A product defines a set of insecure permissions that are inherited by objects that are created by the program.
Volume of CVEs assigned to CWE-277 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
71 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-7891CRITICAL A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not adequately describe the special behavior of the System.User ent | May 7, 2026 | 9.1 | 37 | NO | NO |
CVE-2024-27822HIGH A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to gain root privileges. | May 14, 2024 | 7.8 | 37 | NO | YES |
CVE-2026-9046HIGH A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when i | Jul 16, 2026 | 7.0 | 31 | NO | NO |
CVE-2021-41170CRITICAL neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures directly into the template engine. As a result values that ar | Nov 8, 2021 | 9.8 | 31 | NO | NO |
CVE-2026-30266HIGH Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbitrary code via a crafted file | Apr 20, 2026 | 7.8 | 30 | NO | NO |
CVE-2024-39877HIGH Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that could execute arbitrary code in | Jul 17, 2024 | 8.8 | 29 | NO | NO |
CVE-2023-27842HIGH Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code via the index.php compenent | Mar 21, 2023 | 8.8 | 28 | NO | NO |
CVE-2025-11554HIGH A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown functionality of the file app/Http/Controllers/AccessLevelCon | Oct 9, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-58437HIGH Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3, 2.25.0 and 2.25.1, Coder can be compromised through insec | Sep 6, 2025 | 8.1 | 27 | NO | NO |
CVE-2024-36540CRITICAL Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. | Jul 24, 2024 | 9.8 | 26 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.