Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-732

MITRE ↗

CWE-732

135
CRITICAL
822
HIGH
619
MEDIUM
95
LOW
1,711 CVEs · Page 10/35
7.5
CVE-2024-7986

A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensiti

7.5
CVE-2024-8900

An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigation

7.5
CVE-2024-7594

Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_princip

7.5
CVE-2024-44729

Incorrect access control in the component app/src/server.js of Mirotalk before commit 9de226 allows unauthenticated atta

7.5
CVE-2022-30354

OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserWi

7.4
CVE-2024-1486

Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices

7.3
CVE-2024-27294

dp-golang is a Puppet module for Go installations. Prior to 1.2.7, dp-golang could install files — including the compil

7.3
CVE-2024-29187

WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. When a bundle runs

7.3
CVE-2024-24910

A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for

7.3
CVE-2023-6729

Nokia SR OS routers allow read-write access to the entire file system via SFTP or SCP for users configured with "access

7.3
CVE-2024-9842

Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to crea

7.1
CVE-2024-0128

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager that allows a user of the guest OS to access gl

7.1
CVE-2024-45164

Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the la

7.1
CVE-2024-41974

A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for cri

7.1
CVE-2024-42449

From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is pos

7.1
CVE-2024-10256

Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbi

7.1
CVE-2024-7572

Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitr

7.1
CVE-2024-12363

Insufficient permissions in the TeamViewer Patch & Asset Management component prior to version 24.12 on Windows allows a

6.9
CVE-2024-32478

Git Credential Manager (GCM) is a secure Git credential helper. Prior to 2.5.0, the Debian package does not set root own

6.8
CVE-2024-27108

Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products

6.8
CVE-2024-36821

Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest

6.8
CVE-2022-43915

IBM App Connect Enterprise Certified Container 5.0, 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2

6.8
CVE-2024-47104

IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with auth

6.7
CVE-2023-41776

There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can cre

6.7
CVE-2023-38541

Insecure inherited permissions in some Intel HID Event Filter drivers for Windows 10 for some Intel NUC laptop software

6.7
CVE-2023-33870

Insecure inherited permissions in some Intel(R) Ethernet tools and driver install software may allow an authenticated us

6.7
CVE-2024-28589

An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attac

6.7
CVE-2024-24912

A local privilege escalation vulnerability has been identified in Harmony Endpoint Security Client for Windows versions

6.7
CVE-2024-21835

Insecure inherited permissions in some Intel(R) XTU software before version 7.14.0.15 may allow an authenticated user to

6.7
CVE-2024-20456

A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high priv

6.7
CVE-2024-23908

Insecure inherited permissions in some Flexlm License Daemons for Intel(R) FPGA software before version v11.19.5.0 may a

6.7
CVE-2024-25561

Insecure inherited permissions in some Intel(R) HID Event Filter software installers before version 2.2.2.1 may allow an

6.7
CVE-2024-36276

Insecure inherited permissions for some Intel(R) CIP software before version 2.4.10852 may allow an authenticated user t

6.7
CVE-2024-36294

Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow an authenticated user t

6.7
CVE-2024-55955

An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents between versions 20.0.1-9400

6.5
CVE-2024-3250

It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v

6.5
CVE-2023-52554

Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affe

6.5
CVE-2024-47833

Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine lear

6.5
CVE-2024-45841

Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/E

6.4
CVE-2024-21902

An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operatin

6.4
CVE-2024-21703

This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center a

6.3
CVE-2024-30208

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC

6.3
CVE-2024-1724

In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict w

6.2
CVE-2024-23223

A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS So

6.2
CVE-2024-2905

A security vulnerability has been discovered within rpm-ostree, pertaining to the /etc/shadow file in default builds hav

6.1
CVE-2024-21063

Vulnerability in the PeopleSoft Enterprise HCM Benefits Administration product of Oracle PeopleSoft (component: Benefits

6.0
CVE-2024-41820

Kubean is a cluster lifecycle management toolchain based on kubespray and other cluster LCM engine. The ClusterRole has

6.0
CVE-2024-38646

An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If e

5.9
CVE-2024-28955

Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the

5.7
CVE-2024-29964

Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivilege

Frequently Asked Questions

What is CWE-732?

CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-732?

There are 1,937 CVE records associated with CWE-732 in our database. Of these, 135 are critical severity, 822 are high severity, and 619 are medium severity.

How can I protect against CWE-732 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.

Detect CWE-732 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.

Get Started