The Canon TR150 print driver through 3.71.2.10 is vulnerable to a privilege escalation issue. During the add printer pro
Docker Desktop before 3.6.0 suffers from incorrect access control. If a low-privileged account is able to access the ser
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for critical resource vulner
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for critical resource vulner
Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker
Visual Studio Elevation of Privilege Vulnerability
It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) i
A user-writable application bundle unpacked during the install for all versions of the Zoom Plugin for Microsoft Outlook
In sendBroadcastToInstaller of FirstScreenBroadcast.java, there is a possible activity launch due to an unsafe PendingIn
An insecure modification flaw in the /etc/passwd file was found in the openjdk-1.8 and openjdk-11 containers. This flaw
An issue was discovered in Nagios XI 5.8.5. Insecure file permissions on the nagios_unbundler.py file allow the nagios u
OpenClinic GA 5.194.18 is affected by Insecure Permissions. By default the Authenticated Users group has the modify perm
A vulnerability has been identified in SENTRON powermanager V3 (All versions). The affected application assigns improper
Zoho Remote Access Plus Server Windows Desktop Binary fixed from 10.1.2121.1 is affected by incorrect access control. Th
Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit audio driver pack before version 1.3
Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit Serial IO driver pack before version
Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit Keyboard LED Service driver pack bef
Insecure inherited permissions in the Intel(R) PROSet/Wireless WiFi software installer for Windows 10 before version 22.
Adobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources lev
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to
A incorrect permission assignment for critical resource in Fortinet FortiNAC version 9.2.0, version 9.1.3 and below, ver
Mesa Labs AmegaView Versions 3.0 and prior has insecure file permissions that could be exploited to escalate privileges
All known versions of the Netgear Genie Installer for macOS contain a local privilege escalation vulnerability. The inst
The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon
Insecure File Permissions exist in Aviatrix Controller 5.3.1516. Several world writable files and directories were found
A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to al
In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.
Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud
Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment vulnerability. A low privile
Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server
adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag
Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, G
Windows 10 Update Assistant Elevation of Privilege Vulnerability
Insecure inherited permissions in some Intel(R) ProSet/Wireless WiFi drivers may allow an authenticated user to potentia
The database connection to the server is performed by calling a specific API, which could allow an unprivileged user to
Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password
Bitmask Riseup VPN 0.21.6 contains a local privilege escalation flaw due to improper access controls. When the software
An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a pro
In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' pas
Wowza Streaming Engine through 4.8.5 (in a default installation) has incorrect file permissions of configuration files i
The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in Tr
Dell EMC PowerScale OneFS versions 8.1.2 and 8.2.2 contain an Incorrect Permission Assignment for a Critical Resource vu
An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacke
World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local attacker to comp
The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by
It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate user
In SRAMROM, there is a possible permission bypass due to an insecure permission setting. This could lead to local escala
Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get pe
Insufficient policy enforcement in Autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain p
A user authorized to performing a specific type of find query may trigger a denial of service. This issue affects MongoD
Frequently Asked Questions
What is CWE-732?
CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-732?
There are 1,937 CVE records associated with CWE-732 in our database. Of these, 135 are critical severity, 822 are high severity, and 619 are medium severity.
How can I protect against CWE-732 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.
Detect CWE-732 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.
Get Started