Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-276

MITRE ↗

CWE-276

115
CRITICAL
732
HIGH
580
MEDIUM
61
LOW
1,529 CVEs · Page 5/31
7.8
CVE-2025-24915

When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not

7.8
CVE-2025-24170

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5,

7.8
CVE-2025-24234

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5

7.8
CVE-2025-24267

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma

7.8
CVE-2025-24277

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m

7.8
CVE-2025-29504

Insecure Permission vulnerability in student-manage 1 allows a local attacker to escalate privileges via the Unsafe perm

7.8
CVE-2025-29570

An issue in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 allows a local attacker to escalate privileges via t

7.8
CVE-2025-29801

Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-23386

A Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed package gerbera allows the service user gerbera

7.8
CVE-2025-3617

A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files a

7.8
CVE-2025-24914

When installing Nessus to a non-default location on a Windows host, Nessus versions prior to 10.8.4 did not enforce secu

7.8
CVE-2025-42598

Multiple SEIKO EPSON printer drivers for Windows OS are configured with an improper access permission settings when inst

7.8
CVE-2025-43595

An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a low privileged user to execute com

7.8
CVE-2025-43596

An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands

7.8
CVE-2025-2502

An improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to ele

7.8
CVE-2025-23105

An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processo

7.8
CVE-2025-36632

In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute c

7.8
CVE-2025-0886

An incorrect permissions vulnerability was reported in Elliptic Labs Virtual Lock Sensor that could allow a local, authe

7.8
CVE-2025-8069

During the AWS Client VPN client installation on Windows devices, the install process references the C:\usr\local\window

7.8
CVE-2025-52361

Insecure permissions in the script /etc/init.d/lighttpd in AK-Nord USB-Server-LXL Firmware v0.0.16 Build 2023-03-13 allo

7.8
CVE-2025-8672

MacOS version of GIMP bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permission

7.8
CVE-2025-8098

An improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate pri

7.8
CVE-2025-57846

Multiple i-フィルター products contain an issue with incorrect default permissions. If this vulnerability is exploited, a loc

7.8
CVE-2025-43725

Dell PowerProtect Data Manager, Generic Application Agent, version(s) 19.19 and 19.20, contain(s) an Incorrect Default P

7.8
CVE-2025-23297

NVIDIA Installer for NvAPP for Windows contains a vulnerability in the FrameviewSDK installation process, where an attac

7.8
CVE-2025-11575

Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation.This

7.8
CVE-2025-23347

NVIDIA Project G-Assist contains a vulnerability where an attacker might be able to escalate permissions. A successful e

7.8
CVE-2025-12100

Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation.This issue a

7.8
CVE-2025-13130

A vulnerability has been found in Radarr 5.28.0.10274. The affected element is an unknown function of the file C:\Progra

7.8
CVE-2025-13131

A vulnerability was found in Sonarr 4.0.15.2940. The impacted element is an unknown function of the file C:\ProgramData\

7.8
CVE-2025-34332

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration

7.8
CVE-2025-34333

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document r

7.8
CVE-2025-58097

The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative u

7.8
CVE-2025-61229

An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to ex

7.8
CVE-2025-13155

An improper permissions vulnerability was reported in Lenovo Baiying Client that could allow a local authenticated user

7.8
CVE-2025-53398

The Portrait Dell Color Management application 3.3.8 for Dell monitors has Insecure Permissions,

7.8
CVE-2025-53919

An issue was discovered in the Portrait Dell Color Management application through 3.3.008 for Dell monitors, It creates

7.7
CVE-2025-53947

A local attacker with low privileges on the Windows system where the software is installed can exploit this vulnerabili

7.7
CVE-2025-61035

The seffaflik thru 0.0.9 is vulnerable to symlink attacks due to incorrect default permissions given to the .kimlik file

7.5
CVE-2025-30706

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are aff

7.5
CVE-2025-54530

In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions

7.5
CVE-2025-13025

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunder

7.5
CVE-2025-59030

An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.

7.3
CVE-2023-31360

Incorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation dir

7.3
CVE-2025-0014

Incorrect default permissions on the AMD Ryzen(TM) AI installation folder could allow an attacker to achieve privilege e

7.3
CVE-2025-30701

Vulnerability in the RAS Security component of Oracle Database Server. Supported versions that are affected are 19.3-19

7.3
CVE-2024-21960

Incorrect default permissions in the AMD Optimizing CPU Libraries (AOCL) installation directory could allow an attacker

7.3
CVE-2024-36339

A DLL hijacking vulnerability in the AMD Optimizing CPU Libraries could allow an attacker to achieve privilege escalatio

7.3
CVE-2023-31358

A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, pote

7.3
CVE-2023-31359

Incorrect default permissions in the AMD Manageability API could allow an attacker to achieve privilege escalation, pote

Frequently Asked Questions

What is CWE-276?

CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-276?

There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.

How can I protect against CWE-276 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.

Detect CWE-276 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.

Get Started