Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges vi
Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file na
Missing permission checks in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allow attackers with Overall/Read
Yank Note (YN) 3.52.1 allows execution of arbitrary code when a crafted file is opened, e.g., via nodeRequire('child_pro
In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile
Incorrect Execution-Assigned Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation. This iss
Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbit
PyInstaller bundles a Python application and all its dependencies into a single package. A PyInstaller built application
A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with
Request to LDAP is sent before user permissions are checked.
An Incorrect Permission Assignment for Critical Resource vulnerability in Juniper Networks Junos OS Evolved allows a loc
Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may
Vulnerability of undefined permissions in HUAWEI VR screen projection.Successful exploitation of this vulnerability will
A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q3). The affected product assigns improper ac
An issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Servic
Insecure permissions in the settings page of GARO Wallbox GLB/GTB/GTC before v189 allows attackers to redirect users to
An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any u
RoboDK versions 5.5.3 and prior contain an insecure permission assignment to critical directories vulnerability, which
Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Ru
Dentsply Sirona Sidexis <= 4.3 is vulnerable to Incorrect Access Control.
A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege e
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could set in
An issue was discovered in Genomedics MilleGP5 5.9.2, allows remote attackers to execute arbitrary code and gain escalat
OpenText Documentum Content Server before 23.2 has a flaw that allows for privilege escalation from a non-privileged Doc
Insecure permissions in MobileTrans v4.0.11 allows attackers to escalate privileges to local admin via replacing the exe
Incorrect permission assignment for critical resource exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. ACL
A vulnerability has been identified in SIMATIC WinCC (All versions < V7.5.2.13). Affected applications fail to set prope
SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by crashing t
Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration fi
A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.10). Affected applications do not properly s
A vulnerability, which was classified as critical, was found in MicroWorld eScan Anti-Virus 7.0.32 on Linux. This affect
Wacom Drivers for Windows Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability a
A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application assigns improper access
A vulnerability has been identified in SICAM PAS/PQS (All versions >= V8.00 < V8.20). The affected application is instal
SECUDOS Qiata (DOMOS OS) 4.13 has Insecure Permissions for the previewRm.sh daily cronjob. To exploit this, an attacker
Local attacker can escalate privileges on affected installations of Check Point Harmony Endpoint/ZoneAlarm Extreme Secur
Honeywell ProWatch, 4.5, including all Service Pack versions, contain a Vulnerability in Application Server's executable
An issue was discovered in Mullvad VPN Windows app before 2023.6-beta1. Insufficient permissions on a directory allow an
A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Serie
The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditio
An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege an
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and vi
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and vi
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 pr
Insecure inherited permissions in the Intel(R) oneAPI Toolkits oneapi-cli before version 0.2.0 may allow an authenticate
Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and
NVIDIA DGX-2 SBIOS contains a vulnerability where an attacker may modify the ServerSetup NVRAM variable at runtime by ex
The window management module lacks permission verification.Successful exploitation of this vulnerability may affect conf
Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This iss
Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This iss
Frequently Asked Questions
What is CWE-732?
CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-732?
There are 1,937 CVE records associated with CWE-732 in our database. Of these, 135 are critical severity, 822 are high severity, and 619 are medium severity.
How can I protect against CWE-732 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.
Detect CWE-732 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.
Get Started