CWE-276
1,555 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
CVEs (1,555)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Linuxfoundation2Fedora RuncJun 17, 2026 May 17, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linu...Show more |
1Fidelissecurity 2Deception NetworkJun 17, 2026 May 17, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Improper file permissions in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected script files, which coul...Show more |
1Fidelissecurity 2Deception NetworkJun 17, 2026 May 17, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Improper file permissions in the CommandPost, Collector, Sensor, and Sandbox components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected files and enabl...Show more |
Nextcloud Talk is a video and audio conferencing app for Nextcloud. In versions prior to 13.0.5 and 14.0.0, a call moderator can indirectly enable user webcams by granting permissions, if they were enabled before removin...Show more |
1Simple Social Networking Site Project 1Simple Social Networking Site Jun 17, 2026 May 13, 2022 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 Sourcecodester Simple Social Networking Site v1.0 is vulnerable to file deletion via /sns/classes/Master.php?f=delete_img. |
1Air Cargo Management System Project 1Air Cargo Management System Jun 17, 2026 May 13, 2022 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 Air Cargo Management System v1.0 is vulnerable to file deletion via /acms/classes/Master.php?f=delete_img. |
Joomla Guru extension 5.2.5 is affected by: Insecure Permissions. The impact is: obtain sensitive information (remote). The component is: Access to private information and components, possibility to view other users' inf...Show more |
In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being...Show more |
An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (found in a Roundcube configuration file) that are used to protect Webmail user passwords and two-fac...Show more |
A denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow configuration files to be written to non-standard locations during installation. |
1Cisco 1Virtualized Infrastructure Manager Jun 17, 2026 Apr 21, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A vulnerability in the configuration file protections of Cisco Virtualized Infrastructure Manager (VIM) could allow an authenticated, local attacker to access confidential information and elevate privileges on an affecte...Show more |
The CreateRedirect extension before 2022-04-14 for MediaWiki does not properly check whether the user has permissions to edit the target page. This could lead to an unauthorised (or blocked) user being able to edit a pag...Show more |
The setup program for the affected product configures its files and folders with full access, which may allow unauthorized users permission to replace original binaries and achieve privilege escalation. |
1Liferay 2Digital Experience Platform Liferay PortalJul 9, 2026 Apr 19, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user permission when accessing a list of sites/groups, which allows remote authenticated users to view s...Show more |
4Fedoraproject KubernetesMobyproject+1 more4Cri O FedoraMoby+1 moreJun 17, 2026 Apr 18, 2022 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable L...Show more |
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'pub...Show more |
In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless debugging is enabled, due to a missing permission check. This could lead to local escalation of privile...Show more |
Improper access control vulnerability in SamsungRecovery prior to version 8.1.43.0 allows local attckers to delete arbitrary files as SamsungRecovery permission. |
Discourse is an open source platform for community discussion. In stable versions prior to 2.8.3 and beta versions prior 2.9.0.beta4 erroneously expose groups. When a group with restricted visibility has been used to set...Show more |
Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify users' personal information. |