The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Volume of CVEs assigned to CWE-732 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
1,704 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-3923CRITICAL Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands. | Nov 1, 2019 | 9.8 | 89 | NO | YES |
CVE-2018-15379CRITICAL A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticated, remote attacker to upload an | Oct 5, 2018 | 9.8 | 89 | NO | YES |
CVE-2019-15752HIGH Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\ve | Aug 28, 2019 | 7.8 | 88 | YES | YES |
CVE-2022-22960HIGH VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor | Apr 13, 2022 | 7.8 | 87 | YES | YES |
CVE-2018-13374MEDIUM A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials co | Jan 22, 2019 | 4.3 | 82 | YES | YES |
CVE-2021-44521CRITICAL When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threa | Feb 11, 2022 | 9.1 | 71 | NO | YES |
CVE-2021-23874HIGH Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP | Feb 10, 2021 | 7.8 | 62 | YES | NO |
CVE-2023-32986HIGH Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File Parameters, allowing attackers with Item | May 16, 2023 | 8.8 | 60 | NO | NO |
CVE-2018-1000207HIGH MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpthumb class that can result in Creating f | Jul 13, 2018 | 7.2 | 59 | NO | NO |
CVE-2017-16885CRITICAL Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Changing Passwords, etc.) allows re | Jan 12, 2018 | 9.8 | 56 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.