Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-732

MITRE ↗

CWE-732

135
CRITICAL
822
HIGH
619
MEDIUM
95
LOW
1,711 CVEs · Page 7/35
6.7
CVE-2025-6779

An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privile

6.7
CVE-2025-8108

An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privileg

6.7
CVE-2025-34288

Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between s

6.6
CVE-2025-42997

Under certain conditions, SAP Gateway Client allows a high-privileged user to access restricted information beyond the s

6.5
CVE-2024-39967

Insecure permissions in Aginode GigaSwitch v5 allows attackers to access sensitive information via using the SCP command

6.5
CVE-2025-21566

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

6.5
CVE-2025-0374

When etcupdate encounters conflicts while merging files, it saves a version containing conflict markers in /var/db/etcup

6.5
CVE-2025-27141

Metabase Enterprise Edition is the enterprise version of Metabase business intelligence and data analytics software. Sta

6.5
CVE-2025-30682

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

6.5
CVE-2025-30687

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

6.5
CVE-2025-30688

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a

6.5
CVE-2025-3936

Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on Windows, Tridium Nia

6.5
CVE-2025-36104

IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive information from files due t

6.5
CVE-2025-10059

An improper setting of the lsid field on any sharded query can cause a crash in MongoDB routers. This issue occurs when

6.5
CVE-2025-62251

Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 through 2023.Q4.5, 7.4 GA

6.3
CVE-2025-49131

FastGPT is an open-source project that provides a platform for building, deploying, and operating AI-driven workflows an

6.1
CVE-2025-0758

Overview  The product specifies permissions for a security-critical resource in a way that allows that resource to be

6.1
CVE-2025-1139

IBM Edge Application Manager 4.5 could allow a local user to read or modify resources that they should not have authoriz

6.1
CVE-2025-67794

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 before 24.2.8, and 25.1 before 25.1.6. Directories and fi

6.0
CVE-2025-21551

Vulnerability in the Oracle Solaris product of Oracle Systems (component: File system). The supported version that is

6.0
CVE-2025-46802

For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session.

5.9
CVE-2025-0926

Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to

5.9
CVE-2025-24009

A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2

5.9
CVE-2024-11584

cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grant

5.7
CVE-2025-54618

Permission control vulnerability in the distributed clipboard module. Impact: Successful exploitation of this vulnerabil

5.5
CVE-2024-49385

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis True I

5.5
CVE-2023-38037

ActiveSupport::EncryptedFile writes contents that will be encrypted to a temporary file. The temporary file's permissi

5.5
CVE-2024-29869

Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the fil

5.5
CVE-2025-25041

A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrit

5.5
CVE-2025-23245

NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it a

5.5
CVE-2025-40572

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices

5.5
CVE-2025-31262

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS S

5.5
CVE-2025-32915

Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.

5.5
CVE-2025-48382

Fess is a deployable Enterprise Search Server. Prior to version 14.19.2, the createTempFile() method in org.codelibs.fes

5.5
CVE-2024-45655

IBM Application Gateway 19.12 through 24.09 could allow a local privileged user to perform unauthorized actions due to i

5.5
CVE-2025-43247

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma

5.5
CVE-2025-23285

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where it allows a guest to access global resou

5.5
CVE-2025-43470

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. A standard user

5.3
CVE-2025-38742

Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains an Incorrect Permission Assignment for Critical Res

5.3
CVE-2025-43808

The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1

5.3
CVE-2025-64319

Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Mulesoft Anypoint Code Builder allows

5.3
CVE-2025-64322

Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Agentforce Vibes Extension allows Mani

5.1
CVE-2025-43266

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma

5.0
CVE-2024-47475

Dell PowerScale OneFS 8.2.2.x through 9.8.0.x contains an incorrect permission assignment for critical resource vulnerab

5.0
CVE-2024-45657

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privileged user to perform

5.0
CVE-2025-48747

Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incor

5.0
CVE-2025-5819

An issue has been discovered in GitLab CE/EE affecting all versions from 15.7 before 18.0.6, 18.1 before 18.1.4, and 18.

4.9
CVE-2025-21523

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are

4.9
CVE-2025-21579

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are aff

4.9
CVE-2025-21580

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte

Frequently Asked Questions

What is CWE-732?

CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-732?

There are 1,937 CVE records associated with CWE-732 in our database. Of these, 135 are critical severity, 822 are high severity, and 619 are medium severity.

How can I protect against CWE-732 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.

Detect CWE-732 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.

Get Started