electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vul
Incorrect permission assignment for critical resource issue exists in ServerView Agents for Windows V11.60.04 and earlie
Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint addres
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a l
Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may all
A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attac
Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. In
Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate pri
A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to in
Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability al
OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, al
When a certificate and its private key are installed in the Windows machine certificate store using Network and Security
Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directo
IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to esca
A local information disclosure vulnerability exists in the Ludashi driver before 5.1025 due to a lack of access control
Briefcase is a tool for converting a Python project into a standalone native application. Starting in version 0.3.0 and
Dell AppSync, version(s) 4.6.0, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low
FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to P
A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated r
A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege
wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46
HP System Event Utility might allow denial of service with elevated arbitrary file writes. This potential vulnerability
A vulnerability in uutils coreutils mkfifo allows for the unauthorized modification of permissions on existing files. Wh
A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the sys
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is
npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attack
Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attacker
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible l
Docker Desktop for Windows contains multiple incorrect permission assignment vulnerabilities in the installer's handling
Incorrect permission assignment for critical resource for some System Firmware Update Utility (SysFwUpdt) for Intel(R) S
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis True Image (
ACAP applications can gain elevated privileges due to improper input validation during the installation process, potenti
IBM Storage Scale IBM S through rage Scale 5.2.3.0 - 5.2.3.5, and IBM S through rage Scale 6.0.0.0 - 6.0.0.1 could allow
erase-install prior to v40.4 commit 2c31239 writes swiftDialog credential output to a hardcoded path /var/tmp/dialog.jso
In Nmap Scanner versions below 3.0.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR co
Tanium addressed an insecure file permissions vulnerability in Enforce Recovery Key Portal.
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3
An unauthenticated remote attacker who tricks a user to upload a manipulated HTML file can get access to sensitive infor
SiYuan is a personal knowledge management system. Prior to 3.6.1, POST /api/template/renderSprig lacks model.CheckAdminR
Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filterin
Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command which m
Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics command
Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and i
Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced
This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS
Hermes WebUI before 0.51.521 validates the workspace of an imported session under the active named profile but construct
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the rest_propertie
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, d
Vulnerability in the Oracle Succession planning product of Oracle E-Business Suite (component: Succession plan). Suppor
NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a laten
Frequently Asked Questions
What is CWE-732?
CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-732?
There are 1,937 CVE records associated with CWE-732 in our database. Of these, 135 are critical severity, 822 are high severity, and 619 are medium severity.
How can I protect against CWE-732 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.
Detect CWE-732 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.
Get Started