VulnSea

CWE-281

CVEs classified under CWE-281, newest first.

19 CVEsRSS

CVE-2026-93658High· 7.0PoC
4d ago

uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes…

uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes…

Midnightuutils · coreutilsEPSS 0.15%via NVD
CVE-2026-61709Medium· 5.3
6d ago

OpenFGA is an authorization and permission engine built for developers

OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded when an authorization relation used an intersection containing a base but not e…

Sunlitopenfga · openfgaEPSS 0.34%via NVD
CVE-2026-82964High· 8.8PoC
6d ago

Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox…

Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox…

MidnightGen Digital · Avast Free Antivirus, Avast One, Avast Premium Security, Avast Ultimate, Avast Business SecurityEPSS 0.14%via NVD
CVE-2026-88922Medium· 6.7
1w ago

The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bit…

The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bit…

SunlitHashiCorp · Shared libraryEPSS 0.09%via NVD
CVE-2026-89638High· 7.0
1w ago

kernel: smb: client: clear setuid/setgid bit on write with cifsacl/modefromsid/posix extensions (CVE-2026-89638)

A flaw was found in the Linux kernel's Server Message Block (SMB) client. When a file with the setuid or setgid bit is written to on certain Common Internet File System (CIFS) mounts (specifically those using 'cifsacl', 'modefromsid' optio…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-88016High· 7.1PoC
1w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and l…

Midnightrclone · rcloneEPSS 0.19%via NVD
CVE-2026-58510Medium· 4.3
2mo ago

Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private

Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private

Sunlitgitea · code.gitea.io/giteaEPSS 0.21%via GHSA
CVE-2026-35341High· 7.1
2mo ago

mkfifo: permissions of an existing file are changed after FIFO creation fails

mkfifo: permissions of an existing file are changed after FIFO creation fails

Twilightuu_mkfifo · uu_mkfifoEPSS 0.17%via GHSA
CVE-2026-35361Low· 3.4
2mo ago

mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)

mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)

Sunlituu_mknod · uu_mknodEPSS 0.14%via GHSA
CVE-2026-44832High· 8.8
3mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PATCH request to /api/v1/users/{id} with permissions[admin]…

Twilightsnipeitapp · snipe-itEPSS 0.32%via NVD
CVE-2026-39832Critical· 9.1
4mo ago

When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request

When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of…

Midnightgolang · cryptoEPSS 0.60%via NVD
CVE-2026-39828Medium· 6.3⚖ disputed
4mo ago

Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh

When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succee…

Sunlitgolang.org/x/crypto · golang.org/x/crypto/sshEPSS 0.37%via CVEORG
CVE-2026-35385High· 7.5
5mo ago

In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).

In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).

Twilightopenbsd · opensshEPSS 0.56%via NVD
CVE-2025-9615Low· 3.3
7mo ago

A flaw was found in NetworkManager

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can ac…

SunlitEPSS 0.16%via NVD
CVE-2025-55130Critical· 9.1PoC
8mo ago

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the curren…

Abyssalnodejs · node.jsEPSS 1.7%via NVD
CVE-2024-1726Medium· 5.3
2y ago

A flaw was discovered in the RESTEasy Reactive implementation in Quarkus

A flaw was discovered in the RESTEasy Reactive implementation in Quarkus. Due to security checks for some JAX-RS endpoints being performed after serialization, more processing resources are consumed while the HTTP request is checked. In …

SunlitEPSS 0.72%via NVD
CVE-2022-0330High· 7.8
4y ago

A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU

A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their privileges on the s…

Twilightredhat · codeready_linux_builderEPSS 0.38%via NVD
CVE-2022-24618High· 7.8
4y ago

Heimdal.Wizard.exe installer in Heimdal Premium Security 2.5.395 and earlier has insecure permissions, which allows unprivileged local users to elevate privileges to SYSTEM via the "Browse For Folder" window accessible by triggering a "R…

Heimdal.Wizard.exe installer in Heimdal Premium Security 2.5.395 and earlier has insecure permissions, which allows unprivileged local users to elevate privileges to SYSTEM via the "Browse For Folder" window accessible by triggering a "R…

Twilightheimdalsecurity · heimdal_premium_securityEPSS 0.25%via NVD
CVE-2021-32760Medium· 5.5
5y ago

containerd: pulling and extracting crafted container image may result in Unix file permission changes (CVE-2021-32760)

A flaw was found in containerd where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expe…

SunlitRed Hat · RHOSSM 2.4 for RHEL 8EPSS 1.6%via CSAF
CWE-281 vulnerabilities (CVEs) · VulnSea