Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-732 (关键资源的不正确权限授予) — Vulnerability Class 444

444 vulnerabilities classified as CWE-732 (关键资源的不正确权限授予). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-41366 OpenClaw < 2026.3.31 - Arbitrary Host File Read via appendLocalMediaParentRoots Self-Whitelisting — OpenClaw 5.5 Medium2026-04-27
CVE-2026-35367 uutils coreutils nohup Information Disclosure via Insecure Default Output Permissions — coreutils 3.3 Low2026-04-22
CVE-2026-35341 uutils coreutils mkfifo Unauthorized Permission Change on Existing Files — coreutils 7.1 High2026-04-22
CVE-2026-6842 Nano: nano: local attacker can inject malicious .desktop launcher due to insecure directory permissions — Red Hat Enterprise Linux 10 2.5 Low2026-04-22
CVE-2026-22676 Barracuda RMM < 2025.2.2 Privilege Escalation via Insecure Directory Permissions — RMM 7.8 High2026-04-15
CVE-2026-4482 Insight Agent Private Key Information Disclosure via Inherited File Permissions — Insight Agent 7.1 -2026-04-10
CVE-2026-28264 Dell PowerProtect Agent Service 安全漏洞 — PowerProtect Agent 3.3 Low2026-04-08
CVE-2026-33271 Acronis True Image 安全漏洞 — Acronis True Image 7.8AIHighAI2026-04-02
CVE-2026-21765 HCL BigFix Platform is affected by insecure permissions on private cryptographic keys — BigFix Platform 8.8 High2026-04-01
CVE-2026-22768 Dell AppSync 安全漏洞 — AppSync 7.3 High2026-04-01
CVE-2026-34352 TigerVNC 安全漏洞 — TigerVNC 8.5 High2026-03-26
CVE-2026-33430 Briefcase: Windows MSI Installer Privilege Escalation via Insecure Directory Permissions — briefcase 7.3 High2026-03-26
CVE-2026-3113 mmctl export download command doesn’t restrict permissions to created file to file owner — Mattermost 5.0 Medium2026-03-26
CVE-2026-4761 Unnecessary permissions on private keys of certificates installed by Network and Security Wizard — Panorama Suite 7.5 -2026-03-25
CVE-2026-32048 OpenClaw < 2026.3.1 - Sandbox Escape via Cross-Agent sessions_spawn — OpenClaw 7.5 High2026-03-21
CVE-2026-32810 Halloy has insecure file permissions on credential files — halloy 7.1 -2026-03-20
CVE-2026-28563 Apache Airflow: DAG authorization bypass — Apache Airflow 4.3 -2026-03-17
CVE-2026-26929 Apache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata — Apache Airflow 5.3AIMediumAI2026-03-17
CVE-2026-29516 Buffalo TeraStation TS5400R Excessive File Permissions Information Disclosure — TeraStation NAS TS5400R 4.9 Medium2026-03-16
CVE-2025-15037 ASUS Business System Control Interface 安全漏洞 — ASUS Business System Control Interface 5.5AIMediumAI2026-03-12
CVE-2026-24291 Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability — Windows 10 Version 1607 7.8 High2026-03-10
CVE-2025-41712 Incorrect Permission Assignment on power analyzer — UMG 96RM-E 24V(5222063) 6.5 Medium2026-03-10
CVE-2026-28725 Acronis Cyber Protect 安全漏洞 — Acronis Cyber Protect 17 7.5 -2026-03-05
CVE-2025-30413 Acronis Cyber Protect和Acronis Cyber Protect Cloud Agent 安全漏洞 — Acronis Cyber Protect Cloud Agent 9.8 -2026-03-05
CVE-2025-11790 Acronis Cyber Protect Cloud Agent 安全漏洞 — Acronis Cyber Protect Cloud Agent 9.8 -2026-03-05
CVE-2026-29188 File Browser: TUS Delete Endpoint Bypasses Delete Permission Check — filebrowser 9.1 Critical2026-03-05
CVE-2026-29126 World-Writable, Root Owned/Run `/etc/udhcpc/default.script` in IDC SFX2100 Satellite Receiver Leads To Potential LPE — SFX2100 Satellite Receiver 7.8 -2026-03-05
CVE-2026-29125 IDC SFX2100 Satellite Receiver allows unprivileged modification of DNS configuration due to world-writable `/etc/resolv.conf` — SFX2100 Satellite Receiver 7.0 -2026-03-05
CVE-2025-14604 The following vulnerabilities, which may affect IBM Storage Scale when a directory has a specific ACL composition and could lead to improper execute permissions, have been remediated in Storage Scale versions 5.2.3.6 and 6.0.0.2 — Storage Scale 6.6 Medium2026-03-03
CVE-2026-2637 iBoysoft NTFS for Mac 安全漏洞 — iBoysoft NTFS 7.8AIHighAI2026-03-03

Vulnerabilities classified as CWE-732 (关键资源的不正确权限授予) represent 444 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.