CWE-275
116 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-275page 2 of 3
- CVE-2023-6302HIGHCVSS 7.2EG 7.22023-11-27
A vulnerability was found in CSZCMS 1.3.0 and classified as critical. Affected by this issue is some unknown functionality of the file \views\templates of the component File Manager Page. The manipulation leads to permission issues. The at…
- CVE-2017-8153HIGHCVSS 7.1EG 7.12017-11-22
Huawei VMall (for Android) with the versions before 1.5.8.5 have a privilege elevation vulnerability due to improper design. An attacker can trick users into installing a malicious app which can send out HTTP requests and execute JavaScrip…
- CVE-2015-7842HIGHCVSS 7.1EG 7.12017-10-10
Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V100R003C00SPC503, XH628 V3 with software before V100R003C00SPC602, RH1288 V3 with software before V100R003C00SPC602, RH2288…
- CVE-2026-28553MEDIUMCVSS 6.9EG 6.92026-04-13
Vulnerability of improper permission control in the theme setting module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2020-3152MEDIUMCVSS 6.7EG 6.72020-08-26
A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administrative credentials to execute arbitrary commands with root privileges. The vulnerability is due to improper user permissi…
- CVE-2016-8214MEDIUMCVSS 6.7EG 6.72017-01-25
EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) versions 7.3.0 and 7.3.1 contain a vulnerability that may allow malicious administrators to compromise Avamar servers.
- CVE-2026-41976MEDIUMCVSS 6.6EG 6.62026-06-09
Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2016-10818MEDIUMCVSS 6.5EG 6.52019-08-01
cPanel before 57.9999.54 incorrectly sets log-file permissions in dnsadmin-startup and spamd-startup (SEC-124).
- CVE-2017-9327MEDIUMCVSS 6.5EG 6.52019-07-03
Secret data of processes managed by CM is not secured by file permissions.
- CVE-2016-3022MEDIUMCVSS 6.5EG 6.52017-02-01
IBM Security Access Manager for Web could allow an authenticated user to gain access to highly sensitive information due to incorrect file permissions.
- CVE-2017-0883MEDIUMCVSS 6.4EG 6.42017-04-05
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared files with an increasi…
- CVE-2026-105165MEDIUMCVSS 6.3EG 6.32026-10-04
A vulnerability has been found in devopspolis secrets-replicator up to 0.4.0. Impacted is the function process_single_secret of the file src/handler.py of the component AssumeRole Handler. Such manipulation of the argument external_id lead…
- CVE-2026-75978MEDIUMCVSS 6.3EG 6.32026-08-19
A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affected element is the function DataSourceController.add of the file DataSourceController.java of the component QueryerFactory. Such manipulat…
- CVE-2024-11485MEDIUMCVSS 6.3EG 6.32024-11-20
A vulnerability, which was classified as critical, has been found in Code4Berry Decoration Management System 1.0. Affected by this issue is some unknown functionality of the file /decoration/admin/userregister.php of the component User Han…
- CVE-2024-3118MEDIUMCVSS 6.3EG 6.32024-03-31
A vulnerability, which was classified as critical, has been found in Dreamer CMS up to 4.1.3. This issue affects some unknown processing of the component Attachment Handler. The manipulation leads to permission issues. The attack may be in…
- CVE-2023-3759MEDIUMCVSS 6.3EG 6.32023-07-19
A vulnerability, which was classified as critical, was found in Intergard SGS 8.7.0. Affected is an unknown function. The manipulation leads to permission issues. It is possible to launch the attack remotely. The exploit has been disclosed…
- CVE-2026-49311MEDIUMCVSS 6.2EG 6.22026-09-09
Permission control vulnerability in the event notification module.Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-41969MEDIUMCVSS 6.2EG 6.22026-05-15
Permission control vulnerability in the projection module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2017-7088MEDIUMCVSS 5.9EG 5.92017-10-23
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Exchange ActiveSync" component. It allows remote attackers to erase a device in opportunistic circumstances by hijacking a cleartext Auto…
- CVE-2025-54624MEDIUMCVSS 5.7EG 5.72025-08-06
Unexpected injection event vulnerability in the multimodalinput module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2025-54618MEDIUMCVSS 5.7EG 5.72025-08-06
Permission control vulnerability in the distributed clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2025-53168MEDIUMCVSS 5.7EG 5.72025-07-07
Vulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful exploitation of this vulnerability may allow the peer device to use the camera without user awareness.
- CVE-2025-58288MEDIUMCVSS 5.5EG 5.52025-10-11
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
- CVE-2021-22571MEDIUMCVSS 5.5EG 5.52022-03-18
A local attacker could read files from some other users' SA360 reports stored in the /tmp folder during staging process before the files are loaded in BigQuery. We recommend upgrading to version 1.0.3 or above.
- CVE-2020-6022MEDIUMCVSS 5.5EG 5.52020-10-27
Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to delete arbitrary files while restoring files in Anti-Ransomware.
- CVE-2019-12622MEDIUMCVSS 5.5EG 5.52019-08-21
A vulnerability in Cisco RoomOS Software could allow an authenticated, local attacker to write files to the underlying filesystem with root privileges. The vulnerability is due to insufficient permission restrictions on a specific process.…
- CVE-2018-0392MEDIUMCVSS 5.5EG 5.52018-07-18
A vulnerability in the CLI of Cisco Policy Suite could allow an authenticated, local attacker to access files owned by another user. The vulnerability is due to insufficient access control permissions (i.e., World-Readable). An attacker co…
- CVE-2013-4040MEDIUMCVSS 5.5EG 5.52018-05-01
IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2.x before 7.2.1.5 and 7.2.x before 7.2.2.0 on Unix use weak permissions (755) for unspecified configuration and log files, which allows local users to obtain sensitive inform…
- CVE-2017-5809MEDIUMCVSS 5.5EG 5.52018-02-15
A Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found.
- CVE-2015-7889MEDIUMCVSS 5.5EG 5.52017-12-28
The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions for the com.samsung.android.email.intent.action.QUICK_REPLY_BACKGROUND service action, which might allow remote attacker…
- CVE-2016-4924MEDIUMCVSS 5.5EG 5.52017-10-13
An incorrect permissions vulnerability in Juniper Networks Junos OS on vMX may allow local unprivileged users on a host system read access to vMX or vPFE images and obtain sensitive information contained in them such as private cryptograph…
- CVE-2015-8223MEDIUMCVSS 5.5EG 5.52017-04-13
Huawei P7 before P7-L00C17B851, P7-L05C00B851, and P7-L09C92B85, and P8 ALE-UL00 before ALE-UL00B211 allows local users to cause a denial of service (OS crash) by leveraging camera permissions and via crafted input to the camera driver.
- CVE-2016-9869MEDIUMCVSS 5.5EG 5.52017-01-06
An issue was discovered in EMC ScaleIO versions before 2.0.1.1. Incorrect permissions on the SCINI driver may allow a low-privileged local attacker to modify the configuration and render the ScaleIO Data Client (SDC) server unavailable.
- CVE-2016-6719MEDIUMCVSS 5.5EG 5.52016-11-25
An elevation of privilege vulnerability in the Bluetooth component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to pair wit…
- CVE-2016-6715MEDIUMCVSS 5.5EG 5.52016-11-25
An elevation of privilege vulnerability in the Framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could allow a local malicious application to record audio w…
- CVE-2017-1418MEDIUMCVSS 4.0EG 5.52018-11-26
IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0.9) has insecure permissions on certain files. A local attacker could exploit this vulnerability to modify or delete th…
- CVE-2023-6762MEDIUMCVSS 4.3EG 5.42023-12-13
A vulnerability, which was classified as critical, was found in Thecosy IceCMS 2.0.1. Affected is an unknown function of the file /article/DelectArticleById/ of the component Article Handler. The manipulation leads to permission issues. It…
- CVE-2026-12201MEDIUMCVSS 5.3EG 5.32026-06-15
A flaw has been found in IObit Malware Fighter up to 13.2.0. Affected by this vulnerability is an unknown functionality of the component DLL Handler. This manipulation causes permission issues. The attack requires local access. The exploit…
- CVE-2023-37238MEDIUMCVSS 5.3EG 5.32023-07-06
Vulnerability of apps' permission to access a certain API being incompletely verified in the wireless projection module. Successful exploitation of this vulnerability may affect some wireless projection features.
- CVE-2014-6047MEDIUMCVSS 5.3EG 5.32018-08-28
phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect "download an attachment" permission checks.
- CVE-2017-7145MEDIUMCVSS 5.3EG 5.32017-10-23
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Time" component. The "Setting Time Zone" feature mishandles the possibility of using location data.
- CVE-2016-8605MEDIUMCVSS 5.3EG 5.32017-01-12
The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example, mkdir without the o…
- CVE-2021-32006MEDIUMCVSS 5.0EG 5.02022-03-10
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Permission Issues vulnerability in LinkManager web portal of Secomea GateManager allows logged in LinkManager user to access stored SiteManager backup fi…
- CVE-2014-1422MEDIUMCVSS 5.0EG 5.02020-07-22
In Ubuntu's trust-store, if a user revokes location access from an application, the location is still available to the application because the application will honour incorrect, cached permissions. This is because the cache was not ordered…
- CVE-2026-41978MEDIUMCVSS 4.4EG 4.42026-06-09
Permission control vulnerability in the clone module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2019-15962MEDIUMCVSS 4.4EG 4.42019-10-16
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to write files to the /root directory of an affected device. The vulnerability is due to improper permission…
- CVE-2012-5628MEDIUMCVSS 4.4EG 4.42018-05-04
gofer before 0.68 uses world-writable permissions for /var/lib/gofer/journal/watchdog, which allows local users to cause a denial of service by removing journal entries.
- CVE-2016-6648MEDIUMCVSS 4.4EG 4.42017-02-03
EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by sensitive information disclosure vulnerability as a result of incorrect permissions set on a sensitive system file. A ma…
- CVE-2024-11486MEDIUMCVSS 4.3EG 4.32024-11-20
A vulnerability, which was classified as problematic, was found in Code4Berry Decoration Management System 1.0. This affects an unknown part of the file /decoration/admin/user_permission.php of the component User Permission Handler. The ma…
- CVE-2013-4201MEDIUMCVSS 4.3EG 4.32018-05-01
Katello allows remote authenticated users to call the "system remove_deletion" CLI command via vectors related to "remove system" permissions.
Map vulnerabilities like CWE-275 to your infrastructure
EchelonGraph correlates every CVE — across CWE-275 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →