A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-Se
A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-Se
A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-Se
Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is
Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php.
An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a privat
jitsi-meet-prosody in Jitsi Meet before 2.0.5963-1 does not ensure that restrict_room_creation is set by default. This c
A smart STB product of ZTE is impacted by a permission and access control vulnerability. Due to insufficient protection
There is an Improper Permission Management Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerabi
There is a Permission Control Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affe
There is an Improper permission vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may aff
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to us
On SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3, vSRX Series devices using tenant services on Junip
On SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3, devices using tenant services on Juniper Networks
An incorrect permission vulnerability in the product installer for Trend Micro HouseCall for Home Networks version 5.3.1
An incorrect permission vulnerability in the product installer folders for Trend Micro HouseCall for Home Networks versi
In onCreate of PermissionActivity.java, there is a possible permission bypass due to Confusing UI. This could lead to lo
A privilege escalation vulnerability exists in the Remote Server functionality of Dream Report ODS Remote Connector 20.2
There is an improper permission assignment vulnerability in Huawei ManageOne product. Due to improper security hardening
A smart camera product of ZTE is impacted by a permission and access control vulnerability. Due to the defect of user pe
NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in whic
The Agent in NinjaRMM 5.0.909 has Insecure Permissions.
"Tasks" application version before 9.7.3 is affected by insecure permissions. The VoiceCommandActivity application compo
A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE B
ASUSTek ZenBook Pro Due 15 UX582 laptop firmware through 203 has Insecure Permissions that allow attacks by a physically
Incorrect default permissions in installer for the Intel(R) SSD Toolbox versions before 2/9/2021 may allow a privileged
Incorrect default permissions in the installer for the Intel(R) RealSense(TM) DCM may allow a privileged user to potenti
Acronis True Image through 2021 on macOS allows local privilege escalation from admin to root due to insecure folder per
Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users p
Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validatio
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contains a plain-text password storage vulnerabil
A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0
The ARM TrustZone Technology on which Trusty is based on contains a vulnerability in access permission settings where th
Dell EMC Isilon OneFS supported versions 8.1 and later and Dell EMC PowerScale OneFS supported version 9.0.0 contain an
The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix p
In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could l
When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous us
A local (authenticated) low-privileged user can exploit a behavior in an ESET installer to achieve arbitrary file overwr
Improper default permissions in the firmware for the Intel(R) Ethernet I210 Controller series of network adapters before
In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file
A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.200.2042, that could allow conf
In updateNotifications of DeviceStorageMonitorService.java, there is a possible permission bypass due to an unsafe Pendi
Using unsafe PendingIntent in Samsung Notes prior to version 4.2.00.22 allows local attackers unauthorized action withou
Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android
A privilege escalation vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that
Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries
Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries
A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow conf
An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe keeps a log in a folder where
IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of service due to insecure fi
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started