CWE-276

Medium likelihood

Incorrect Default Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

During installation, installed file permissions are set to allow anyone to modify those files.

1,487 vulnerabilities with CWE-276
CVE-2025-57848 MEDIUM
Container-native Virtualization - Privilege Escalation
CVSS 6.4
CVE-2025-23347 HIGH
NVIDIA Project G-Assist - Privilege Escalation
CVSS 7.8
CVE-2025-11575 HIGH
MongoDB Atlas SQL ODBC driver <2.0.0 - Privilege Escalation
CVSS 7.8
CVE-2025-58712 MEDIUM
AMQ Broker - Privilege Escalation
CVSS 6.4
CVE-2025-61035 HIGH
seffaflik <0.0.9 - Path Traversal
CVSS 7.7
CVE-2025-62661 MEDIUM
Mediawiki <1.44 - Privilege Escalation
CVE-2025-62577 HIGH
ETERNUS SF - Privilege Escalation
CVSS 8.8
CVE-2025-62668 MEDIUM
Mediawiki - GrowthExperiments Extension <1.39 - Info Disclosure
CVE-2025-35062 MEDIUM
Newforma Project Center < 2023.1 - Incorrect Default Permissions
CVSS 5.3
CVE-2025-11535 HIGH
MongoDB Connector for BI <2.14.24 - Privilege Escalation
CVE-2025-54086 LOW
Absolute Secure Access < 14.10 - Incorrect Default Permissions
CVSS 3.3
CVE-2025-23297 HIGH
NVIDIA Installer for NvAPP for Windows - Privilege Escalation
CVSS 7.8
CVE-2025-57852 MEDIUM
KServe ModelMesh - Privilege Escalation
CVSS 6.4
CVE-2025-36857 LOW
Rapid7 Appspider Pro < 7.5.021 - Incorrect Default Permissions
CVSS 3.3
CVE-2025-34191 HIGH
Vasion Virtual Appliance Application < 20.0.1923 - Symlink Following
CVSS 8.4
CVE-2025-53947 HIGH
Software <unknown> - Info Disclosure
CVSS 7.7
CVE-2025-57625 HIGH
CYRISMA Sensor <444 - Privilege Escalation
CVSS 8.8
CVE-2025-55111 MEDIUM
Control-M/Agent <9.0.20 - Info Disclosure
CVSS 5.5
CVE-2025-43887 HIGH
Dell Powerprotect Data Manager < 19.21 - Incorrect Default Permissions
CVSS 7.0
CVE-2025-43725 HIGH
Dell Powerprotect Data Manager < 19.21 - Incorrect Default Permissions
CVSS 7.8
CVE-2025-10231 HIGH
N-able N-central < 2025.3 - Incorrect Default Permissions
CVSS 7.0
CVE-2025-22425 MEDIUM
Google Android - Incorrect Default Permissions
CVSS 5.1
CVE-2025-57846 HIGH
i-フィルター - Privilege Escalation
CVSS 7.8
CVE-2025-9190 MEDIUM
Cursor - RCE
CVE-2025-53813 MEDIUM
Nozbe <2025.11 - Code Injection
Details
Vulnerabilities 1,487
Exploit Likelihood Medium