Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-276

MITRE ↗

CWE-276

115
CRITICAL
732
HIGH
580
MEDIUM
61
LOW
1,529 CVEs · Page 13/31
5.3
CVE-2024-48572

A User enumeration vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to obtain email addres

5.3
CVE-2024-43430

A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.

5.3
CVE-2024-48533

A discrepancy between responses for valid and invalid e-mail accounts in the Forgot your Login? module of eSoft Planner

5.3
CVE-2024-11088

The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in

5.3
CVE-2024-11089

The Anonymous Restricted Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up

5.1
CVE-2024-20841

Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to acc

5.1
CVE-2024-2819

Incorrect Default Permissions, Improper Preservation of Permissions vulnerability in Hitachi Ops Center Common Services

5.1
CVE-2024-34616

Improper handling of insufficient permission in KnoxDualDARPolicy prior to SMR Aug-2024 Release 1 allows local attackers

5.1
CVE-2024-34648

Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers t

5.0
CVE-2024-21615

An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, low-pri

5.0
CVE-2024-39544

An Incorrect Default Permissions vulnerability in the command line interface (CLI) of Juniper Networks Junos OS Evolved

4.8
CVE-2024-26302

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenti

4.7
CVE-2024-26280

Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated Ops and Viewers users to view all i

4.4
CVE-2024-0770

A vulnerability, which was classified as critical, was found in European Chemicals Agency IUCLID 7.10.3 on Windows. Affe

4.4
CVE-2024-29967

In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance ha

4.4
CVE-2024-34012

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manage

4.4
CVE-2024-22385

Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read an

4.3
CVE-2024-34223

Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow

4.3
CVE-2024-34661

Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to

4.3
CVE-2024-47593

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the serv

4.2
CVE-2024-6476

Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user

4.0
CVE-2024-34617

Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to conf

4.0
CVE-2024-47825

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 an

4.0
CVE-2024-34679

Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone

3.7
CVE-2024-21012

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE

3.7
CVE-2024-42188

HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update dat

3.5
CVE-2024-4226

It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all use

3.3
CVE-2024-23253

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be

3.3
CVE-2023-46270

MacPaw The Unarchiver before 4.3.6 contains vulnerability related to missing quarantine attributes for extracted items.

3.3
CVE-2024-40792

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A malicious app

2.8
CVE-2024-30204

In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.

2.8
CVE-2024-53921

An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders

2.7
CVE-2024-5967

A vulnerability was found in Keycloak. The LDAP testing endpoint allows changing the Connection URL  independently witho

2.5
CVE-2024-21002

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). S

2.5
CVE-2024-21004

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). S

2.3
CVE-2024-21123

Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are

CVE-2024-10183

A vulnerability in Jamf Pro's Jamf Remote Assist tool allows a local, non-privileged user to escalate their privileges t

CVE-2024-49504

grub2 allowed attackers with access to the grub shell to access files on the encrypted disks.

CVE-2024-54131

The Kolide Agent (aka: Launcher) is the lightweight agent designed to work with Kolide's service. An implementation bug

CVE-2024-12564

Exposure of Sensitive Information to an Unauthorized Actor vulnerability was discovered in Open Design Alliance CDE inWE

CVE-2024-55950

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.216, Tabby terminal emulator contains

10.0
CVE-2022-42150

TinyLab linux-lab v1.1-rc1 and cloud-labv0.8-rc2, v1.1-rc1 are vulnerable to insecure permissions. The default configura

9.9
CVE-2023-22651

Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic o

9.8
CVE-2023-23566

A 2-Step Verification problem in Axigen 10.3.3.52 allows an attacker to access a mailbox by bypassing 2-Step Verificatio

9.8
CVE-2021-34182

An issue in ttyd v.1.6.3 allows attacker to execute arbitrary code via default configuration permissions.

9.8
CVE-2023-26918

Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan

9.8
CVE-2023-23059

An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions

9.8
CVE-2023-29732

SoLive 1.6.14 thru 1.6.20 for Android exists exposed component, the component provides the method to modify the SharedPr

9.8
CVE-2023-33282

Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. A remote attacker is able to lo

9.8
CVE-2023-31116

An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. An incorrect default permiss

Frequently Asked Questions

What is CWE-276?

CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-276?

There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.

How can I protect against CWE-276 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.

Detect CWE-276 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.

Get Started