Supermicro X11SSL-CF HW Rev 1.01, BMC firmware v1.63 was discovered to contain insecure permissions.
A permission misconfiguration in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow an user to hijack VP
A vulnerability has been identified in SICAM P850 (7KG8500-0AA00-0AA0) (All versions < V3.11), SICAM P850 (7KG8500-0AA00
In multiple files, there is a possible way to access traces in the dev mode due to a permissions bypass. This could lead
Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SE
An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure. An atta
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3. An app
Broken access control in the Registration page (/Registration.aspx) of Termenos CWX v8.5.6 allows attackers to access se
An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbi
A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (
An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allo
xxl-job-admin 2.4.0 is vulnerable to Insecure Permissions via /xxl-job-admin/joblog/clearLog and /xxl-job-admin/joblog/l
The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensu
In Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp.
Permissions vulnerability found in isoftforce Dreamer CMS v.4.0.1 allows local attackers to obtain sensitive information
Cassia Access controller before 2.1.1.2203171453, was discovered to have a unprivileged -information disclosure vulnerab
IBM Security Directory Suite VA 8.0.1 specifies permissions for a security-critical resource in a way that allows that r
A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the
Vulnerability of improper permission management in the displayengine module. Successful exploitation of this vulnerabili
Broadcast permission control vulnerability in the framework module. Successful exploitation of this vulnerability may ca
An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before
Planet is software that provides satellite data. The secret file stores the user's Planet API authentication information
An Incorrect Permission Assignment for Critical Resource vulnerability in a specific file of Juniper Networks Junos OS
In BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and a
When Akka HTTP before 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll directive, the temporary fi
An issue was discovered in Click Studios Passwordstate before 9811. Existing users (Security Administrators) could use t
A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authentica
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to create a file or overw
A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged use
Bhima version 1.27.0 allows an authenticated attacker with regular user permissions to update arbitrary user session dat
No access control for the OTP key on OTP entries in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prio
IBM API Connect V10 could allow an authenticated user to perform actions that they should not have access to. IBM X-For
Jenkins Email Extension Plugin does not perform a permission check in a method implementing form validation, allowing at
A missing permission check in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers with Overall/Read permission
An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. Upon an a
Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution
An issue was discovered in the PageTriage extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, a
A vulnerability classified as problematic has been found in PHPGurukul Online Notes Sharing System 1.0. Affected is an u
Discourse is an open source platform for community discussion. In affected versions a user logged as an administrator ca
The FACSChorus software database can be accessed directly with the privileges of the currently logged-in user. A threat
IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.4 could allow a local user to perform unauthorized act
Azure/setup-kubectl is a GitHub Action for installing Kubectl. This vulnerability only impacts versions before version 3
Nextcloud server is an open source, personal cloud implementation. In versions from 24.0.0 and before 24.0.9 a user coul
SAP Cloud Connector - version 2.0, allows an authenticated user with low privilege to perform Denial of service attack f
Default permissions for a properties file were too permissive. Local system users could read potentially sensitive infor
Gradle is a build tool with a focus on build automation and support for multi-language development. When copying or arch
An issue was discovered in Exynos Mobile Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, and E
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware
A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, where the s
An incorrect permission check in Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier allows attackers with g
Frequently Asked Questions
What is CWE-732?
CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-732?
There are 1,937 CVE records associated with CWE-732 in our database. Of these, 135 are critical severity, 822 are high severity, and 619 are medium severity.
How can I protect against CWE-732 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.
Detect CWE-732 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.
Get Started