A vulnerability in the filesystem management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mo
Improper file permissions in the installer for Intel(R) Easy Streaming Wizard before version 2.1.0731 may allow an authe
In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control"
The PKI keys exported using the command "run request security pki key-pair export" on Junos OS may have insecure file pe
An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors m
The Spotfire Library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO
A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events
WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions gran
In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has it
An information disclosure vulnerability exists in the way Azure WaLinuxAgent creates swap files on resource disks, aka '
Incorrect Access Controls of Security Officer (SO) in PKCS11 R2 provider that ships with the Utimaco CryptoServer HSM pr
An Insecure Permissions issue (issue 1 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11
An Insecure Permissions issue (issue 2 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11
Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows ma
Improper data access control in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows authenticated user
Incorrect access control in the mail templating system in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and e
Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions.
The orbisius-child-theme-creator plugin before 1.2.8 for WordPress has incorrect access control for file modification vi
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute va
Insufficient filtering in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass multiple file
Insufficient policy enforcement in site isolation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to by
Insufficient access control in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (a
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be rea
It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt e
Improper file permissions for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to p
Improper file permissions for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to p
In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administra
The permissions on /proc/iomem were world-readable. This could lead to local information disclosure with no additional e
An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy's Games, vers
A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved
A permissions issue existed in the handling of the Apple ID. This issue was addressed with improved access controls. Thi
The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user
There is an information disclosure vulnerability on Secure Input of certain Huawei smartphones in Versions earlier than
cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435).
lib/install/install.go in cnlh nps through 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, lead
An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-tex
There is an improper access control vulnerability in Huawei Share. The software does not properly restrict access to cer
OpenStack nova base images permissions are world readable
In various functions of RecentLocationApps.java, DevicePolicyManagerService.java, and RecognitionService.java, there is
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readab
cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429).
An issue was discovered in GitLab Community and Enterprise Edition 10.8 through 12.2.1. An internal endpoint unintention
Incorrect scoping of kill operations in MongoDB Server's packaged SysV init scripts allow users with write access to the
SilverStripe through 4.3.3 has incorrect access control for protected files uploaded via Upload::loadIntoFile(). An atta
Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable V
An issue was discovered in GitLab Community and Enterprise Edition 11.3 to 12.3 in the protected environments feature. I
An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4 when moving an issue to a public pr
An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by E
PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation o
IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by insecure file permissions. I
Frequently Asked Questions
What is CWE-732?
CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-732?
There are 1,937 CVE records associated with CWE-732 in our database. Of these, 135 are critical severity, 822 are high severity, and 619 are medium severity.
How can I protect against CWE-732 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.
Detect CWE-732 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.
Get Started