A User enumeration vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to obtain email addres
A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.
A discrepancy between responses for valid and invalid e-mail accounts in the Forgot your Login? module of eSoft Planner
The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in
The Anonymous Restricted Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up
Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to acc
Incorrect Default Permissions, Improper Preservation of Permissions vulnerability in Hitachi Ops Center Common Services
Improper handling of insufficient permission in KnoxDualDARPolicy prior to SMR Aug-2024 Release 1 allows local attackers
Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers t
An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, low-pri
An Incorrect Default Permissions vulnerability in the command line interface (CLI) of Juniper Networks Junos OS Evolved
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenti
Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated Ops and Viewers users to view all i
A vulnerability, which was classified as critical, was found in European Chemicals Agency IUCLID 7.10.3 on Windows. Affe
In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance ha
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manage
Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read an
Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow
Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the serv
Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user
Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to conf
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 an
Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update dat
It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all use
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be
MacPaw The Unarchiver before 4.3.6 contains vulnerability related to missing quarantine attributes for extracted items.
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A malicious app
In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders
A vulnerability was found in Keycloak. The LDAP testing endpoint allows changing the Connection URL independently witho
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). S
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). S
Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are
A vulnerability in Jamf Pro's Jamf Remote Assist tool allows a local, non-privileged user to escalate their privileges t
grub2 allowed attackers with access to the grub shell to access files on the encrypted disks.
The Kolide Agent (aka: Launcher) is the lightweight agent designed to work with Kolide's service. An implementation bug
Exposure of Sensitive Information to an Unauthorized Actor vulnerability was discovered in Open Design Alliance CDE inWE
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.216, Tabby terminal emulator contains
TinyLab linux-lab v1.1-rc1 and cloud-labv0.8-rc2, v1.1-rc1 are vulnerable to insecure permissions. The default configura
Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic o
A 2-Step Verification problem in Axigen 10.3.3.52 allows an attacker to access a mailbox by bypassing 2-Step Verificatio
An issue in ttyd v.1.6.3 allows attacker to execute arbitrary code via default configuration permissions.
Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan
An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions
SoLive 1.6.14 thru 1.6.20 for Android exists exposed component, the component provides the method to modify the SharedPr
Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. A remote attacker is able to lo
An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. An incorrect default permiss
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started