Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-275 (Permission Issues) — Vulnerability Class 51

51 vulnerabilities classified as CWE-275 (Permission Issues). AI Chinese analysis included.

This page is a comprehensive vulnerability aggregation resource focused on the weakness type defined as CWE-275, which corresponds to the improper control of filenames for included files. It systematically collects all documented instances where software applications fail to properly validate external inputs before including files, a critical security flaw that can lead to remote code execution, information disclosure, and unauthorized system access. The database encompasses a wide historical range of vulnerabilities, capturing reports from early 2000s up to the most recent disclosures in the current year, ensuring a thorough coverage of both legacy systems and modern applications. By browsing this index, security professionals and developers can track vendor-specific security advisories to understand how different organizations have addressed this specific flaw across their product lines. Users can also deepen their understanding of the CWE-275 weakness class by analyzing common patterns, root causes, and mitigation strategies derived from real-world incidents. Furthermore, the page allows for looking up a specific product's vulnerability history, providing a clear timeline of when and how this weakness manifested in particular software versions. This structured approach facilitates easier risk assessment and helps in prioritizing patch management efforts by highlighting the prevalence and impact of inclusion flaws across various technology stacks.

CVE IDTitleCVSSSeverityPublished
CVE-2026-19376 Uasoft Badaso File API api.php class permission — Badaso 7.3 High2026-08-09
CVE-2026-19191 StableBit DrivePool DrivePoolService DrivePool.Service.exe permission — DrivePool 7.8 High2026-08-07
CVE-2026-19190 StableBit Scanner ScannerService Scanner.Service.exe permission — Scanner 7.8 High2026-08-07
CVE-2026-12201 IObit Malware Fighter DLL permission — Malware Fighter 5.3 Medium2026-06-15
CVE-2026-41976 Huawei EMUI和Huawei HarmonyOS 授权问题漏洞 — HarmonyOS 6.6 Medium2026-06-09
CVE-2026-41978 Huawei HarmonyOS 授权问题漏洞 — HarmonyOS 4.4 Medium2026-06-09
CVE-2026-41969 Huawei HarmonyOS 授权问题漏洞 — HarmonyOS 6.2 Medium2026-05-15
CVE-2026-28553 Huawei EMUI和Huawei HarmonyOS 安全漏洞 — HarmonyOS 6.9 Medium2026-04-13
CVE-2025-58288 Huawei HarmonyOS 安全漏洞 — HarmonyOS 5.5 Medium2025-10-11
CVE-2025-58287 Huawei HarmonyOS 安全漏洞 — HarmonyOS 7.8 High2025-10-11
CVE-2025-10941 Topaz SERVCore Teller Installer SERVCoreTeller_2.0.40D.msi permission — SERVCore Teller 7.8 High2025-09-25
CVE-2025-8797 LitmusChaos Litmus LocalStorage permission — Litmus 6.3 Medium2025-08-10
CVE-2025-54624 Huawei HarmonyOS 安全漏洞 — HarmonyOS 5.7 Medium2025-08-06
CVE-2025-54618 Huawei HarmonyOS 安全漏洞 — HarmonyOS 5.7 Medium2025-08-06
CVE-2025-53168 Huawei HarmonyOS 安全漏洞 — HarmonyOS 5.7 Medium2025-07-07
CVE-2025-6765 Intelbras InControl HTTP PUT Request operador permission — InControl 6.3 Medium2025-06-27
CVE-2024-13189 ZeroWdd myblog MyBlogMvcConfig.java permission — myblog 7.3 High2025-01-08
CVE-2024-11486 Code4Berry Decoration Management System User Permission user_permission.php — Decoration Management System 4.3 Medium2024-11-20
CVE-2024-11485 Code4Berry Decoration Management System User userregister.php permission — Decoration Management System 6.3 Medium2024-11-20
CVE-2024-3118 Dreamer CMS Attachment permission — CMS 6.3 Medium2024-03-31
CVE-2023-6762 Thecosy IceCMS Article permission — IceCMS 5.4 Medium2023-12-13
CVE-2023-6302 CSZCMS File Manager Page templates permission — CSZCMS 4.7 Medium2023-11-27
CVE-2023-5263 ZZZCMS Database Backup File save.php restore permission — ZZZCMS 6.3 Medium2023-09-29
CVE-2023-39399 Huawei HarmonyOS 安全漏洞 — HarmonyOS 9.8 -2023-08-13
CVE-2023-39398 Huawei HarmonyOS 安全漏洞 — HarmonyOS 9.8 -2023-08-13
CVE-2023-3759 Intergard SGS permission — SGS 6.3 Medium2023-07-19
CVE-2023-37238 Huawei HarmonyOS 安全漏洞 — HarmonyOS 6.5 -2023-07-06
CVE-2022-25153 ITarian - Local privilege escalation in Endpoint Manager agent on Windows — Endpoint Manager Communication Client for Windows 7.8 High2022-06-08
CVE-2020-14496 Mitsubishi Electric Multiple Factory Automation Engineering Software Products (Update A) - Permission Issues — CPU Module Logging Configuration Tool 8.3 High2022-05-19
CVE-2022-0343 Local Priviledge escalation in Perfetto Dev scripts — Perfetto Dev Scripts 3.3 Low2022-03-29

Vulnerabilities classified as CWE-275 (Permission Issues) represent 51 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.