CWE-732 · 1,473 records
Incorrect Permission Assignment for Critical Resource
CVEs in this class
1,476 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
76This week | CVE-2019-15752Weaponized | Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exdocker · docker · CWE-732 | High7.8 | KEV | 48.6% | Aug 28, 2019 |
72This week | CVE-2022-22960Weaponized | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissiovmware · cloud foundation · CWE-732 | High7.8 | KEV | 35.5% | Apr 13, 2022 |
66This week | CVE-2011-3923Weaponized | Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary apache · struts · CWE-732 | Critical9.8 | — | 89.5% | Nov 1, 2019 |
58Plan | CVE-2018-13374Weaponized | A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtfortinet · fortiadc · CWE-732 | Medium4.3 | KEV | 37.8% | Jan 22, 2019 |
53Plan | CVE-2023-32986No exploit | Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File jenkins · file parameters · CWE-732 | High8.8 | — | 60.7% | May 16, 2023 |
49Plan | CVE-2017-16885Proof of concept | Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usfiberhome · lm53q1 firmware · CWE-732 | Critical9.8 | — | 33.5% | Jan 12, 2018 |
47Plan | CVE-2018-1000207No exploit | MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phptmodx · modx revolution · CWE-732 | High7.2 | — | 64.1% | Jul 13, 2018 |
43Plan | CVE-2018-4072No exploit | An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLinksierrawireless · airlink es450 firmware · CWE-732 | High8.8 | — | 26.4% | May 6, 2019 |
43Plan | CVE-2018-4073No exploit | An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLinksierrawireless · airlink es450 firmware · CWE-732 | High8.8 | — | 25.6% | May 6, 2019 |
43Plan | CVE-2018-10285Proof of concept | The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms.ericssonlg · ipecs nms · CWE-732 | Critical9.8 | — | 12.8% | Apr 22, 2018 |
43Plan | CVE-2018-1000226Proof of concept | Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versioncobblerd · cobbler · CWE-732 | Critical9.8 | — | 12.6% | Aug 20, 2018 |
42Plan | CVE-2020-11107Proof of concept | An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows.apachefriends · xampp · CWE-732 | High8.8 | — | 22.5% | Apr 2, 2020 |
42Plan | CVE-2022-43773No exploit | Hitachi Vantara Pentaho Business Analytics Server - Incorrect Permission Assignment for Critical Resourcehitachi · vantara pentaho business analytics server · CWE-732 | High8.8 | — | 22.2% | Apr 3, 2023 |
42Plan | CVE-2017-9462Weaponized | In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbimercurial · mercurial · CWE-732 | High8.8 | — | 21.7% | Jun 6, 2017 |
42Plan | CVE-2026-21902Proof of concept | Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as rootjuniper · junos os evolved · CWE-732 | Critical9.3 | — | 18.0% | Feb 25, 2026 |
41Plan | CVE-2018-14916Proof of concept | LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.loytec · lgate-902 firmware · CWE-732 | Critical9.1 | — | 17.2% | Jun 28, 2019 |
41Plan | CVE-2017-8857No exploit | In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated file copy and arbitrary remote commanveritas · netbackup · CWE-732 | Critical9.8 | — | 5.7% | May 9, 2017 |
40Plan | CVE-2019-7958No exploit | Creative Cloud Desktop Application versions 4.6.1 and earlier have an insecure inherited permissions vulnerability.adobe · creative cloud · CWE-732 | Critical9.8 | — | 4.4% | Aug 16, 2019 |
40Plan | CVE-2017-9602Proof of concept | KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component.kbvault mysql project · kbvault mysql · CWE-732 | Critical9.8 | — | 4.3% | Jun 16, 2017 |
40Plan | CVE-2019-8256No exploit | ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability.adobe · coldfusion · CWE-732 | Critical9.8 | — | 4.0% | Dec 19, 2019 |
40Plan | CVE-2020-9671No exploit | Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability.adobe · creative cloud desktop application · CWE-732 | Critical9.8 | — | 4.0% | Jul 16, 2020 |
40Plan | CVE-2020-28910No exploit | Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of snagios · nagios xi · CWE-732 | Critical9.8 | — | 3.9% | May 24, 2021 |
40Plan | CVE-2018-10381No exploit | TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service.mcafee · tunnelbear · CWE-732 | Critical9.8 | — | 3.8% | Apr 25, 2018 |
40Plan | CVE-2017-8856No exploit | In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated, arbitrary remote command execution uveritas · netbackup · CWE-732 | Critical9.8 | — | 3.8% | May 9, 2017 |
40Plan | CVE-2017-6950No exploit | SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAsap · gui for windows · CWE-732 | Critical9.8 | — | 3.8% | Mar 23, 2017 |
- CVE-2019-1575276This week
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.ex
HighCVSS 7.8KEVWeaponizedEPSS 49%docker · dockerAug 28, 2019
- CVE-2022-2296072This week
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissio
HighCVSS 7.8KEVWeaponizedEPSS 36%vmware · cloud foundationApr 13, 2022
- CVE-2011-392366This week
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary
CriticalCVSS 9.8WeaponizedEPSS 89%apache · strutsNov 1, 2019
- CVE-2018-1337458Plan
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obt
MediumCVSS 4.3KEVWeaponizedEPSS 38%fortinet · fortiadcJan 22, 2019
- CVE-2023-3298653Plan
Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File
HighCVSS 8.8No exploitEPSS 61%jenkins · file parametersMay 16, 2023
- CVE-2017-1688549Plan
Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Us
CriticalCVSS 9.8Proof of conceptEPSS 33%fiberhome · lm53q1 firmwareJan 12, 2018
- CVE-2018-100020747Plan
MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpt
HighCVSS 7.2No exploitEPSS 64%modx · modx revolutionJul 13, 2018
- CVE-2018-407243Plan
An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink
HighCVSS 8.8No exploitEPSS 26%sierrawireless · airlink es450 firmwareMay 6, 2019
- CVE-2018-407343Plan
An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink
HighCVSS 8.8No exploitEPSS 26%sierrawireless · airlink es450 firmwareMay 6, 2019
- CVE-2018-1028543Plan
The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms.
CriticalCVSS 9.8Proof of conceptEPSS 13%ericssonlg · ipecs nmsApr 22, 2018
- CVE-2018-100022643Plan
Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older version
CriticalCVSS 9.8Proof of conceptEPSS 13%cobblerd · cobblerAug 20, 2018
- CVE-2020-1110742Plan
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows.
HighCVSS 8.8Proof of conceptEPSS 22%apachefriends · xamppApr 2, 2020
- CVE-2022-4377342Plan
Hitachi Vantara Pentaho Business Analytics Server - Incorrect Permission Assignment for Critical Resource
HighCVSS 8.8No exploitEPSS 22%hitachi · vantara pentaho business analytics serverApr 3, 2023
- CVE-2017-946242Plan
In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbi
HighCVSS 8.8WeaponizedEPSS 22%mercurial · mercurialJun 6, 2017
- CVE-2026-2190242Plan
Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as root
CriticalCVSS 9.3Proof of conceptEPSS 18%juniper · junos os evolvedFeb 25, 2026
- CVE-2018-1491641Plan
LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.
CriticalCVSS 9.1Proof of conceptEPSS 17%loytec · lgate-902 firmwareJun 28, 2019
- CVE-2017-885741Plan
In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated file copy and arbitrary remote comman
CriticalCVSS 9.8No exploitEPSS 6%veritas · netbackupMay 9, 2017
- CVE-2019-795840Plan
Creative Cloud Desktop Application versions 4.6.1 and earlier have an insecure inherited permissions vulnerability.
CriticalCVSS 9.8No exploitEPSS 4%adobe · creative cloudAug 16, 2019
- CVE-2017-960240Plan
KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component.
CriticalCVSS 9.8Proof of conceptEPSS 4%kbvault mysql project · kbvault mysqlJun 16, 2017
- CVE-2019-825640Plan
ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability.
CriticalCVSS 9.8No exploitEPSS 4%adobe · coldfusionDec 19, 2019
- CVE-2020-967140Plan
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability.
CriticalCVSS 9.8No exploitEPSS 4%adobe · creative cloud desktop applicationJul 16, 2020
- CVE-2020-2891040Plan
Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of s
CriticalCVSS 9.8No exploitEPSS 4%nagios · nagios xiMay 24, 2021
- CVE-2018-1038140Plan
TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service.
CriticalCVSS 9.8No exploitEPSS 4%mcafee · tunnelbearApr 25, 2018
- CVE-2017-885640Plan
In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated, arbitrary remote command execution u
CriticalCVSS 9.8No exploitEPSS 4%veritas · netbackupMay 9, 2017
- CVE-2017-695040Plan
SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABA
CriticalCVSS 9.8No exploitEPSS 4%sap · gui for windowsMar 23, 2017