A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-au
SolarWinds N-Central version 12.3 GA and lower does not set the JSESSIONID attribute to HTTPOnly. This makes it possible
Ingenico Telium 2 POS Telium2 OS allow bypass of file-reading restrictions via the NTPT3 protocol. This is fixed in Teli
During installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, wi
In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vuln
Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 1 of 2).
Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 2 of 2).
GitLab Enterprise Edition (EE) 11.9 and later through 12.5 has Insecure Permissions.
GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions.
IBM Quality Manager (RQM) 6.02, 6.06, and 6.0.6.1 could allow an authenticated user to create keywords through the REST
An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, and 4.3.4. It mishandled webhook access control in the
An issue was discovered in Mattermost Server before 5.1, 5.0.2, and 4.10.2. An attacker could use the invite_people slas
An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access control (for direct-mess
An issue was discovered in Mattermost Server before 5.1. Non-members of a channel could use the Channel PATCH API to mod
An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. An e-mail invite accidentally included the
An issue was discovered in Mattermost Server before 4.4.3 and 4.3.3. Attackers could reconfigure an OAuth app in some ca
An issue was discovered in Mattermost Server before 5.2, 5.1.1, 5.0.3, and 4.10.3. Attackers could use multiple e-mail a
An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking a
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. E-mail notifications can have spoofed links
An issue was discovered in Mattermost Server before 3.3.0. An attacker could use the WebSocket feature to send pop-up me
An issue was discovered in Mattermost Server before 3.0.0. It offers superfluous APIs for a Team Administrator to view a
An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified b
debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whe
A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine
An issue was discovered in Mattermost Server before 3.0.0. It has a superfluous API in which the System Admin can change
A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified
In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and co
Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control (issue 2 of 2).
Systems using the Marel Food Processing Systems Pluto platform do not restrict remote access. Marel has created an updat
Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSh
Kromtech MacKeeper 3.20.4 suffers from a root privilege escalation vulnerability through its `com.mackeeper.AdwareAnalyz
DGLogik Inc DGLux Server All Versions is affected by: Insecure Permissions. The impact is: Remote Execution, Credential
Akeo Consulting Rufus 3.0 and earlier is affected by: Insecure Permissions. The impact is: arbitrary code execution with
In Univa Grid Engine before 8.6.3, when configured for Docker jobs and execd spooling on root_squash, weak file permissi
Creative Cloud Desktop Application versions 4.6.1 and earlier have an insecure inherited permissions vulnerability. Succ
An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable t
Adobe Download Manager versions 2.0.0.363 have an insecure file permissions vulnerability. Successful exploitation could
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class an
ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulner
Kentico 11 through 12 lets attackers upload and explore files without authentication via the cmsmodules/medialibrary/for
LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.
browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windo
Improper access control and open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168
The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater ac
Imperva SecureSphere running v13.0, v12.0, or v11.5 allows low privileged users to add SSH login keys to the admin user,
UiPath Orchestrator through 2018.2.4 allows any authenticated user to change the information of arbitrary users (even ad
Insecure permissions in the Web management portal on all IP cameras based on Hisilicon Hi3510 firmware allow authenticat
An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sie
An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sie
Frequently Asked Questions
What is CWE-732?
CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-732?
There are 1,937 CVE records associated with CWE-732 in our database. Of these, 135 are critical severity, 822 are high severity, and 619 are medium severity.
How can I protect against CWE-732 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.
Detect CWE-732 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.
Get Started