Fallos del tipo CWE-732

690 resultados
CVE-2020-16202WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, which may allow code exeEPSS 0.4%CVE-2025-34025HIGHVersa Concerto Insecure Docker Mount Container EscapeEPSS 0.4%CVE-2023-1692HIGHThe window management module lacks permission verification.Successful exploitation of this vulnerability may affect confidentiality.EPSS 0.4%CVE-2025-66723HIGHinMusic Brands Engine DJ before 4.3.4 suffers from Insecure Permissions due to exposed HTTP service in the Remote Library, which allows attaEPSS 0.4%CVE-2017-12167MEDIUMIt was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user tEPSS 0.4%CVE-2025-4609CRITICALIncorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attackerEPSS 0.4%CVE-2024-57068HIGHA prototype pollution in the lib.mutateMergeDeep function of @tanstack/form-core v0.35.0 allows attackers to cause a Denial of Service (DoS)EPSS 0.4%CVE-2016-2121MEDIUMA permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitiveEPSS 0.4%CVE-2020-36770HIGHpkg_postinst in the Gentoo ebuild for Slurm through 22.05.3 unnecessarily calls chown to assign root's ownership on files in the live root fEPSS 0.4%CVE-2026-10591HIGHKiro IDE Insufficient File Write Restrictions to Execution-Sensitive PathsEPSS 0.4%CVE-2023-35841HIGHWinFlash Driver Permissions IssueEPSS 0.4%CVE-2024-11497HIGHPhoenix Contact: CHARX-SEC3xxx Charge controllers vulnerable to privilege escalationEPSS 0.4%CVE-2025-3936MEDIUMIncorrect Permission Assignment for Critical ResourceEPSS 0.4%CVE-2025-49131MEDIUMFastGPT Sandbox Vulnerable to Sandbox BypassEPSS 0.4%CVE-2020-10140HIGHAcronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory. Because some privileged processes are executed fEPSS 0.4%CVE-2026-42812CRITICALApache Polaris: No protection on `write.metadata.path`EPSS 0.4%CVE-2023-23939LOWAzure/setup-kubectl: Escalation of privilege vulnerability for v3 and lowerEPSS 0.4%CVE-2025-24009HIGHA vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). TheEPSS 0.4%CVE-2024-24740MEDIUMInformation Disclosure vulnerability in SAP NetWeaver Application Server ABAP (SAP Kernel)EPSS 0.4%CVE-2025-0064HIGHImproper Authorization in SAP BusinessObjects Business Intelligence platform (Central Management Console)EPSS 0.4%