Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerab
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) mount host configu
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.843 and Application prior to version 2
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allow
An incorrect default permissions vulnerability exists in the CServerSettings::SetRegistryValues functionality of MedDrea
The com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through 1.1 for Android enables any appli
The com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: Call Screen Theme) application through 21.1.
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker
A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions). The affected applica
Wondershare Repairit Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remo
An issue in the snxpcamd.sys component of SUNIX Multi I/O Card v10.1.0.0 allows attackers to perform arbitrary read and
An authenticated attacker can use this vulnerability to perform a privilege escalation to gain root access.
The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escape vulnerab
Insecure permissions in measure-cold-start v1.4.1 allows attackers to escalate privileges and compromise the customer cl
Insecure permissions in fc-stable-diffusion-plus v1.0.18 allows attackers to escalate privileges and compromise the cust
Insecure permissions in autodeploy-layer v1.2.0 allows attackers to escalate privileges and compromise the customer clou
Multiple Incorrect Permission Assignment for Critical Resource in UISP Application may allow a malicious actor with cert
A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installat
Ross Video DashBoard 8.5.1 contains an elevation of privileges vulnerability that allows authenticated users to modify e
Epic Games Psyonix Rocket League <=1.95 contains an insecure permissions vulnerability that allows authenticated users t
Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allo
IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could all
NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are expose
AspEmail 5.6.0.2 contains a binary permission vulnerability that allows local users to escalate privileges through the P
Wondershare MirrorGo 2.0.11.346 contains a local privilege escalation vulnerability due to incorrect file permissions on
A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and wri
NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and o
It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services).
IXON VPN Client before 1.4.4 on Linux and macOS allows Local Privilege Escalation to root because there is code executio
IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there is code execution from
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vul
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management oper
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management ope
An issue was discovered in Akamai Enterprise Application Access (EAA) before 2025-01-17. If an admin knows another tenan
In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to
NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which
In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to
In Splunk Universal Forwarder for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an u
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacke
Dell ThinOS 2408 and prior, contains an improper permissions vulnerability. A low privileged attacker with local access
A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux) versions older than 1.3.
An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware
Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder.This issue affects Automat
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices
GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local atta
Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listeni
GPMAW 14, a bioinformatics software, has a critical vulnerability related to insecure file permissions in its installati
Insecure Permissions vulnerability in PDQ Smart Deploy V.3.0.2040 allows a local attacker to execute arbtirary code via
Frequently Asked Questions
What is CWE-732?
CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-732?
There are 1,937 CVE records associated with CWE-732 in our database. Of these, 135 are critical severity, 822 are high severity, and 619 are medium severity.
How can I protect against CWE-732 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.
Detect CWE-732 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.
Get Started