CWE-276

Medium likelihood

Incorrect Default Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

During installation, installed file permissions are set to allow anyone to modify those files.

1,487 vulnerabilities with CWE-276
CVE-2025-53811 MEDIUM
Mosh-Pro - Code Injection
CVE-2025-8098 HIGH
Lenovo Pcmanager < 5.1.120.7041 - Incorrect Default Permissions
CVSS 7.8
CVE-2025-27559 MEDIUM
AI Playground <v2.3.0 alpha - Privilege Escalation
CVSS 6.7
CVE-2025-26470 MEDIUM
Intel(R) Distribution for Python <2025.1.0 - Privilege Escalation
CVSS 6.7
CVE-2025-20087 MEDIUM
Intel(R) oneAPI DPC++/C++ Compiler - Privilege Escalation
CVSS 6.7
CVE-2025-20023 MEDIUM
Intel(R) Graphics Driver - Privilege Escalation
CVSS 6.7
CVE-2025-8672 HIGH
Gimp - Incorrect Default Permissions
CVSS 7.8
CVE-2025-7195 MEDIUM
Operator-framework Operator-sdk - Incorrect Default Permissions
CVSS 6.4
CVE-2025-44643 HIGH
Draytek AP903 <1.4.18-AP918R <1.4.9 - Privilege Escalation
CVSS 8.6
CVE-2025-41658 MEDIUM
CODESYS Runtime Toolkit - Info Disclosure
CVSS 5.5
CVE-2025-52361 HIGH
AK-Nord USB-Server-LXL Firmware v0.0.16 Build 2023-03-13 - Command ...
CVSS 7.8
CVE-2025-54085 LOW
Absolute Secure Access < 13.56 - Incorrect Default Permissions
CVSS 3.8
CVE-2025-49084 CRITICAL
Absolute Secure Access < 13.56 - Incorrect Default Permissions
CVSS 9.1
CVE-2025-49082 LOW
Absolute Secure Access < 13.56 - Incorrect Default Permissions
CVSS 2.7
CVE-2025-54530 HIGH
Jetbrains Teamcity < 2025.07 - Incorrect Default Permissions
CVSS 7.5
CVE-2025-45467 HIGH
Unitree Go1 Firmware - Incorrect Default Permissions
CVSS 7.1
CVE-2025-8069 HIGH
AWS Client VPN - Code Injection
CVSS 7.8
CVE-2025-8031 CRITICAL
Mozilla Firefox < 128.13.0 - Incorrect Default Permissions
CVSS 9.8
CVE-2025-54059 MEDIUM
Chainguard.dev Melange < 0.29.5 - Incorrect Default Permissions
CVSS 4.4
CVE-2025-53945 HIGH
apko <0.29.5 - Privilege Escalation
CVSS 7.0
CVE-2025-0886 HIGH
Elliptic Labs Virtual Lock Sensor - Privilege Escalation
CVSS 7.8
CVE-2025-7672 MEDIUM
JiranSoft CrossEditor4 <4.6.0.23 - XSS
CVSS 4.3
CVE-2025-5199 HIGH
Canonical Multipass < 1.16.0 - Incorrect Authorization
CVSS 7.3
CVE-2025-41665 MEDIUM
PLC <unknown> - DoS
CVSS 6.5
CVE-2025-46014 HIGH
Honor PC Manager < 16.0.0.118 - Improper Access Control
CVSS 8.8
Details
Vulnerabilities 1,487
Exploit Likelihood Medium