CWE-275
114 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-275page 2 of 3
- CVE-2017-18397LOWCVSS 3.3EG 3.32019-08-02
cPanel before 68.0.15 does not preserve permissions for local backup transport (SEC-330).
- CVE-2017-18422LOWCVSS 3.3EG 3.32019-08-02
In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272).
- CVE-2017-18425LOWCVSS 2.5EG 2.52019-08-02
In cPanel before 66.0.2, the cpdavd_error_log file can be created with weak permissions (SEC-280).
- CVE-2017-18427LOWCVSS 3.3EG 3.32019-08-02
In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).
- CVE-2017-2590HIGHCVSS 8.1EG 8.12018-07-27
A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delet…
- CVE-2017-2694LOWCVSS 3.3EG 3.32017-11-22
The AlarmService component in HwVmall with software earlier than 1.5.2.0 versions has no control over calling permissions, allowing any third party to call. An attacker can construct a malicious application to call it. Consequently, alert …
- CVE-2017-5809MEDIUMCVSS 5.5EG 5.52018-02-15
A Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found.
- CVE-2017-6513CRITICALCVSS 9.9EG 9.92017-03-11
The WHMCS Reseller Module V2 2.0.2 in Softaculous Virtualizor before 2.9.1.0 does not verify the user correctly, which allows remote authenticated users to control other virtual machines managed by Virtualizor by accessing a modified URL.
- CVE-2017-7088MEDIUMCVSS 5.9EG 5.92017-10-23
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Exchange ActiveSync" component. It allows remote attackers to erase a device in opportunistic circumstances by hijacking a cleartext Auto…
- CVE-2017-7144MEDIUMCVSS 4.3EG 4.32017-10-23
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to track Safari Private Browsing users by leveraging cookie m…
- CVE-2017-7145MEDIUMCVSS 5.3EG 5.32017-10-23
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Time" component. The "Setting Time Zone" feature mishandles the possibility of using location data.
- CVE-2017-8153HIGHCVSS 7.1EG 7.12017-11-22
Huawei VMall (for Android) with the versions before 1.5.8.5 have a privilege elevation vulnerability due to improper design. An attacker can trick users into installing a malicious app which can send out HTTP requests and execute JavaScrip…
- CVE-2017-9327MEDIUMCVSS 6.5EG 6.52019-07-03
Secret data of processes managed by CM is not secured by file permissions.
- CVE-2018-0392MEDIUMCVSS 5.5EG 5.52018-07-18
A vulnerability in the CLI of Cisco Policy Suite could allow an authenticated, local attacker to access files owned by another user. The vulnerability is due to insufficient access control permissions (i.e., World-Readable). An attacker co…
- CVE-2018-0449MEDIUMCVSS 4.2EG 4.22019-01-10
A vulnerability in the Cisco Jabber Client Framework (JCF) software, installed as part of the Cisco Jabber for Mac client, could allow an authenticated, local attacker to corrupt arbitrary files on an affected device that has elevated priv…
- CVE-2018-15379CRITICALCVSS 9.8EG 9.82018-10-05
A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticated, remote attacker to upload an arbitrary file. This file could allow the attacker to exec…
- CVE-2019-11145HIGHCVSS 7.8EG 7.82019-08-19
Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2019-11146HIGHCVSS 7.8EG 7.82019-08-19
Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2019-12622MEDIUMCVSS 5.5EG 5.52019-08-21
A vulnerability in Cisco RoomOS Software could allow an authenticated, local attacker to write files to the underlying filesystem with root privileges. The vulnerability is due to insufficient permission restrictions on a specific process.…
- CVE-2019-15962MEDIUMCVSS 4.4EG 4.42019-10-16
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to write files to the /root directory of an affected device. The vulnerability is due to improper permission…
- CVE-2019-1618HIGHCVSS 7.8EG 7.82019-03-11
A vulnerability in the Tetration Analytics agent for Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, local attacker to execute arbitrary code as root. The vulnerability is due to an incorrect permiss…
- CVE-2019-2177HIGHCVSS 8.8EG 8.82019-09-05
In isPreferred of HidProfile.java in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible device type confusion due to a permissions bypass. This could lead to remote code execution with no additional execution privileges needed. User…
- CVE-2020-14496CRITICALCVSS 8.3EG 9.82022-05-19
Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could c…
- CVE-2020-3152MEDIUMCVSS 6.7EG 6.72020-08-26
A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administrative credentials to execute arbitrary commands with root privileges. The vulnerability is due to improper user permissi…
- CVE-2020-6022MEDIUMCVSS 5.5EG 5.52020-10-27
Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to delete arbitrary files while restoring files in Anti-Ransomware.
- CVE-2020-8471HIGHCVSS 7.8EG 7.82020-04-29
For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+…
- CVE-2020-8474HIGHCVSS 7.8EG 7.82020-04-22
Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify registry settings related to control system functionality, allowing an authenticated attacker to cause system functions to stop or malfunction.
- CVE-2021-1437HIGHCVSS 7.5EG 7.52021-03-24
A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to an u…
- CVE-2021-22566CRITICALCVSS 9.8EG 9.82022-01-18
An incorrect setting of UXN bits within mmu_flags_to_s1_pte_attr lead to privileged executable pages being mapped as executable from an unprivileged context. This can be leveraged by an attacker to bypass executability restrictions of kern…
- CVE-2021-22571MEDIUMCVSS 5.5EG 5.52022-03-18
A local attacker could read files from some other users' SA360 reports stored in the /tmp folder during staging process before the files are loaded in BigQuery. We recommend upgrading to version 1.0.3 or above.
- CVE-2021-32006MEDIUMCVSS 5.0EG 5.02022-03-10
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Permission Issues vulnerability in LinkManager web portal of Secomea GateManager allows logged in LinkManager user to access stored SiteManager backup fi…
- CVE-2022-0343HIGHCVSS 3.3EG 7.82022-03-29
A local attacker, as a different local user, may be able to send a HTTP request to 127.0.0.1:10000 after the user (typically a developer) manually invoked the ./tools/run-dev-server script. It is recommended to upgrade to any version beyon…
- CVE-2022-0742CRITICALCVSS 9.1EG 9.12022-03-18
Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-memory via icmp6 packets of type 130 or 131. We recommend upgrading past commit 2d3916f3189172d5c69d33065c3c21119fe539f…
- CVE-2022-22251HIGHCVSS 7.8EG 7.82022-10-18
On cSRX Series devices software permission issues in the container filesystem and stored files combined with storing passwords in a recoverable format in Juniper Networks Junos OS allows a local, low-privileged attacker to elevate their pe…
- CVE-2022-22988CRITICALCVSS 7.7EG 9.12022-01-13
File and directory permissions have been corrected to prevent unintended users from modifying or accessing resources. It would be more difficult for an authenticated attacker to now traverse through the files and directories. This can only…
- CVE-2022-25153HIGHCVSS 7.8EG 7.82022-06-09
The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL settings. Due to this setting, a malicious actor with low privileges access to a system can escalate his privileges to …
- CVE-2023-37238MEDIUMCVSS 5.3EG 5.32023-07-06
Vulnerability of apps' permission to access a certain API being incompletely verified in the wireless projection module. Successful exploitation of this vulnerability may affect some wireless projection features.
- CVE-2023-3759MEDIUMCVSS 6.3EG 6.32023-07-19
A vulnerability, which was classified as critical, was found in Intergard SGS 8.7.0. Affected is an unknown function. The manipulation leads to permission issues. It is possible to launch the attack remotely. The exploit has been disclosed…
- CVE-2023-39398CRITICALCVSS 9.1EG 9.12023-08-13
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
- CVE-2023-39399CRITICALCVSS 9.1EG 9.12023-08-13
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
- CVE-2023-5263HIGHCVSS 8.8EG 8.82023-09-29
A vulnerability was found in ZZZCMS 2.1.7 and classified as critical. Affected by this issue is the function restore of the file /admin/save.php of the component Database Backup File Handler. The manipulation leads to permission issues. Th…
- CVE-2023-6302HIGHCVSS 7.2EG 7.22023-11-27
A vulnerability was found in CSZCMS 1.3.0 and classified as critical. Affected by this issue is some unknown functionality of the file \views\templates of the component File Manager Page. The manipulation leads to permission issues. The at…
- CVE-2023-6762MEDIUMCVSS 4.3EG 5.42023-12-13
A vulnerability, which was classified as critical, was found in Thecosy IceCMS 2.0.1. Affected is an unknown function of the file /article/DelectArticleById/ of the component Article Handler. The manipulation leads to permission issues. It…
- CVE-2024-11485MEDIUMCVSS 6.3EG 6.32024-11-20
A vulnerability, which was classified as critical, has been found in Code4Berry Decoration Management System 1.0. Affected by this issue is some unknown functionality of the file /decoration/admin/userregister.php of the component User Han…
- CVE-2024-11486MEDIUMCVSS 4.3EG 4.32024-11-20
A vulnerability, which was classified as problematic, was found in Code4Berry Decoration Management System 1.0. This affects an unknown part of the file /decoration/admin/user_permission.php of the component User Permission Handler. The ma…
- CVE-2024-13189HIGHCVSS 7.3EG 7.32025-01-08
A vulnerability classified as critical has been found in ZeroWdd myblog 1.0. This affects an unknown part of the file src/main/java/com/wdd/myblog/config/MyBlogMvcConfig.java. The manipulation leads to permission issues. It is possible to …
- CVE-2024-3118MEDIUMCVSS 6.3EG 6.32024-03-31
A vulnerability, which was classified as critical, has been found in Dreamer CMS up to 4.1.3. This issue affects some unknown processing of the component Attachment Handler. The manipulation leads to permission issues. The attack may be in…
- CVE-2025-10941HIGHCVSS 7.8EG 7.82025-09-25
A vulnerability was determined in Topaz SERVCore Teller 2.14.0-RC2/2.14.1. Affected by this issue is some unknown functionality of the file SERVCoreTeller_2.0.40D.msi of the component Installer. Executing manipulation can lead to permissio…
- CVE-2025-53168MEDIUMCVSS 5.7EG 5.72025-07-07
Vulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful exploitation of this vulnerability may allow the peer device to use the camera without user awareness.
- CVE-2025-54618MEDIUMCVSS 5.7EG 5.72025-08-06
Permission control vulnerability in the distributed clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Map vulnerabilities like CWE-275 to your infrastructure
EchelonGraph correlates every CVE — across CWE-275 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →