Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-276

MITRE ↗

CWE-276

115
CRITICAL
732
HIGH
580
MEDIUM
61
LOW
1,529 CVEs · Page 9/31
8.2
CVE-2024-20005

In da, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of p

8.2
CVE-2023-24460

Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated

8.1
CVE-2024-7525

It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and

8.1
CVE-2024-9947

The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4

8.1
CVE-2024-52867

guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users b

8.0
CVE-2024-1488

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound grou

8.0
CVE-2024-52551

Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile)

7.9
CVE-2024-21840

Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMware vCenter allows local users to read and

7.8
CVE-2023-50612

Insecure Permissions vulnerability in fit2cloud Cloud Explorer Lite version 1.4.1, allow local attackers to escalate pri

7.8
CVE-2024-0833

In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the

7.8
CVE-2023-50236

A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The affected product is vulnerable due to

7.8
CVE-2024-0034

In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BA

7.8
CVE-2024-1155

Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authentic

7.8
CVE-2024-1156

Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ

7.8
CVE-2023-42928

The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.1 and iPadOS 17.1. An app may be able

7.8
CVE-2024-27674

Macro Expert through 4.9.4 allows BUILTIN\Users:(OI)(CI)(M) access to the "%PROGRAMFILES(X86)%\GrassSoft\Macro Expert" f

7.8
CVE-2024-30977

An issue in Secnet Security Network Intelligent AC Management System v.1.02.040 allows a local attacker to escalate priv

7.8
CVE-2024-26574

Insecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code vi

7.8
CVE-2024-21116

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a

7.8
CVE-2023-38295

Certain software builds for the TCL 30Z and TCL 10 Android devices contain a vulnerable, pre-installed app that relies o

7.8
CVE-2024-34474

Clario through 2024-04-11 for Desktop has weak permissions for %PROGRAMDATA%\Clario and tries to load DLLs from there as

7.8
CVE-2023-43629

Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated

7.8
CVE-2024-38459

langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an o

7.8
CVE-2024-4679

Incorrect Default Permissions vulnerability in Hitachi JP1/Extensible SNMP Agent for Windows, Hitachi JP1/Extensible SNM

7.8
CVE-2024-32861

Under certain circumstances the impacted Software House C•CURE 9000 installer will utilize unnecessarily wide permission

7.8
CVE-2024-42053

The MSI installer for Splashtop Streamer for Windows before 3.6.0.0 uses a temporary folder with weak permissions during

7.8
CVE-2024-2175

An insecure permissions vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Di

7.8
CVE-2024-4763

An insecure driver vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display

7.8
CVE-2024-43791

RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666

7.8
CVE-2024-40654

In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalati

7.8
CVE-2024-40655

In bindAndGetCallIdentification of CallScreeningServiceHelper.java, there is a possible way to maintain a while-in-use p

7.8
CVE-2024-9167

Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local a

7.8
CVE-2024-9858

There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windo

7.8
CVE-2024-49389

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Files

7.8
CVE-2024-7587

Incorrect Default Permissions vulnerability in GenBroker32, which is included in the installers for Mitsubishi Electric

7.8
CVE-2024-47012

In mm_GetMobileIdIndexForNsUpdate of mm_GmmPduCodec.c, there is a possible out of bounds write due to an incorrect bound

7.8
CVE-2024-47013

In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible arbitrary write due to uninitialized data. This c

7.8
CVE-2024-47016

there is a possible privilege escalation due to an insecure default value. This could lead to local escalation of privil

7.8
CVE-2024-50590

Attackers with local access to the medical office computer can escalate their Windows user privileges to "NT AUTHORITY\

7.8
CVE-2024-40660

In setTransactionState of SurfaceFlinger.cpp, there is a possible way to change protected display attributes due to a lo

7.8
CVE-2024-40661

In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due

7.8
CVE-2024-43081

In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a lo

7.8
CVE-2024-43085

In handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over USB without unlocki

7.8
CVE-2024-43089

In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission

7.8
CVE-2024-46462

By default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical fil

7.8
CVE-2024-46463

By default, dedicated folders of ORIZON for Windows up to 2024.3 can be accessed by other users to misuse technical file

7.8
CVE-2024-46465

By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical file

7.8
CVE-2024-46466

By default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission)

7.8
CVE-2024-46467

By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical f

7.8
CVE-2017-13310

In createFromParcel of ViewPager.java, there is a possible read/write serialization issue leading to a permissions bypas

Frequently Asked Questions

What is CWE-276?

CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-276?

There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.

How can I protect against CWE-276 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.

Detect CWE-276 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.

Get Started