CWE-281

Improper Preservation of Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

337 vulnerabilities with CWE-281
CVE-2025-43701 HIGH
Salesforce OmniStudio <254 - Info Disclosure
CVSS 7.5
CVE-2025-43700 HIGH
Salesforce OmniStudio <Spring 2025 - Info Disclosure
CVSS 7.5
CVE-2025-43698 CRITICAL
Salesforce OmniStudio <Spring 2025 - Privilege Escalation
CVSS 9.1
CVE-2025-43697 HIGH
Salesforce OmniStudio <Spring 2025 - Info Disclosure
CVSS 7.5
CVE-2025-27563 LOW
OpenHarmony < 5.0.3 - Information Leak via Permission Handling
CVSS 3.3
CVE-2025-27247 MEDIUM
OpenHarmony <5.0.3 - Info Disclosure
CVSS 5.5
CVE-2025-26693 LOW
OpenHarmony < 5.0.3 - Information Disclosure via Permission Handling
CVSS 3.3
CVE-2025-26691 MEDIUM
OpenHarmony < 5.0.3 - Information Disclosure via Permission Handling
CVSS 5.5
CVE-2025-43026 HIGH
HP Support Assistant <9.44.18.0 - Privilege Escalation
CVSS 7.8
CVE-2025-27703 MEDIUM
Absolute Secure Access < 13.54 - Privilege Escalation in Management Console
CVSS 6.0
CVE-2025-32697 NONE
MediaWiki <1.42.6, 1.43.1 - Info Disclosure
CVE-2025-32696 NONE
MediaWiki <1.39.12, 1.42.6, 1.43.1 - Info Disclosure
CVE-2025-31184 HIGH
visionOS < 2.4 - Unauthorized Local Network Access via Improper Permissions
CVSS 7.8
CVE-2025-30456 HIGH
macOS Ventura <13.7.5 - Privilege Escalation
CVSS 7.8
CVE-2025-30449 HIGH
macOS Ventura <13.7.5, macOS Sequoia <15.4, macOS Sonoma <14.7.5 - ...
CVSS 7.8
CVE-2025-25871 HIGH
Open Panel <0.3.4 - Privilege Escalation
CVSS 8.0
CVE-2025-25711 HIGH
dtp.ae tNexus Airport View <2.8 - Privilege Escalation
CVSS 8.8
CVE-2025-0914 LOW
Velociraptor <0.73.4 - Privilege Escalation
CVSS 3.8
CVE-2025-24791 MEDIUM
Snowflake NodeJS Driver <2.0.1 - Privilege Escalation
CVSS 4.4
CVE-2025-24087 MEDIUM
macOS Sequoia <15.3 - Info Disclosure
CVSS 5.5
CVE-2025-21544 MEDIUM
Oracle Communications Order and Service Management <7.5.0 - Info Di...
CVSS 5.4
CVE-2025-21541 MEDIUM
Oracle Workflow <12.2.14 - Privilege Escalation
CVSS 5.4
CVE-2025-22620 MEDIUM
gix-worktree-state < 0.17.0 - Improper Preservation of Permissions
CVSS 5.0
CVE-2025-24337 HIGH
WriteFreely <0.15.1 - Info Disclosure
CVSS 8.4
CVE-2024-47270 LOW
Synology Surveillance Station - Improper Preservation of Permissions
CVSS 2.7
Details
Vulnerabilities 337