exploitEPSS 26%

    sierrawireless · airlink es450 firmwareMay 6, 2019

  • An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink

    HighCVSS 8.8No exploitEPSS 26%

    sierrawireless · airlink es450 firmwareMay 6, 2019

  • The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms.

    CriticalCVSS 9.8Proof of conceptEPSS 13%

    ericssonlg · ipecs nmsApr 22, 2018

  • Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older version

    CriticalCVSS 9.8Proof of conceptEPSS 13%

    cobblerd · cobblerAug 20, 2018

  • An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows.

    HighCVSS 8.8Proof of conceptEPSS 22%

    apachefriends · xamppApr 2, 2020

  • Hitachi Vantara Pentaho Business Analytics Server - Incorrect Permission Assignment for Critical Resource

    HighCVSS 8.8No exploitEPSS 22%

    hitachi · vantara pentaho business analytics serverApr 3, 2023

  • In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbi

    HighCVSS 8.8WeaponizedEPSS 22%

    mercurial · mercurialJun 6, 2017

  • Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as root

    CriticalCVSS 9.3Proof of conceptEPSS 18%

    juniper · junos os evolvedFeb 25, 2026

  • LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.

    CriticalCVSS 9.1Proof of conceptEPSS 17%

    loytec · lgate-902 firmwareJun 28, 2019

  • In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated file copy and arbitrary remote comman

    CriticalCVSS 9.8No exploitEPSS 6%

    veritas · netbackupMay 9, 2017

  • Creative Cloud Desktop Application versions 4.6.1 and earlier have an insecure inherited permissions vulnerability.

    CriticalCVSS 9.8No exploitEPSS 4%

    adobe · creative cloudAug 16, 2019

  • KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component.

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    kbvault mysql project · kbvault mysqlJun 16, 2017

  • ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability.

    CriticalCVSS 9.8No exploitEPSS 4%

    adobe · coldfusionDec 19, 2019

  • Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability.

    CriticalCVSS 9.8No exploitEPSS 4%

    adobe · creative cloud desktop applicationJul 16, 2020

  • Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of s

    CriticalCVSS 9.8No exploitEPSS 4%

    nagios · nagios xiMay 24, 2021

  • TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service.

    CriticalCVSS 9.8No exploitEPSS 4%

    mcafee · tunnelbearApr 25, 2018

  • In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated, arbitrary remote command execution u

    CriticalCVSS 9.8No exploitEPSS 4%

    veritas · netbackupMay 9, 2017

  • SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABA

    CriticalCVSS 9.8No exploitEPSS 4%

    sap · gui for windowsMar 23, 2017

All vulnerability classes