A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for
Dell Grab for Windows, versions 5.0.4 and below, contains an improper file permissions vulnerability. A locally authenti
Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to name
SAP NetWeaver Application Server (ABAP) - versions KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERN
Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwi
Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which
Under certain conditions, Support Web Pages of SAP NetWeaver Process Integration (PI) - versions 7.50, allows an attacke
The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server m
The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote att
FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account cred
The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versio
In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when rest
Incorrect permission assignment in the user migration feature in Devolutions Server 2024.3.8.0 and earlier allows users
Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sono
The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Refere
The Easy Social Feed plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability
Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to vers
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application
The spring-security.xsd file inside the spring-security-config jar is world writable which means that if it were extra
stalld through 1.19.7 allows local users to cause a denial of service (file overwrite) via a /tmp/rtthrottle symlink att
Incorrect permission assignment for critical resource issue exists in Exment v6.1.4 and earlier and Exment v5.0.11 and e
The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacke
RELY-PCIe v22.2.1 to v23.1.0 does not set the Secure attribute for sensitive cookies in HTTPS sessions, which could caus
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the fail
In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.
Improper export of Android application components issue exists in 'ABEMA' App for Android prior to 10.65.0 allowing anot
Improper permission control in the mobile application (com.android.server.telecom) may lead to user information security
Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p23, < 2.2.0p38 and <= 2.1.0p49 (E
In Ocean Data Systems Dream Report, an incorrect permission vulnerability could allow a local unprivileged attacker to e
Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation
Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access o
In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1.
Exposure of Sensitive Information to an Unauthorized Actor vulnerability was discovered in Open Design Alliance CDE inWE
SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition a
Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via
PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.
Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edit
Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker t
Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProCon
Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions start
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City go
Memory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities related to direct memory
In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissio
NETSCOUT nGeniusPULSE 3.8 has Weak File Permissions Vulnerability
Improper File Permissions in NetScout nGeniusONE 6.3.2 build 904 allows authenticated remote users to gain permissions v
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x is installed w
Frequently Asked Questions
What is CWE-732?
CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-732?
There are 1,937 CVE records associated with CWE-732 in our database. Of these, 135 are critical severity, 822 are high severity, and 619 are medium severity.
How can I protect against CWE-732 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.
Detect CWE-732 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.
Get Started