CWE-276
Incorrect Default Permissions
Common consequences1
- ConfidentialityIntegrityRead Application DataModify Application Data
Potential mitigations2
- Architecture and DesignOperation
The architecture needs to access and modification attributes for files to only those users who actually require those actions.
- Architecture and Design
Compartmentalize the system to have "safe" areas where trust boundaries can be unambiguously drawn. Do not allow sensitive data to go outside of the trust boundary and always be careful when interfacing with a compartment outside of the safe area. Ensure that appropriate compartmentalization is built into the system design, and the compartmentalization allows for and reinforces privilege separation functionality. Architects and designers should rely on the principle of least privilege to decide the appropriate time to use privileges and the time to drop privileges.
CVEs referencing this CWE138
| CVE | Description | Severity | EPSS | Flags | Modified |
|---|---|---|---|---|---|
| CVE-2013-0632 | administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013. | CRITICAL9.8 | 94%p100 | KEVWeaponized | 2026-04-21 |
| CVE-2017-11610 | The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups. | HIGH8.8 | 88%p100 | Weaponized | 2026-05-13 |
| CVE-2023-29919 | SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted. | CRITICAL9.1 | 60%p99 | PoC | 2025-01-17 |
| CVE-2019-17124 | Kramer VIAware 2.5.0719.1034 has Incorrect Access Control. | CRITICAL9.8 | 23%p97 | PoC | 2024-11-21 |
| CVE-2020-12608 | An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Monitoring Agent. There are insecure file permissions for %PROGRAMDATA%\SolarWinds MSP\SolarWinds.MSP.CacheService\config\. This can lead to code execution by changing the CacheService.xml SISServerURL parameter. | HIGH7.8 | 22%p97 | PoC | 2024-11-21 |
| CVE-2021-3437 | Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of privilege and/or denial of service. HP is releasing software updates to mitigate the potential vulnerabilities. | CRITICAL9.8 | 16%p96 | 2025-04-29 | |
| CVE-2017-8625 | Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to bypass Device Guard User Mode Code Integrity (UMCI) policies due to Internet Explorer failing to validate UMCI policies, aka "Internet Explorer Security Feature Bypass Vulnerability". | NONE | 15%p96 | PoC | 2026-05-13 |
| CVE-2020-12695 | The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue. | HIGH7.5 | 15%p96 | PoC | 2024-11-21 |
| CVE-2022-22948 | The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information. | MEDIUM6.5 | 14%p96 | KEVFunctional | 2025-10-31 |
| CVE-2024-57684 | An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted POST request. | CRITICAL9.8 | 14%p96 | 2025-05-02 | |
| CVE-2018-14335 | An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file. | MEDIUM6.5 | 13%p96 | PoC | 2024-11-21 |
| CVE-2020-12834 | eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, by unauthenticated attackers with access to the web interface, due to the default auto-login feature being enabled during first-time setup (or factory reset). | CRITICAL9.8 | 11%p95 | 2024-11-21 | |
| CVE-2024-39924 | An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for altering the metadata of an emergency access. It permits an attacker with granted emergency access to escalate their privileges by changing the access level and modifying the wait time. Consequently, the attacker can gain full control over the vault (when only intended to have read access) while bypassing the necessary wait period. | HIGH8.8 | 11%p95 | 2025-07-10 | |
| CVE-1999-0426 | The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing. | CRITICAL9.8 | 11%p95 | Functional | 2026-06-16 |
| CVE-2023-29923 | PowerJob V4.3.1 is vulnerable to Insecure Permissions. via the list job interface. | MEDIUM5.3 | 9.55%p95 | PoC | 2025-02-05 |
| CVE-2020-11444 | Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control. | HIGH8.8 | 8.51%p94 | PoC | 2024-11-21 |
| CVE-2020-7943 | Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined types (which may contain sensitive information) as well as function names and class names. Previously, these endpoints were open to the local network. PE 2018.1.13 & 2019.5.0, Puppet Server 6.9.2 & 5.3.12, and PuppetDB 6.9.1 & 5.2.13 disable trapperkeeper-metrics /v1 metrics API and only allows /v2 access on localhost by default. This affects software versions: Puppet Enterprise 2018.1.x stream prior to 2018.1.13 Puppet Enterprise prior to 2019.5.0 Puppet Server prior to 6.9.2 Puppet Server prior to 5.3.12 PuppetDB prior to 6.9.1 PuppetDB prior to 5.2.13 Resolved in: Puppet Enterprise 2018.1.13 Puppet Enterprise 2019.5.0 Puppet Server 6.9.2 Puppet Server 5.3.12 PuppetDB 6.9.1 PuppetDB 5.2.13 | HIGH7.5 | 7.88%p94 | 2024-11-21 | |
| CVE-2013-4859 | INSTEON Hub 2242-222 lacks Web and API authentication | HIGH8.1 | 6.97%p93 | Functional | 2024-11-21 |
| CVE-2021-44140 | Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance. Apache JSPWiki users should upgrade to 2.11.0 or later. | CRITICAL9.1 | 6.16%p93 | 2024-11-21 | |
| CVE-2023-26918 | Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as LocalSystem. This occurs because %ProgramFiles%\FileReplicationPro allows Everyone:(F) access. | CRITICAL9.8 | 6.05%p92 | PoC | 2025-02-07 |
| CVE-2023-20178 | A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update process is executed after a successful VPN connection is established. This vulnerability exists because improper permissions are assigned to a temporary directory that is created during the update process. An attacker could exploit this vulnerability by abusing a specific function of the Windows installer process. A successful exploit could allow the attacker to execute code with SYSTEM privileges. | HIGH7.8 | 5.94%p92 | PoC | 2024-11-21 |
| CVE-2021-3394 | Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder permissions allowing a malicious user for a local privilege escalation. | HIGH8.8 | 5.79%p92 | Functional | 2024-11-21 |
| CVE-2022-32207 | When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended. | CRITICAL9.8 | 5.48%p92 | 2025-04-23 | |
| CVE-2020-28906 | Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root. Low-privileged users are able to modify files that are included (aka sourced) by scripts executed by root. | HIGH8.8 | 4.73%p91 | 2024-11-21 | |
| CVE-2020-24583 | An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMISSIONS mode was not applied to intermediate-level directories created in the process of uploading files. It was also not applied to intermediate-level collected static directories when using the collectstatic management command. | HIGH7.5 | 3.97%p89 | 2024-11-21 | |
| CVE-2020-9039 | Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they allow unauthenticated access).The /settings REST endpoint exposed by the projector process is an endpoint that administrators can use for various tasks such as updating configuration and collecting performance profiles. The endpoint was unauthenticated and has been updated to only allow authenticated users to access these administrative APIs. | CRITICAL9.8 | 3.87%p89 | 2024-11-21 | |
| CVE-2017-12763 | An unspecified server utility in NoMachine before 5.3.10 on Mac OS X and Linux allows authenticated users to gain privileges by gaining access to local files. | NONE | 3.86%p89 | PoC | 2026-05-13 |
| CVE-2006-5014 | Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin. | HIGH8.8 | 3.84%p89 | Functional | 2026-04-23 |
| CVE-2021-31217 | In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM. | CRITICAL9.1 | 3.80%p89 | 2024-11-21 | |
| CVE-2002-0493 | Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions. | NONE | 3.80%p89 | 2026-06-16 | |
| CVE-2016-5425 | The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group. | HIGH7.8 | 3.78%p89 | Weaponized | 2026-05-06 |
| CVE-2021-40904 | The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code. As a result, remote code execution is achieved. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session by a user with the role of administrator. | HIGH8.8 | 3.76%p89 | PoC | 2024-11-21 |
| CVE-2021-36365 | Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh. | CRITICAL9.8 | 3.68%p88 | 2024-11-21 | |
| CVE-2021-36363 | Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php. | CRITICAL9.8 | 3.68%p88 | 2024-11-21 | |
| CVE-2023-21433 | Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applications from Galaxy Store. | HIGH7.8 | 3.67%p88 | 2025-03-24 | |
| CVE-2019-0683 | An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privilege Vulnerability'. | NONE | 3.36%p87 | 2024-11-21 | |
| CVE-2012-4434 | fwknop before 2.0.3 allow remote authenticated users to cause a denial of service (server crash) or possibly execute arbitrary code. | HIGH8.8 | 3.31%p87 | 2024-11-21 | |
| CVE-2020-24584 | An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077. | HIGH7.5 | 3.27%p87 | 2024-11-21 | |
| CVE-2017-12230 | A vulnerability in the web-based user interface (web UI) of Cisco IOS XE 16.2 could allow an authenticated, remote attacker to elevate their privileges on an affected device. The vulnerability is due to incorrect default permission settings for new users who are created by using the web UI of the affected software. An attacker could exploit this vulnerability by using the web UI of the affected software to create a new user and then logging into the web UI as the newly created user. A successful exploit could allow the attacker to elevate their privileges on the affected device. This vulnerability affects Cisco devices that are running a vulnerable release Cisco IOS XE Software, if the HTTP Server feature is enabled for the device. The newly redesigned, web-based administration UI was introduced in the Denali 16.2 Release of Cisco IOS XE Software. This vulnerability does not affect the web-based administration UI in earlier releases of Cisco IOS XE Software. Cisco Bug IDs: CSCuy83062. | NONE | 3.18%p86 | 2026-05-13 | |
| CVE-2021-39274 | In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing an unprivileged user to modify the main application and the application configuration file. This results in arbitrary code execution with root privileges. | CRITICAL9.8 | 3.12%p86 | 2024-11-21 | |
| CVE-2022-28932 | D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions. | CRITICAL9.8 | 3.05%p86 | 2024-11-21 | |
| CVE-2019-19896 | In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share. The default file permissions of the IXP$ share on the server allows modification of directories and files (e.g., bat-scripts), which allows execution of code in the context of NT AUTHORITY\SYSTEM on the target server and clients. | CRITICAL9.9 | 3.04%p86 | 2024-11-21 | |
| CVE-2021-45003 | Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.php through the "image" parameter that can execute a webshell payload. | CRITICAL9.8 | 3.01%p86 | 2025-04-22 | |
| CVE-2020-9409 | The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theoretically allows an unauthenticated attacker to obtain the permissions of a JasperReports Server "superuser" for the affected systems. The attacker can theoretically exploit the vulnerability consistently, remotely, and without authenticating. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions 7.1.1 and below, TIBCO JasperReports Server for AWS Marketplace: versions 7.1.1 and below, and TIBCO JasperReports Server for ActiveMatrix BPM: versions 7.1.1 and below. | CRITICAL9.8 | 3.01%p86 | 2024-11-21 | |
| CVE-2023-31067 | An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\Clients\www. | CRITICAL9.8 | 2.88%p85 | PoC | 2024-11-21 |
| CVE-2023-31068 | An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\UserDesktop\themes. | CRITICAL9.8 | 2.85%p85 | PoC | 2026-03-03 |
| CVE-2021-37351 | Nagios XI before version 5.8.5 is vulnerable to insecure permissions and allows unauthenticated users to access guarded pages through a crafted HTTP request to the server. | MEDIUM5.3 | 2.83%p85 | 2024-11-21 | |
| CVE-2020-13452 | In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution. | CRITICAL9.8 | 2.75%p84 | 2024-11-21 | |
| CVE-2021-39273 | In XeroSecurity Sn1per 9.0 (free version), insecure permissions (0777) are set upon application execution, allowing an unprivileged user to modify the application, modules, and configuration files. This leads to arbitrary code execution with root privileges. | HIGH8.8 | 2.67%p84 | PoC | 2024-11-21 |
| CVE-2011-4361 | MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning function, or by (2) leveraging an extension, as demonstrated by the CategoryTree, ExtTab, and InlineEditor extensions. | NONE | 2.62%p83 | 2026-04-29 | |
| CVE-2019-12450 | file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used. | CRITICAL9.8 | 2.60%p83 | 2024-11-21 | |
| CVE-2022-27773 | A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elevated privileges. | CRITICAL9.8 | 2.59%p83 | 2025-04-24 | |
| CVE-2020-29582 | In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions. | MEDIUM5.3 | 2.57%p83 | 2026-02-25 | |
| CVE-2017-16522 | MitraStar GPT-2541GNAC (HGU) 1.00(VNJ0)b1 and DSL-100HN-T1 ES_113WJY0b16 devices allow remote authenticated users to obtain root access by specifying /bin/sh as the command to execute. | NONE | 2.57%p83 | 2026-05-13 | |
| CVE-2019-19475 | An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is prone to attack due to lack of file permission security. The malicious users who are in “Authenticated Users” group can exploit privilege escalation and modify PostgreSQL configuration to execute arbitrary command to escalate and gain full system privilege user access and rights over the system. | HIGH8.8 | 2.55%p83 | 2024-11-21 | |
| CVE-2023-25355 | CoreDial sipXcom up to and including 21.04 is vulnerable to Insecure Permissions. A user who has the ability to run commands as the `daemon` user on a sipXcom server can overwrite a service file, and escalate their privileges to `root`. | HIGH8.8 | 2.50%p83 | PoC | 2025-02-13 |
| CVE-2010-4176 | plymouth-pretrigger.sh in dracut and udev, when running on Fedora 13 and 14, sets weak permissions for the /dev/systty device file, which allows remote authenticated users to read terminal data from tty0 for local users. | NONE | 2.32%p81 | 2026-04-29 | |
| CVE-2019-20468 | An issue was discovered in SeTracker2 for TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It has unnecessary permissions such as READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE, and READ_CONTACTS. | CRITICAL9.8 | 2.30%p81 | 2024-11-21 | |
| CVE-2019-14861 | All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stores DNS records in LDAP. In AD, the default permissions on the DNS partition allow creation of new records by authenticated users. This is used for example to allow machines to self-register in DNS. If a DNS record was created that case-insensitively matched the name of the zone, the ldb_qsort() and dns_name_compare() routines could be confused into reading memory prior to the list of DNS entries when responding to DnssrvEnumRecords() or DnssrvEnumRecords2() and so following invalid memory as a pointer. | MEDIUM5.3 | 2.30%p81 | 2024-11-21 | |
| CVE-2014-2721 | In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is not the result of an underlying SSH defect. | HIGH8.8 | 2.29%p81 | 2024-11-21 | |
| CVE-2019-17383 | The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesystem. | CRITICAL9.8 | 2.29%p81 | 2024-11-21 | |
| CVE-2023-40076 | In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | MEDIUM5.5 | 2.28%p81 | 2025-05-29 | |
| CVE-2020-8539 | Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an attacker to inject unauthorized commands, by executing the micomd executable deamon, to trigger unintended functionalities. In addition, this executable may be used by an attacker to inject commands to generate CAN frames that are sent into the M-CAN bus (Multimedia CAN bus) of the vehicle. | HIGH7.8 | 2.26%p81 | Functional | 2024-11-21 |
| CVE-2021-38557 | raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. The www-data account can execute /etc/raspap/hostapd/enablelog.sh as root with no password; however, the www-data account can also overwrite /etc/raspap/hostapd/enablelog.sh with any executable content. | HIGH8.8 | 2.22%p80 | 2024-11-21 | |
| CVE-2020-8219 | An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change the password of a full administrator. | HIGH7.2 | 2.22%p80 | 2024-11-21 | |
| CVE-2017-11156 | Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsearch directory, which allows remote authenticated users to execute arbitrary code by uploading an executable via unspecified vectors. | NONE | 2.21%p80 | 2026-05-13 | |
| CVE-2020-26809 | SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders. This folder could contain sensitive files that results in disclosure of sensitive information and impact system configuration confidentiality. | MEDIUM5.3 | 2.05%p79 | 2024-11-21 | |
| CVE-2020-27358 | An issue was discovered in REDCap 8.11.6 through 9.x before 10. The messenger's CSV feature (that allows users to export their conversation threads as CSV) allows non-privileged users to export one another's conversation threads by changing the thread_id parameter in the request to the endpoint Messenger/messenger_download_csv.php?title=Hey&thread_id={THREAD_ID}. | MEDIUM4.3 | 2.03%p79 | PoC | 2024-11-21 |
| CVE-2018-8848 | Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permissions for an object that exposes it to an unintended actor. | HIGH7.5 | 2.03%p78 | 2024-11-21 | |
| CVE-2020-12101 | The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by manipulating an id field in the POST request for altering an address. | MEDIUM4.3 | 1.99%p78 | 2024-11-21 | |
| CVE-2020-28041 | The SIP ALG implementation on NETGEAR Nighthawk R7000 1.0.9.64_10.2.64 devices allows remote attackers to communicate with arbitrary TCP and UDP services on a victim's intranet machine, if the victim visits an attacker-controlled web site with a modern browser, aka NAT Slipstreaming. This occurs because the ALG takes action based on an IP packet with an initial REGISTER substring in the TCP data, and the correct intranet IP address in the subsequent Via header, without properly considering that connection progress and fragmentation affect the meaning of the packet data. | MEDIUM6.5 | 1.98%p78 | 2024-11-21 | |
| CVE-2022-36640 | influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states "If InfluxDB is being deployed on a publicly accessible endpoint, we strongly recommend authentication be enabled. Otherwise the data will be publicly available to any unauthenticated user. The default settings do NOT enable authentication and authorization. | CRITICAL9.8 | 1.93%p77 | 2024-11-21 | |
| CVE-2011-4285 | The default configuration of Moodle 2.0.x before 2.0.2 has an incorrect setting of the moodle/course:delete capability, which allows remote authenticated users to delete arbitrary courses by leveraging the teacher role. | NONE | 1.91%p77 | 2026-04-29 | |
| CVE-2020-6445 | Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page. | MEDIUM6.5 | 1.90%p77 | 2024-11-21 | |
| CVE-2020-10792 | openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header. | HIGH7.5 | 1.90%p77 | 2024-11-21 | |
| CVE-2017-5642 | During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs. | NONE | 1.89%p77 | 2026-05-13 | |
| CVE-2021-28271 | Soyal Technologies SOYAL 701Server 9.0.1 suffers from an elevation of privileges vulnerability which can be used by an authenticated user to change the executable file with a binary choice. The vulnerability is due to improper permissions with the 'F' flag (Full) for 'Everyone'and 'Authenticated Users' group. | HIGH8.8 | 1.87%p77 | 2024-11-21 | |
| CVE-2024-26280 | Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated Ops and Viewers users to view all information on audit logs, including dag names and usernames they were not permitted to view. With 2.8.2 and newer, Ops and Viewer users do not have audit log permission by default, they need to be explicitly granted permissions to see the logs. Only admin users have audit log permission by default. Users of Apache Airflow are recommended to upgrade to version 2.8.2 or newer to mitigate the risk associated with this vulnerability | MEDIUM4.7 | 1.86%p76 | 2026-03-26 | |
| CVE-2021-33038 | An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a private mailing list's archives, these archives are publicly visible for the duration of the import. For example, sensitive information might be available on the web for an hour during a large migration from Mailman 2 to Mailman 3. | HIGH7.5 | 1.85%p76 | 2024-11-21 | |
| CVE-2020-29491 | Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access to the sensitive information on the local network, leading to the potential compromise of impacted thin clients. | HIGH8.6 | 1.85%p76 | 2024-11-21 | |
| CVE-2023-27035 | An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page. | HIGH7.5 | 1.84%p76 | PoC | 2025-01-30 |
| CVE-2021-29005 | Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute chmod as root without password which may let an attacker with low privilege to gain root access on server. | HIGH8.8 | 1.83%p76 | 2024-11-21 | |
| CVE-2020-14156 | user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has strong file permissions. | HIGH8.8 | 1.81%p76 | 2024-11-21 | |
| CVE-2021-1056 | NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely honor operating system file system permissions to provide GPU device-level isolation, which may lead to denial of service or information disclosure. | HIGH7.1 | 1.78%p75 | PoC | 2024-11-21 |
| CVE-2020-6439 | Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page. | HIGH8.8 | 1.78%p75 | 2024-11-21 | |
| CVE-2021-41635 | When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations or vulnerabilities with administrative access over the entire host system. | HIGH8.8 | 1.74%p75 | 2024-11-21 | |
| CVE-2020-29492 | Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to access the writable file and manipulate the configuration of any target specific station. | CRITICAL10.0 | 1.74%p75 | 2024-11-21 | |
| CVE-2023-23583 | Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access. | HIGH7.8 | 1.73%p75 | PoC | 2025-12-16 |
| CVE-2022-27919 | Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configuration allows certain anonymous access to administration and an API. | CRITICAL9.8 | 1.73%p75 | 2024-11-21 | |
| CVE-2020-13922 | Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface. | MEDIUM6.5 | 1.73%p75 | 2025-02-13 | |
| CVE-2020-6441 | Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page. | MEDIUM4.3 | 1.72%p75 | 2024-11-21 | |
| CVE-2019-16919 | Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or pull access permissions to a project they don't have access or control for. The Harbor API did not enforce the proper project permissions and project scope on the API request to create a new robot account. | HIGH7.5 | 1.71%p74 | 2024-11-21 | |
| CVE-2019-16716 | OX App Suite through 7.10.2 has Incorrect Access Control. | MEDIUM6.6 | 1.70%p74 | 2024-11-21 | |
| CVE-2014-2723 | In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is not the result of an underlying SSH defect. | HIGH8.8 | 1.69%p74 | 2024-11-21 | |
| CVE-2014-2722 | In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is not the result of an underlying SSH defect. | HIGH8.8 | 1.69%p74 | 2024-11-21 | |
| CVE-2020-24402 | Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability in the Integrations component. This vulnerability could be abused by authenticated users with permissions to the Resource Access API to delete customer details via the REST API without authorization. | MEDIUM4.9 | 1.68%p74 | 2025-02-10 | |
| CVE-2020-9392 | An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTable, createFromTpl, and getJSONExportTable endpoints, unauthenticated users can retrieve pricing table information, create new tables, or import/modify a table. | HIGH7.3 | 1.68%p74 | 2024-11-21 | |
| CVE-2024-28056 | Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed from an Amplify project, a Condition property is removed but "Effect":"Allow" remains present, and consequently sts:AssumeRoleWithWebIdentity would be available to threat actors with no conditions. Thus, if Amplify CLI had been used to remove the Authentication component from a project built between August 2019 and January 2024, an "assume role" may have occurred, and may have been leveraged to obtain unauthorized access to an organization's AWS resources. NOTE: the problem could only occur if an authorized AWS user removed an Authentication component. (The vulnerability did not give a threat actor the ability to remove an Authentication component.) However, in realistic situations, an authorized AWS user may have removed an Authentication component, e.g., if the objective were to stop using built-in Cognito resources, or move to a completely different identity provider. | CRITICAL9.8 | 1.67%p74 | 2025-06-30 | |
| CVE-2020-6483 | Insufficient policy enforcement in payments in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | MEDIUM6.5 | 1.67%p74 | 2024-11-21 | |
| CVE-2019-19118 | Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline related models, where the user has view-only permissions to a parent model but edit permissions to the inline model, would be presented with an editing UI, allowing POST requests, for updating the inline model. Directly editing the view-only parent model was not possible, but the parent model's save() method was called, triggering potential side effects, and causing pre and post-save signal handlers to be invoked. (To resolve this, the Django admin is adjusted to require edit permissions on the parent model in order for inline models to be editable.) | MEDIUM6.5 | 1.66%p74 | 2024-11-21 | |
| CVE-2019-14737 | Ubisoft Uplay 92.0.0.6280 has Insecure Permissions. | HIGH7.8 | 1.66%p74 | PoC | 2024-11-21 |
| CVE-2018-10604 | SEL Compass version 3.0.5.1 and prior allows all users full access to the SEL Compass directory, which may allow modification or overwriting of files within the Compass installation folder, resulting in escalation of privilege and/or malicious code execution. | HIGH8.8 | 1.64%p73 | 2024-11-21 | |
| CVE-2020-6446 | Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page. | MEDIUM6.5 | 1.62%p73 | 2024-11-21 | |
| CVE-2021-42098 | An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via batch custom PowerShell. | HIGH8.8 | 1.60%p73 | 2024-11-21 | |
| CVE-2020-6487 | Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | MEDIUM6.5 | 1.60%p73 | 2024-11-21 | |
| CVE-2021-20001 | It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions for the user web shares (~/public_html), which could result in privilege escalation. | CRITICAL9.8 | 1.59%p72 | 2024-11-21 | |
| CVE-2021-37363 | An Insecure Permissions issue exists in Gestionale Open 11.00.00. A low privilege account is able to rename the mysqld.exe file located in bin folder and replace with a malicious file that would connect back to an attacking computer giving system level privileges (nt authority\system) due to the service running as Local System. While a low privilege user is unable to restart the service through the application, a restart of the computer triggers the execution of the malicious file. The application also have unquoted service path issues. | HIGH7.8 | 1.57%p72 | 2024-11-21 | |
| CVE-2021-44833 | The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file. | CRITICAL9.8 | 1.56%p72 | 2024-11-21 | |
| CVE-2020-6431 | Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted HTML page. | MEDIUM4.3 | 1.55%p72 | 2024-11-21 | |
| CVE-2020-23971 | gmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions. An attacker can access the upload function without authenticating to the application and also can upload files due the issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions. | HIGH7.5 | 1.54%p72 | 2024-11-21 | |
| CVE-2020-6527 | Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page. | MEDIUM4.3 | 1.54%p72 | 2024-11-21 | |
| CVE-2020-6488 | Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | MEDIUM4.3 | 1.54%p72 | 2024-11-21 | |
| CVE-2019-3944 | Parrot ANAFI is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect drone from controller during mid-flight. | HIGH7.5 | 1.53%p72 | 2024-11-21 | |
| CVE-2019-3689 | The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system. | CRITICAL9.8 | 1.50%p71 | 2024-11-21 | |
| CVE-2020-6484 | Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted request. | MEDIUM6.5 | 1.49%p71 | 2024-11-21 | |
| CVE-2020-3838 | The issue was addressed with improved permissions logic. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with system privileges. | HIGH7.8 | 1.49%p71 | 2024-11-21 | |
| CVE-2015-9475 | The Pont theme 1.5 for WordPress has insufficient restrictions on option updates. | HIGH8.8 | 1.49%p71 | 2024-11-21 | |
| CVE-2015-9474 | The Simpolio theme 1.3.2 for WordPress has insufficient restrictions on option updates. | HIGH8.8 | 1.49%p71 | 2024-11-21 | |
| CVE-2023-45690 | Default file permissions on South River Technologies' Titan MFT and Titan SFTP servers on Linux allows a user that's authentication to the OS to read sensitive files on the filesystem | MEDIUM4.9 | 1.48%p71 | 2024-11-21 | |
| CVE-2023-23059 | An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions within the default installation and allows attackers to execute arbitrary code and gain escalated privileges. | CRITICAL9.8 | 1.48%p71 | 2025-01-29 | |
| CVE-2021-27193 | Incorrect default permissions vulnerability in the API of Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to read and write files on the remote machine with system privileges resulting in a privilege escalation. | CRITICAL9.8 | 1.48%p71 | 2024-11-21 | |
| CVE-2018-10605 | Martem TELEM GW6/GWM versions prior to 2.0.87-4018403-k4 may allow unprivileged users to modify/upload a new system configuration or take the full control over the RTU using default credentials to connect to the RTU. | NONE | 1.48%p71 | 2024-11-21 | |
| CVE-2012-5577 | Python keyring lib before 0.10 created keyring files with world-readable permissions. | HIGH7.5 | 1.46%p70 | 2024-11-21 | |
| CVE-2017-16128 | The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry. | CRITICAL9.8 | 1.46%p70 | 2024-11-21 | |
| CVE-2017-16127 | The module pandora-doomsday infects other modules. It's since been unpublished from the registry. | CRITICAL9.8 | 1.46%p70 | 2024-11-21 | |
| CVE-2020-12118 | The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parameters in order to compromise a signing round or obtain sensitive information from other parties. | HIGH8.2 | 1.42%p69 | 2024-11-21 | |
| CVE-2023-47250 | In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, broken Access Control on X11 server sockets allows authenticated attackers (with access to a VNC session) to access the X11 desktops of other users by specifying their DISPLAY ID. This allows complete control of their desktop, including the ability to inject keystrokes and perform a keylogging attack. | HIGH8.8 | 1.40%p69 | 2024-11-21 | |
| CVE-2020-6471 | Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. | CRITICAL9.6 | 1.40%p69 | 2024-11-21 | |
| CVE-2022-27649 | A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. | HIGH7.5 | 1.39%p69 | 2024-11-21 | |
| CVE-2020-12424 | When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been the URI of an origin that was previously granted permission; bypassing the prompt. This vulnerability affects Firefox < 78. | MEDIUM6.5 | 1.39%p69 | 2024-11-21 | |
| CVE-2020-5551 | Toyota 2017 Model Year DCU (Display Control Unit) allows an unauthenticated attacker within Bluetooth range to cause a denial of service attack and/or execute an arbitrary command. The affected DCUs are installed in Lexus (LC, LS, NX, RC, RC F), TOYOTA CAMRY, and TOYOTA SIENNA manufactured in the regions other than Japan from Oct. 2016 to Oct. 2019. An attacker with certain knowledge on the target vehicle control system may be able to send some diagnostic commands to ECUs with some limited availability impacts; the vendor states critical vehicle controls such as driving, turning, and stopping are not affected. | HIGH8.8 | 1.39%p69 | 2024-11-21 | |
| CVE-2019-19392 | The forDNN.UsersExportImport module before 1.2.0 for DNN (formerly DotNetNuke) allows an unprivileged user to import (create) new users with Administrator privileges, as demonstrated by Roles="Administrators" in XML or CSV data. | CRITICAL9.8 | 1.39%p69 | 2024-11-21 | |
| CVE-2020-6456 | Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allowed a local attacker to bypass site isolation via crafted clipboard contents. | MEDIUM6.5 | 1.38%p69 | 2024-11-21 | |
| CVE-2020-8114 | GitLab EE 8.9 and later through 12.7.2 has Insecure Permission | CRITICAL9.8 | 1.38%p69 | 2024-11-21 | |
| CVE-2019-9630 | Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images. | NONE | 1.38%p69 | 2024-11-21 | |
| CVE-2022-45924 | An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint itemtemplate.createtemplate2 allows a low-privilege user to delete arbitrary files on the server's local filesystem. | HIGH8.1 | 1.37%p68 | 2025-04-04 | |
| CVE-2020-25208 | In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permissions. | MEDIUM5.3 | 1.36%p68 | 2024-11-21 | |
| CVE-2020-11716 | Panasonic P110, Eluga Z1 Pro, Eluga X1, and Eluga X1 Pro devices through 2020-04-10 have Insecure Permissions. NOTE: the vendor states that all affected products are at "End-of-software-support." | CRITICAL9.8 | 1.36%p68 | 2024-11-21 |