CWE-276
Medium likelihoodIncorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
1,533 vulnerabilities with CWE-276
CVE-2025-57847
MEDIUM
Ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissions
CVSS 6.4
CVE-2025-7024
HIGH
Local privilege escalation in Windows Server OS through installed Tetra Connectivity Server (TCS)
CVSS 7.3
CVE-2025-15615
MEDIUM
Wazuh Manager authd service Improper SSL/TLS Renegotiation Handling leading to Denial of Service
CVSS 5.8
CVE-2025-8766
MEDIUM
Noobaa-core: excessive permissions of /etc could lead to escalation of privilege in the noobaa-core container
CVSS 6.4
CVE-2025-57849
MEDIUM
Fuse: privilege escalation via excessive /etc/passwd permissions
CVSS 6.4
CVE-2025-1789
HIGH
Genetec Update Service - Privilege Escalation
CVSS 7.8
CVE-2025-36522
MEDIUM
Intel(R) Chipset Software <10.1.20266.8668 - Privilege Escalation
CVSS 6.7
CVE-2025-36511
MEDIUM
Intel(R) Memory and Storage Tool <2.5.2 - Privilege Escalation
CVSS 6.7
CVE-2025-32453
MEDIUM
Intel(R) Graphics Driver - Privilege Escalation
CVSS 6.7
CVE-2025-31655
MEDIUM
Intel(R) Battery Life Diagnostic Tool - Privilege Escalation
CVSS 6.7
CVE-2025-22849
MEDIUM
Intel(R) Optane(TM) PMem management <CR_MGMT_01.00.00.3584, CR_MGMT...
CVSS 6.7
CVE-2025-15343
MEDIUM
Tanium Enforce 2.7.0-2.7.366 - Incorrect Default Permissions
CVSS 6.5
CVE-2025-15341
MEDIUM
Tanium Benchmark 2.7.0-2.7.98 - Incorrect Default Permissions
CVSS 6.5
CVE-2025-15340
MEDIUM
Tanium Comply 2.24.0-2.24.158 - Incorrect Default Permissions
CVSS 6.5
CVE-2025-15339
MEDIUM
Tanium Discover 4.10.0-4.10.117 - Incorrect Default Permissions
CVSS 6.5
CVE-2025-15338
MEDIUM
Tanium Partner Integration 1.0.0-1.0.223 - Incorrect Default Permissions
CVSS 6.5
CVE-2025-15337
MEDIUM
Tanium Patch 3.17.0-3.17.2299 - Incorrect Default Permissions
CVSS 6.5
CVE-2025-15336
MEDIUM
Tanium Performance 1.17.0-1.17.133 - Incorrect Default Permissions
CVSS 6.5
CVE-2025-15335
MEDIUM
Tanium Threat Response 4.5.0-4.5.265 - Information Disclosure via Incorrect Default Permissions
CVSS 4.3
CVE-2025-15334
MEDIUM
Tanium Threat Response 4.5.0-4.5.265 - Information Disclosure via Incorrect Default Permissions
CVSS 4.3
CVE-2025-15333
MEDIUM
Tanium Threat Response 4.5.0-4.5.265 - Information Disclosure via Incorrect Default Permissions
CVSS 4.3
CVE-2025-10314
HIGH
Mitsubishi Electric FREQSHIP-mini <8.0.2 - Code Injection
CVSS 8.8
CVE-2025-69604
HIGH
SuperDuper! < 3.12 - Unauthenticated Arbitrary Package Installation via Default Task Template
CVSS 7.8
CVE-2025-13905
HIGH
CWE-276 - Privilege Escalation
CVE-2025-67230
HIGH
ToDesktop Builder < 0.33.0 - Improper Permissions in Custom URL Scheme Handler
CVSS 7.1
Details
Vulnerabilities
1,533
Exploit Likelihood
Medium