Vulnerabilities (CVE)

Filtered by CWE-276
Total 1559 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-48070 1 Plane 1 Plane 2026-06-17 N/A 3.5 LOW
Plane is open-source project management software. Versions prior to 0.23 have insecure permissions in UserSerializer that allows users to change fields that are meant to be read-only, such as email. This can lead to account takeover when chained with another vulnerability such as cross-site scripting (XSS). Version 0.23 fixes the issue.
CVE-2025-46803 2026-06-17 N/A 5.0 MEDIUM
The default mode of pseudo terminals (PTYs) allocated by Screen was changed from 0620 to 0622, thereby allowing anyone to write to any Screen PTYs in the system.
CVE-2025-46587 1 Huawei 1 Harmonyos 2026-06-17 N/A 6.2 MEDIUM
Permission control vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2025-46586 1 Huawei 1 Harmonyos 2026-06-17 N/A 5.1 MEDIUM
Permission control vulnerability in the contacts module Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2025-46355 2026-06-17 N/A 7.3 HIGH
Incorrect default permissions issue in PC Time Tracer prior to 5.2. If exploited, arbitrary code may be executed with SYSTEM privilege on Windows system where the product is running by a local authenticated attacker.
CVE-2025-46185 2026-06-17 N/A 6.2 MEDIUM
An Insecure Permission vulnerability in pgcodekeeper 10.12.0 allows a local attacker to obtain sensitive information via the plaintext storage of passwords and usernames.
CVE-2025-46014 1 Honor 1 Pc Manager 2026-06-17 N/A 8.8 HIGH
Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named pipe iMateBookAssistant with default or overly permissive security attributes, leading to a privilege escalation.
CVE-2025-45467 1 Unitree 2 Go1, Go1 Firmware 2026-06-17 N/A 7.1 HIGH
Unitree Go1 <= Go1_2022_05_11 is vulnerable to Insecure Permissions as the firmware update functionality (via Wi-Fi/Ethernet) implements an insecure verification mechanism that solely relies on MD5 checksums for firmware integrity validation.
CVE-2025-43887 1 Dell 1 Powerprotect Data Manager 2026-06-17 N/A 7.0 HIGH
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
CVE-2025-43725 1 Dell 1 Powerprotect Data Manager 2026-06-17 N/A 7.8 HIGH
Dell PowerProtect Data Manager, Generic Application Agent, version(s) 19.19 and 19.20, contain(s) an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
CVE-2025-43596 1 Msp360 1 Backup 2026-06-17 N/A 7.8 HIGH
An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands with SYSTEM level privileges using a specially crafted file with an arbitrary file backup target. Upgrade to MSP360 Backup 8.1.1.19 (released on 2025-05-15).
CVE-2025-43595 2 Linux, Msp360 2 Linux Kernel, Backup 2026-06-17 N/A 7.8 HIGH
An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a low privileged user to execute commands with root privileges in the 'Online Backup' folder. Upgrade to MSP360 Backup 4.4 (released on 2025-04-22).
CVE-2025-43519 1 Apple 1 Macos 2026-06-17 N/A 5.5 MEDIUM
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app may be able to access sensitive user data.
CVE-2025-43507 1 Apple 4 Ipados, Iphone Os, Visionos and 1 more 2026-06-17 N/A 6.5 MEDIUM
A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. An app may be able to fingerprint the user.
CVE-2025-43444 1 Apple 5 Ipados, Iphone Os, Tvos and 2 more 2026-06-17 N/A 5.3 MEDIUM
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to fingerprint the user.
CVE-2025-43442 1 Apple 2 Ipados, Iphone Os 2026-06-17 N/A 3.3 LOW
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app may be able to identify what other apps a user has installed.
CVE-2025-43350 1 Apple 2 Ipados, Iphone Os 2026-06-17 N/A 2.4 LOW
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker may be able to view restricted content from the lock screen.
CVE-2025-42598 2026-06-17 N/A 7.8 HIGH
Multiple SEIKO EPSON printer drivers for Windows OS are configured with an improper access permission settings when installed or used in a language other than English. If a user is directed to place a crafted DLL file in a location of an attacker's choosing, the attacker may execute arbitrary code with SYSTEM privilege on a Windows system on which the printer driver is installed.
CVE-2025-41665 2026-06-17 N/A 6.5 MEDIUM
An low privileged remote attacker can enforce the watchdog of the affected devices to reboot the PLC due to incorrect default permissions of a config file.
CVE-2025-41658 2026-06-17 N/A 5.5 MEDIUM
CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.