A flaw was found in the KubeVirt main virt-handler versions before 0.26.0 regarding the access permissions of virt-handl
Incorrect permission assignment for critical resource vulnerability in QSAN Storage Manager allows authenticated remote
In SapphireIMS 4097_1, a guest user is able to change the password of an administrative user by utilizing an Insecure Di
Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to
GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autolo
In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated u
HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-cr
PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 databa
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker En
A potential security vulnerability has been identified in HPE Superdome Flex Servers. The vulnerability could be remotel
This affects the package fastify-csrf before 3.0.0. 1. The generated cookie used insecure defaults, and did not have the
When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0,
The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate
In several functions of GlobalScreenshot.java, there is a possible permission bypass due to an unsafe PendingIntent. Thi
A vulnerability in the storage of proxy server credentials of Cisco Firepower Management Center (FMC) could allow an aut
An issue was discovered in Psyprax before 3.2.2. The file %PROGRAMDATA%\Psyprax32\PPScreen.ini contains a hash for the l
Dell EMC PowerScale OneFS versions 8.1.0-9.1.0 contain a Backup/Restore Privilege implementation issue. A user with the
HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations thro
HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations thro
An insecure file permissions vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could al
The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with c
A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of
In doNotification of AccountManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent. T
In getEndItemSliceAction of MediaOutputSlice.java, there is a possible permission bypass due to an unsafe PendingIntent.
In cPanel before 96.0.8, weak permissions on web stats can lead to information disclosure (SEC-584).
An inherited permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.0.1,
A permissions issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.0.1. A local attack
An inherited permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.1, w
An Incorrect Permission Assignment for Critical Resource vulnerability of a certain file in the filesystem of Junos OS a
HGiga EIP product lacks ineffective access control in certain pages that allow attackers to access database or perform p
swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set th
In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly.
In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferre
IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 could allow a remote attacker to obtain sensitive information, ca
The access controls on the Mobility read-only API improperly validate user access permissions. Attackers with both netwo
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set t
IBM Security SiteProtector System 3.1.1 could allow a remote attacker to obtain sensitive information, caused by missing
containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and ext
MK-AUTH through 19.01 K4.9 allows XSS via the admin/logs_ajax.php tipo parameter. An attacker can leverage this to read
A vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Sof
Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access r
InspIRCd 3.8.0 through 3.9.x before 3.10.0 allows any user (able to connect to the server) to access recently deallocate
Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify loyalty campaigns and se
An issue was discovered in the Translate extension in MediaWiki through 1.36. The Aggregategroups Action API module does
NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Authorization Bypass (to access an endpoint) in FDSQueryService.
In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project
"HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron App
A Incorrect Permission Assignment for Critical Resource vulnerability in skuba of SUSE CaaS Platform 4.5 allows local at
HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID
Frequently Asked Questions
What is CWE-732?
CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-732?
There are 1,937 CVE records associated with CWE-732 in our database. Of these, 135 are critical severity, 822 are high severity, and 619 are medium severity.
How can I protect against CWE-732 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.
Detect CWE-732 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.
Get Started