A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application,
NVIDIA distributions of Jetson Linux contain a vulnerability where an error in the IOMMU configuration may allow an unpr
An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker co
In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.
BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber
Within the Service Desk module of the ITarian platform (SAAS and on-premise), a remote attacker can obtain sensitive inf
The Log WP_Mail WordPress plugin through 0.1 saves sent email in a publicly accessible directory using predictable filen
In universal forwarder versions before 9.0, management services are available remotely by default. When not required, it
In Car Settings app, the NotificationAccessConfirmationActivity is exported. In NotificationAccessConfirmationActivity,
An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7
An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7
Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions.
Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie
A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP
In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowi
Incorrect permissions for the folder C:\ProgramData\NoMachine\var\uninstall of Nomachine v7.9.2 allows attackers to perf
An Incorrect Permission Assignment vulnerability in shell processing of Juniper Networks Junos OS Evolved allows a low-p
Talos Linux is a Linux distribution built for Kubernetes deployments. Talos worker nodes use a join token to get accepte
Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclos
Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inj
An incorrect permission assignment for critical resource vulnerability [CWE-732] in FortiClient for Linux version 6.0.8
PCProtect Endpoint prior to v5.17.470 for Microsoft Windows lacks tamper protection, allowing authenticated attackers wi
IObit Malware Fighter v9.2 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administ
Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.
A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created Servi
In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the pass
On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ing
A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel exec
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.
Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows
Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrato
An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session
An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstal
IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow
The default privileges for the running service Normand Message Buffer in Beckman Coulter Remisol Advance v2.0.12.1 and p
Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated priv
g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nod
ZTE OTCP product is impacted by a permission and access control vulnerability. Due to improper permission settings, an a
Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one
A local unprivileged attacker may escalate to administrator privileges in Honeywell SoftMaster version 4.51, due to inse
An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRo
The affected product is vulnerable to misconfigured binaries, allowing users on the target PC with SYSTEM level privileg
TMS v2.28.0 contains an insecure permissions vulnerability via the component /TMS/admin/user/Update2. This vulnerability
Moby is an open-source project created by Docker to enable and accelerate software containerization. A bug was found in
CBRN-Analysis before 22 has weak file permissions under Public Profile, leading to disclosure of file contents or privil
It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with wor
In the SEPolicy configuration of system apps, there is a possible access to the 'ip' utility due to an insecure default
The default privileges for the running service Normand Viewer Service in Beckman Coulter Remisol Advance v2.0.12.1 and p
Frequently Asked Questions
What is CWE-732?
CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-732?
There are 1,937 CVE records associated with CWE-732 in our database. Of these, 135 are critical severity, 822 are high severity, and 619 are medium severity.
How can I protect against CWE-732 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.
Detect CWE-732 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.
Get Started