CWE-276

Medium likelihood

Incorrect Default Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

During installation, installed file permissions are set to allow anyone to modify those files.

1,487 vulnerabilities with CWE-276
CVE-2025-34332 HIGH
Audiocodes Fax Server < 2.6.23 - Incorrect Default Permissions
CVSS 7.8
CVE-2025-54990 MEDIUM
Com.xwiki.admintools Application-admi... - Incorrect Default Permissions
CVSS 5.3
CVE-2025-12792 LOW
Canva for Mac <1.117.1 - RCE
CVSS 3.2
CVE-2025-13193 MEDIUM
libvirt - Info Disclosure
CVSS 5.5
CVE-2025-13131 HIGH
Sonarr 4.0.15.2940 - Local Privilege Escalation
CVSS 7.8
CVE-2025-13130 HIGH
Radarr 5.28.0.10274 - Privilege Escalation
CVSS 7.8
CVE-2025-8485 HIGH
Lenovo App Store < 9.0.2530.1027 - Incorrect Default Permissions
CVSS 7.3
CVE-2025-8421 MEDIUM
Lenovo Dock Manager - Privilege Escalation
CVSS 6.6
CVE-2025-61667 HIGH
Datadog Linux Host Agent <7.70.2 - Code Injection
CVE-2025-11567 HIGH
Unknown - Privilege Escalation
CVE-2025-32091 HIGH
Intel(R) Arc(TM) B-series GPUs - Privilege Escalation
CVSS 8.2
CVE-2025-31940 MEDIUM
Intel(R) Thread Director Visualizer <1.1.1 - Privilege Escalation
CVSS 6.7
CVE-2025-30518 MEDIUM
Intel(R) PresentMon <2.3.1 - Privilege Escalation
CVSS 6.7
CVE-2025-27711 MEDIUM
Intel(R) OFU <14.1.31 - Privilege Escalation
CVSS 6.7
CVE-2025-27246 MEDIUM
Intel(R) Processor Identification Utility <8.0.43 - Privilege Escal...
CVSS 6.7
CVE-2025-13025 HIGH
Mozilla Firefox < 145.0 - Incorrect Default Permissions
CVSS 7.5
CVE-2025-10918 HIGH
Ivanti Endpoint Manager < 2024 - Incorrect Default Permissions
CVSS 7.1
CVE-2025-64436 MEDIUM
Kubevirt < 1.5.3 - Improper Privilege Management
CVSS 5.3
CVE-2025-43507 MEDIUM
Apple watchOS <26.1 - Info Disclosure
CVSS 6.5
CVE-2025-43444 MEDIUM
tvOS <26.1 - Info Disclosure
CVSS 5.3
CVE-2025-43442 LOW
iOS <26.1 - Info Disclosure
CVSS 3.3
CVE-2025-43350 LOW
iOS <26.1 - Info Disclosure
CVSS 2.4
CVE-2025-8432 HIGH
Centreon Infra Monitoring <24.10.6-<24.04.9-<23.10.15 - Info Disclo...
CVSS 8.4
CVE-2025-46185 MEDIUM
pgcodekeeper 10.12.0 - Info Disclosure
CVSS 6.2
CVE-2025-12100 HIGH
MongoDB BI Connector ODBC driver <1.4.6 - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities 1,487
Exploit Likelihood Medium