Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-732

MITRE ↗

CWE-732

135
CRITICAL
822
HIGH
619
MEDIUM
95
LOW
1,711 CVEs · Page 27/35
6.7
CVE-2019-1803

A vulnerability in the filesystem management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mo

6.7
CVE-2019-11166

Improper file permissions in the installer for Intel(R) Easy Streaming Wizard before version 2.1.0731 may allow an authe

6.6
CVE-2019-14743

In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control"

6.6
CVE-2019-0073

The PKI keys exported using the command "run request security pki key-pair export" on Junos OS may have insecure file pe

6.5
CVE-2019-0588

An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors m

6.5
CVE-2018-18812

The Spotfire Library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO

6.5
CVE-2018-12396

A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events

6.5
CVE-2018-18495

WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions gran

6.5
CVE-2018-12546

In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has it

6.5
CVE-2019-0804

An information disclosure vulnerability exists in the way Azure WaLinuxAgent creates swap files on resource disks, aka '

6.5
CVE-2018-19589

Incorrect Access Controls of Security Officer (SO) in PKCS11 R2 provider that ships with the Utimaco CryptoServer HSM pr

6.5
CVE-2019-10110

An Insecure Permissions issue (issue 1 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11

6.5
CVE-2019-10115

An Insecure Permissions issue (issue 2 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11

6.5
CVE-2019-8283

Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows ma

6.5
CVE-2018-14861

Improper data access control in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows authenticated user

6.5
CVE-2018-14862

Incorrect access control in the mail templating system in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and e

6.5
CVE-2018-12357

Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions.

6.5
CVE-2015-9456

The orbisius-child-theme-creator plugin before 1.2.8 for WordPress has incorrect access control for file modification vi

6.5
CVE-2019-14824

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute va

6.5
CVE-2019-13665

Insufficient filtering in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass multiple file

6.5
CVE-2019-13677

Insufficient policy enforcement in site isolation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to by

6.3
CVE-2018-12223

Insufficient access control in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (a

6.1
CVE-2019-19736

MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be rea

5.7
CVE-2018-14662

It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt e

5.5
CVE-2019-0108

Improper file permissions for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to p

5.5
CVE-2019-0111

Improper file permissions for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to p

5.5
CVE-2018-9867

In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administra

5.5
CVE-2019-2001

The permissions on /proc/iomem were world-readable. This could lead to local information disclosure with no additional e

5.5
CVE-2018-4051

An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy's Games, vers

5.5
CVE-2018-4178

A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved

5.5
CVE-2018-4324

A permissions issue existed in the handling of the Apple ID. This issue was addressed with improved access controls. Thi

5.5
CVE-2019-13142

The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user

5.5
CVE-2019-5222

There is an information disclosure vulnerability on Secure Input of certain Huawei smartphones in Versions earlier than

5.5
CVE-2018-20908

cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435).

5.5
CVE-2019-15119

lib/install/install.go in cnlh nps through 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, lead

5.5
CVE-2019-3866

An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-tex

5.5
CVE-2019-5212

There is an improper access control vulnerability in Huawei Share. The software does not properly restrict access to cer

5.5
CVE-2013-0326

OpenStack nova base images permissions are world readable

5.5
CVE-2019-9464

In various functions of RecentLocationApps.java, DevicePolicyManagerService.java, and RecognitionService.java, there is

5.5
CVE-2019-19341

A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readab

5.4
CVE-2018-20905

cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429).

5.4
CVE-2019-15721

An issue was discovered in GitLab Community and Enterprise Edition 10.8 through 12.2.1. An internal endpoint unintention

5.3
CVE-2019-2389

Incorrect scoping of kill operations in MongoDB Server's packaged SysV init scripts allow users with write access to the

5.3
CVE-2019-12245

SilverStripe through 4.3.3 has incorrect access control for protected files uploaded via Upload::loadIntoFile(). An atta

5.3
CVE-2019-6465

Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable V

5.3
CVE-2019-18459

An issue was discovered in GitLab Community and Enterprise Edition 11.3 to 12.3 in the protected environments feature. I

5.3
CVE-2019-18452

An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4 when moving an issue to a public pr

5.3
CVE-2019-18456

An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by E

5.3
CVE-2011-2515

PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation o

5.1
CVE-2018-1787

IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by insecure file permissions. I

Frequently Asked Questions

What is CWE-732?

CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-732?

There are 1,937 CVE records associated with CWE-732 in our database. Of these, 135 are critical severity, 822 are high severity, and 619 are medium severity.

How can I protect against CWE-732 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.

Detect CWE-732 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.

Get Started