Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-276

MITRE ↗

CWE-276

115
CRITICAL
732
HIGH
580
MEDIUM
61
LOW
1,529 CVEs · Page 12/31
6.5
CVE-2024-8037

Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the

6.5
CVE-2024-10469

VINCE versions before 3.0.9 is vulnerable to exposure of User information to authenticated users.

6.5
CVE-2024-52926

Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.

6.5
CVE-2024-48293

Incorrect access control in QuickHeal Antivirus Pro 24.1.0.182 and earlier allows authenticated attackers with low-level

6.3
CVE-2024-22062

There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permis

6.3
CVE-2024-6640

In ICMPv6 Neighbor Discovery (ND), the ID is always 0. When pf is configured to allow ND and block incoming Echo Reques

6.3
CVE-2024-46894

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not p

6.2
CVE-2024-22085

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The shadow file is world reada

6.2
CVE-2024-35139

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information fr

6.1
CVE-2023-38294

Certain software builds for the Itel Vision 3 Turbo Android device contain a vulnerable pre-installed app with a package

6.1
CVE-2024-3779

Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker t

6.1
CVE-2024-5321

A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read contai

6.0
CVE-2023-29162

Improper buffer restrictions the Intel(R) C++ Compiler Classic before version 2021.8 for Intel(R) oneAPI Toolkits before

5.9
CVE-2024-20921

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE

5.9
CVE-2024-23847

Incorrect default permissions issue exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary co

5.9
CVE-2024-39347

Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227

5.9
CVE-2024-46544

Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared mem

5.6
CVE-2024-27461

Incorrect default permissions in software installer for Intel(R) MAS (GUI) may allow an authenticated user to potentiall

5.5
CVE-2022-45793

Sysmac Studio installs executables in a directory with poor permissions. This can allow a locally-authenticated attacker

5.5
CVE-2024-23301

Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local att

5.5
CVE-2022-4964

Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.

5.5
CVE-2023-29081

A vulnerability has been reported in Suite Setups built with versions prior to InstallShield 2023 R2. This vulnerability

5.5
CVE-2024-22430

Dell PowerScale OneFS versions 8.2.x through 9.6.0.x contains an incorrect default permissions vulnerability. A local l

5.5
CVE-2023-42945

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1. An app may gai

5.5
CVE-2023-42953

A permissions issue was addressed with additional restrictions. This issue is fixed in tvOS 17.1, watchOS 10.1, macOS So

5.5
CVE-2023-48678

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber

5.5
CVE-2024-23201

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS M

5.5
CVE-2024-23295

A permissions issue was addressed to help ensure Personas are always protected. This issue is fixed in visionOS 1.1. An

5.5
CVE-2024-20671

Microsoft Defender Security Feature Bypass Vulnerability

5.5
CVE-2024-25654

Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with l

5.5
CVE-2024-29962

Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable. T

5.5
CVE-2024-31312

In multiple locations, there is a possible information leak due to a missing permission check. This could lead to local

5.5
CVE-2024-6326

An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A mali

5.5
CVE-2024-6122

An incorrect permission in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may r

5.5
CVE-2024-27888

A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS

5.5
CVE-2024-34018

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Snap D

5.5
CVE-2024-44135

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14

5.5
CVE-2024-44151

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14

5.5
CVE-2024-5474

A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning softwar

5.5
CVE-2024-47240

Dell Secure Connect Gateway (SCG) 5.24 contains an Incorrect Default Permissions vulnerability. A local attacker with lo

5.5
CVE-2024-43086

In validateAccountsInternal of AccountManagerService.java, there is a possible way to leak account credentials to a thir

5.5
CVE-2024-51764

A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configura

5.5
CVE-2024-51765

A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration,

5.5
CVE-2024-45819

PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local

5.4
CVE-2024-21122

Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Text Catalog).

5.3
CVE-2024-22301

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ignazio Scimone Albo Pretorio On line.This i

5.3
CVE-2024-25605

The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3

5.3
CVE-2024-20830

Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock sett

5.3
CVE-2024-28862

The Ruby One Time Password library (ROTP) is an open source library for generating and validating one time passwords. Af

5.3
CVE-2023-52717

Permission verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability w

Frequently Asked Questions

What is CWE-276?

CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-276?

There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.

How can I protect against CWE-276 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.

Detect CWE-276 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.

Get Started