CWE-276— Incorrect Default Permissions
1,613 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 27 of 33
- CVE-2024-49504HIGHCVSS 7.0EG 0.02024-11-13
grub2 allowed attackers with access to the grub shell to access files on the encrypted disks.
- CVE-2024-49724HIGHCVSS 7.0EG 7.02025-01-21
In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected activities due to a race condition. This could lead to local escalation of privilege with no additional execution privi…
- CVE-2024-49732HIGHCVSS 7.8EG 7.82025-01-21
In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution…
- CVE-2024-49735HIGHCVSS 7.8EG 7.82025-01-21
In multiple locations, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed …
- CVE-2024-49736MEDIUMCVSS 5.5EG 7.82025-01-21
In onClick of MainClear.java, there is a possible way to trigger factory reset without explicit user consent due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User …
- CVE-2024-49737HIGHCVSS 7.8EG 7.82025-01-21
In applyTaskFragmentOperation of WindowOrganizerController.java, there is a possible way to launch arbitrary activities as the system UID due to a logic error in the code. This could lead to local escalation of privilege with no additional…
- CVE-2024-49742HIGHCVSS 7.8EG 7.82025-01-21
In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification access in Settings due to a missing permission check. This could lead to local escalation of privilege with no additional…
- CVE-2024-49744HIGHCVSS 7.8EG 7.82025-01-21
In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass parcel mismatch mitigation due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution p…
- CVE-2024-50590HIGHCVSS 7.8EG 7.82024-11-08
Attackers with local access to the medical office computer can escalate their Windows user privileges to "NT AUTHORITY\SYSTEM" by overwriting one of two Elefant service binaries with weak permissions. The default installation directory …
- CVE-2024-50657MEDIUMCVSS 6.8EG 6.82024-11-22
An issue in Owncloud android apk v.4.3.1 allows a physically proximate attacker to escalate privileges via the PassCodeViewModel class, specifically in the checkPassCodeIsValid method
- CVE-2024-51051CRITICALCVSS 9.8EG 9.82024-11-18
AVSCMS v8.2.0 was discovered to contain weak default credentials for the Administrator account.
- CVE-2024-51162HIGHCVSS 8.8EG 9.82024-11-20
An issue in Audimex EE versions 15.1.20 and earlier allowing a remote attacker to escalate privileges. Analyzing the offline client code, it was identified that it is possible for any user (with any privilege) of Audimex to dump the whole …
- CVE-2024-51378CRITICALCVSS 10.0EG 10.0⚠ KEV2024-10-29
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secM…
- CVE-2024-51440HIGHCVSS 7.8EG 7.82025-02-12
An issue in Nothing Tech Nothing OS v.2.6 allows a local attacker to escalate privileges via the NtBpfService component.
- CVE-2024-51567CRITICALCVSS 10.0EG 10.0⚠ KEV2024-10-29
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which is …
- CVE-2024-51764MEDIUMCVSS 5.5EG 5.52024-11-15
A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.
- CVE-2024-51765MEDIUMCVSS 5.5EG 5.52024-11-15
A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.
- CVE-2024-52323HIGHCVSS 8.1EG 8.12024-11-27
Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve sensitive tokens associated to the org-admin account.
- CVE-2024-52551HIGHCVSS 8.0EG 8.02024-11-13
Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Build permission to res…
- CVE-2024-52783MEDIUMCVSS 5.1EG 5.12025-01-15
Insecure permissions in the XNetSocketClient component of XINJE XDPPro.exe v3.2.2 to v3.7.17c allows attackers to execute arbitrary code via modification of the configuration file.
- CVE-2024-52867HIGHCVSS 8.1EG 8.12024-11-17
guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users before file metadata concerns (e.g., for setuid and setgid programs) are properly addressed. The vulnerability can be re…
- CVE-2024-52926MEDIUMCVSS 6.5EG 7.32024-11-18
Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.
- CVE-2024-52946HIGHCVSS 8.8EG 8.82024-11-18
An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment…
- CVE-2024-5321MEDIUMCVSS 6.1EG 6.12024-07-18
A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may be able to modify container logs.
- CVE-2024-53351CRITICALCVSS 9.8EG 9.82025-03-21
Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalation of privileges.
- CVE-2024-53835HIGHCVSS 7.8EG 7.82025-01-03
there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2024-53840HIGHCVSS 7.8EG 7.82025-01-03
there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2024-53841HIGHCVSS 7.8EG 7.82025-01-03
In startListeningForDeviceStateChanges, there is a possible Permission Bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp…
- CVE-2024-53921LOWCVSS 2.8EG 2.82024-12-03
An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders in the system permission directory via a symbolic link during the installation process.
- CVE-2024-54131HIGHCVSS 7.3EG 0.02024-12-03
The Kolide Agent (aka: Launcher) is the lightweight agent designed to work with Kolide's service. An implementation bug in the Kolide Agent (known as `launcher`) allows for local privilege escalation to the SYSTEM user on Windows 10 and 11…
- CVE-2024-54564MEDIUMCVSS 6.5EG 6.52025-03-21
This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, visionOS 1.3. A file received from AirDrop may not have the quarantine flag applied.
- CVE-2024-5474MEDIUMCVSS 5.5EG 5.52024-10-11
A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacker to read files on the system with elevated privileges durin…
- CVE-2024-54745CRITICALCVSS 9.8EG 9.82024-12-06
WAVLINK WN701AE M01AE_V240305 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
- CVE-2024-54747CRITICALCVSS 9.8EG 9.82024-12-06
WAVLINK WN531P3 202383 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
- CVE-2024-54751CRITICALCVSS 9.8EG 9.82024-12-10
COMFAST CF-WR630AX v2.7.0.2 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
- CVE-2024-55215CRITICALCVSS 9.8EG 9.82025-02-07
An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization interface /auth/register.
- CVE-2024-55225CRITICALCVSS 9.8EG 9.82025-01-09
An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request.
- CVE-2024-55398MEDIUMCVSS 6.5EG 6.52025-08-06
4C Strategies Exonaut before v22.4 was discovered to contain insecure permissions.
- CVE-2024-55930MEDIUMCVSS 6.7EG 6.62025-01-23
Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete files
- CVE-2024-55950HIGHCVSS 8.6EG 0.02024-12-26
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.216, Tabby terminal emulator contains overly permissive entitlements that are unnecessary for its core functionality and plugin system, creating potential s…
- CVE-2024-55956CRITICALCVSS 9.8EG 9.8⚠ KEV2024-12-13
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autor…
- CVE-2024-55957HIGHCVSS 7.8EG 7.82025-01-22
In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control Software (ICSW) before 3.1 SP10, the driver packages have a local privilege escalation vulnerability due to improper access control permissions on…
- CVE-2024-55959CRITICALCVSS 9.1EG 9.12025-01-21
Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions.
- CVE-2024-56440MEDIUMCVSS 6.2EG 6.22025-01-08
Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
- CVE-2024-56447HIGHCVSS 7.8EG 7.82025-01-08
Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-56525CRITICALCVSS 9.8EG 9.82025-02-24
In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading …
- CVE-2024-57032CRITICALCVSS 9.8EG 9.82025-01-17
WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so it is possible to change the password by placing any value in the senha_antiga field.
- CVE-2024-57438MEDIUMCVSS 5.4EG 5.42025-01-29
Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level roles.
- CVE-2024-57548CRITICALCVSS 9.1EG 9.12025-01-27
CMSimple 5.16 allows the user to edit log.php file via print page.
- CVE-2024-57604CRITICALCVSS 9.8EG 9.82025-02-12
An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →