VulnSea

CWE-276

CVEs classified under CWE-276, newest first.

47 CVEsRSS

CVE-2025-57848Medium· 6.4
11mo ago

A container privilege escalation flaw was found in certain Container-native Virtualization images

A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an atta…

SunlitEPSS 0.18%via NVD
CVE-2025-53811None
1y ago

The configuration of Mosh-Pro on macOS, specifically the "RunAsNode" fuse enabled, allows a local attacker with unprivileged access to execute arbitrary code that inherits Mosh-Pro TCC (Transparency, Consent, and Control) permissions.  A…

The configuration of Mosh-Pro on macOS, specifically the "RunAsNode" fuse enabled, allows a local attacker with unprivileged access to execute arbitrary code that inherits Mosh-Pro TCC (Transparency, Consent, and Control) permissions.  A…

SunlitEPSS 0.13%via NVD
CVE-2025-7195Medium· 6.4
1y ago

Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID

Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/p…

Sunlitoperator-framework · operator-sdkEPSS 0.22%via NVD
CVE-2025-30706High· 7.5
1y ago

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J)

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via mult…

Twilightoracle · mysql_connector/jEPSS 0.61%via NVD
CVE-2025-2782None
1y ago

The WatchGuard Terminal Services Agent on Windows does not properly configure directory permissions when installed in a non-default directory

The WatchGuard Terminal Services Agent on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnera…

SunlitEPSS 0.15%via NVD
CVE-2025-2781None
1y ago

The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory permissions when installed in a non-default directory

The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vuln…

SunlitEPSS 0.14%via NVD
CVE-2024-28056Critical· 9.8
2y ago

Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects

Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed from an Amplify project, a Condition property is removed but "…

Midnightamazon · aws_amplify_cliEPSS 1.7%via NVD
CVE-2024-1488High· 8.0
2y ago

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the…

Twilightfedoraproject · unboundEPSS 0.32%via NVD
CVE-2023-43902Critical· 9.8
2y ago

Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.

Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.

Midnightemudhra · emsignerEPSS 0.83%via NVD
CVE-2022-36640Critical· 9.8
4y ago

influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands

influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states "If …

Midnightinfluxdata · influxdbEPSS 2.5%via NVD
CVE-2022-28932Critical· 9.8
4y ago

D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.

D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.

Midnightdlink · dsl-g2452dg_firmwareEPSS 1.2%via NVD
CVE-2022-26595Medium· 4.3
4y ago

Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user permission when accessing a list of sites/groups, which allows remote authenticated users to view sites/groups via t…

Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user permission when accessing a list of sites/groups, which allows remote authenticated users to view sites/groups via t…

Sunlitliferay · digital_experience_platformEPSS 0.75%via NVD
CVE-2021-40904High· 8.8PoC
4y ago

The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code

The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code. As a result, remote code execution is achieved. Success…

Midnightcheckmk · checkmkEPSS 3.7%via NVD
CVE-2021-38268Medium· 6.5
4y ago

The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 2 incorrectly sets default permissions for site member…

The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 2 incorrectly sets default permissions for site member…

Sunlitliferay · digital_experience_platformEPSS 0.78%via NVD
CVE-2021-29005High· 8.8
4y ago

Insecure permission of chmod command on rConfig server 3.9.6 exists

Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute chmod as root without password which may let an attacker with low privilege to gain root access on server.

Twilightrconfig · rconfigEPSS 2.2%via NVD
CVE-2021-29052Medium· 4.3
5y ago

The Data Engine module in Liferay Portal 7.3.0 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 does not check permissions in DataDefinitionResourceImpl.getSiteDataDefinitionByContentTypeByDataDefinitionKey, which allows remote authe…

The Data Engine module in Liferay Portal 7.3.0 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 does not check permissions in DataDefinitionResourceImpl.getSiteDataDefinitionByContentTypeByDataDefinitionKey, which allows remote authe…

Sunlitliferay · dxpEPSS 0.77%via NVD
CVE-2019-1982Medium· 5.3
6y ago

A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker…

A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker…

Sunlitcisco · firepower_services_software_for_asaEPSS 0.97%via NVD
CWE-276 vulnerabilities (CVEs) — page 2 · VulnSea