Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-276

MITRE ↗

CWE-276

115
CRITICAL
732
HIGH
580
MEDIUM
61
LOW
1,529 CVEs · Page 4/31
9.8
CVE-2025-8031

The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authenti

9.8
CVE-2024-43166

Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: bef

9.6
CVE-2025-24891

Dumb Drop is a file upload application. Users with permission to upload to the service are able to exploit a path traver

9.1
CVE-2024-46505

Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.

9.1
CVE-2024-55959

Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions.

9.1
CVE-2024-57548

CMSimple 5.16 allows the user to edit log.php file via print page.

9.1
CVE-2025-49084

CVE-2025-49084 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers

8.8
CVE-2025-24399

Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats u

8.8
CVE-2025-48950

MaxKB is an open-source AI assistant for enterprise. Prior to version 1.10.8-lts, Sandbox only restricts the execution p

8.8
CVE-2025-46014

Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named p

8.8
CVE-2024-13972

A vulnerability related to registry permissions in the Intercept X for Windows updater prior to Core Agent version 2024.

8.8
CVE-2025-57625

CYRISMA Sensor before 444 for Windows has an Insecure Folder and File Permissions vulnerability. A low-privileged user c

8.8
CVE-2025-62577

ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect default permissions vulnerability. A low-privileged

8.6
CVE-2025-44643

Certain Draytek products are affected by Insecure Configuration. This affects AP903 v1.4.18 and AP912C v1.4.9 and AP918R

8.4
CVE-2021-27285

An issue was discovered in Inspur ClusterEngine v4.0 that allows attackers to gain escalated Local privileges and execut

8.4
CVE-2024-58044

Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerab

8.4
CVE-2025-34191

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.192

8.4
CVE-2025-8432

Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within S

8.2
CVE-2025-3528

A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has

8.2
CVE-2024-45067

Incorrect default permissions in some Intel(R) Gaudi(R) software installers before version 1.18 may allow an authenticat

8.2
CVE-2025-32091

Incorrect default permissions in some firmware for the Intel(R) Arc(TM) B-series GPUs within Ring 1: Device Drivers may

8.1
CVE-2024-46916

Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical sys

8.0
CVE-2023-1907

A vulnerability was found in pgadmin. Users logging into pgAdmin running in server mode using LDAP authentication may be

7.8
CVE-2024-43769

In isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could prevent the uninstallat

7.8
CVE-2024-11624

there is a possible to add apps to bypass VPN due to Undeclared Permission . This could lead to local escalation of priv

7.8
CVE-2024-53835

there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with

7.8
CVE-2024-53840

there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with

7.8
CVE-2024-53841

In startListeningForDeviceStateChanges, there is a possible Permission Bypass due to a confused deputy. This could lead

7.8
CVE-2024-56447

Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vul

7.8
CVE-2024-13206

A vulnerability classified as critical has been found in REVE Antivirus 1.0.0.0 on Linux. This affects an unknown part o

7.8
CVE-2024-46464

In PRIMX ZED Enterprise up to 2024.3, technical files stored in local folders with common user access can be manipulated

7.8
CVE-2018-9434

In multiple functions of Parcel.cpp, there is a possible way to bypass address space layout randomization. This could le

7.8
CVE-2018-9401

In many locations, there is a possible way to access kernel memory in user space due to an incorrect bounds check. This

7.8
CVE-2025-21532

Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Install). Supported versions that

7.8
CVE-2023-40132

In setActualDefaultRingtoneUri of RingtoneManager.java, there is a possible way to bypass content providers read permiss

7.8
CVE-2024-34730

In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in

7.8
CVE-2024-43765

In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/overlay attack. This cou

7.8
CVE-2024-49732

In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions without user c

7.8
CVE-2024-49735

In multiple locations, there is a possible failure to persist permissions settings due to resource exhaustion. This coul

7.8
CVE-2024-49737

In applyTaskFragmentOperation of WindowOrganizerController.java, there is a possible way to launch arbitrary activities

7.8
CVE-2024-49744

In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass parcel mismatch mit

7.8
CVE-2024-55957

In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control Software (ICSW) before 3.1

7.8
CVE-2025-0542

Local privilege escalation due to incorrect assignment of privileges of temporary files in the update mechanism of G DAT

7.8
CVE-2025-0543

Local privilege escalation in G DATA Security Client due to incorrect assignment of privileges to directories. This vuln

7.8
CVE-2025-24107

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS S

7.8
CVE-2025-24135

This issue was addressed with improved message validation. This issue is fixed in macOS Sequoia 15.3. An app may be able

7.8
CVE-2024-11468

Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installa

7.8
CVE-2024-51440

An issue in Nothing Tech Nothing OS v.2.6 allows a local attacker to escalate privileges via the NtBpfService component.

7.8
CVE-2025-22447

Incorrect access permission of a specific service issue exists in RemoteView Agent (for Windows) versions prior to v8.1.

7.8
CVE-2025-24864

Incorrect access permission of a specific folder issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5

Frequently Asked Questions

What is CWE-276?

CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-276?

There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.

How can I protect against CWE-276 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.

Detect CWE-276 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.

Get Started