CWE-732
Incorrect Permission Assignment for Critical Resource
MITRENo catalog description on file. The MITRE CWE site has the canonical reference.
Recent CVEs
showing 10 of 10- CVE-2019-15752High· 7.8KEVEXPLOITEPSS 46%23 h ago
Docker Desktop Community Edition Privilege Escalation Vulnerability
- CVE-2018-13374Medium· 4.3KEVEXPLOITEPSS 3%23 h ago
Fortinet FortiOS and FortiADC Improper Access Control Vulnerability
- CVE-2026-0271—EPSS 0%2 d ago
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Prisma Access Agent on Windows, macOS, iOS,
- CVE-2026-50570High· 8.5EPSS 0%2 d ago
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, Fission added PodSpec safety validation for tenant-facing Environment and
- CVE-2026-10840High· 7.1EPSS 0%4 d ago
A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRol
- CVE-2026-25112High· 7.8EPSS 0%4 d ago
A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack.
- CVE-2026-10997Medium· 6.5EPSS 0%4 d ago
Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium
- CVE-2026-26422High· 8.4EPSS 0%5 d ago
clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, leading to local privilege escalation.
- CVE-2017-7563High· 8.1EPSS 0%5 d ago
In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mechanism. This issue occurs because of inconsistency in the number of execute-never bits (one b
- CVE-2021-36133High· 7.1EPSS 0%7 d ago
The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure World memory. Th
CWE catalog data sourced from MITRE. CVE associations come from NVD weakness mappings; some CVEs carry multiple CWEs.