← Back
CWE-552

479 CVEs • Abstraction: Base

Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

JSON object

Loading...

CVEs (479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Catalyst Center
Jun 17, 2026
May 18, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in...Show more
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Weaver
1E Office
Jun 17, 2026
May 17, 2023
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini. The manipulation leads to fi...Show more
A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini. The manipulation leads to files or directories accessible. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-229271. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Webroot
1Secureanywhere
Jul 9, 2026
May 12, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to access sensitive information via the EXE installer. NOTE: the vendor's perspective is that this is no...Show more
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to access sensitive information via the EXE installer. NOTE: the vendor's perspective is that this is not a separate vulnerability relative to CVE-2023-29818 and CVE-2023-29819.Show less
1Siemens
26gk1411 1ac00 Firmware
6gk1411 5ac00 Firmware
Jun 17, 2026
May 9, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The export endpoint discloses some undocumented files. This...Show more
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The export endpoint discloses some undocumented files. This could allow an unauthenticated remote attacker to gain access to additional information resources.Show less
1Gdidees
1Gdidees Cms
Jun 17, 2026
Apr 7, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
GDidees CMS v3.9.1 was discovered to contain a source code disclosure vulnerability by the backup feature which is accessible via /_admin/backup.php.
1Wpeasycart
1Wp Easycart
Jun 17, 2026
Apr 3, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticated users with admin privileges to perform LFI attacks.
1Propumpservice
1Osprey Pump Controller Firmware
Jun 17, 2026
Mar 28, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated file disclosure. Using a GET parameter, attackers can disclose arbitrary files on the affected device and disclose sensitive and system information.
1Stimulsoft
1Designer
Jul 9, 2026
Mar 28, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.
1Amano
1Xoffice
Jun 17, 2026
Mar 28, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
amano Xparc parking solutions 7.1.3879 was discovered to be vulnerable to local file inclusion.
1Saysis
1Starcities
Jun 17, 2026
Mar 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Files or Directories Accessible to External Parties vulnerability in Saysis Starcities allows Collect Data from Common Resource Locations. This issue affects Starcities: through 1.3.
1Onekeyadmin
1Onekeyadmin
Jun 17, 2026
Mar 9, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/file/download.
1Onekeyadmin
1Onekeyadmin
Jun 17, 2026
Mar 8, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/curd/code.
1Blogengine
1Blogengine.net
Jun 17, 2026
Mar 6, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files of unpublished blogs.
1Open Emr
1Openemr
Jun 17, 2026
Feb 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controlling a connection to an attacker-controlled MySQL server.
1Deltaww
1Diaenergie
Jun 17, 2026
Feb 17, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization, which could allow an unauthorized user to bypass authorization and access privileged functionality.
1Crmeb
1Crmeb
Jun 17, 2026
Feb 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
CRMEB 4.4.4 is vulnerable to Any File download.
1Lmxcms
1Lmxcms
Jun 17, 2026
Feb 1, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
lmxcms v1.41 was discovered to contain an arbitrary file read vulnerability via TemplateAction.class.php.
1Easy Images Project
1Easy Images
Jun 17, 2026
Feb 1, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Easy Images v2.0 was discovered to contain an arbitrary file download vulnerability via the component /application/down.php. This vulnerability is exploited via a crafted GET request.
2Debian
Openstack
2Debian Linux
Swift
Jun 17, 2026
Jan 18, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host...Show more
An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and earlier, no longer actively developed).Show less
1Weave
1Weave Gitops
Jun 17, 2026
Jan 9, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in GitOps run could allow a local user or process to alter a K...Show more
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in GitOps run could allow a local user or process to alter a Kubernetes cluster's resources. GitOps run has a local S3 bucket which it uses for synchronizing files that are later applied against a Kubernetes cluster. Its endpoint had no security controls to block unauthorized access, therefore allowing local users (and processes) on the same machine to see and alter the bucket content. By leveraging this vulnerability, an attacker could pick a workload of their choosing and inject it into the S3 bucket, which resulted in the successful deployment in the target cluster, without the need to provide any credentials to either the S3 bucket nor the target Kubernetes cluster. There are no known workarounds for this issue, please upgrade. This vulnerability has been fixed by commits 75268c4 and 966823b. Users should upgrade to Weave GitOps version >= v0.12.0 released on 08/12/2022. ### Workarounds There is no workaround for this vulnerability. ### References Disclosed by Paulo Gomes, Senior Software Engineer, Weaveworks. ### For more information If you have any questions or comments about this advisory: - Open an issue in [Weave GitOps repository](https://github.com/weaveworks/weave-gitops) - Email us at [support@weave.works](mailto:support@weave.works) Show less