← Back
CWE-552

507 CVEs • Abstraction: Base

Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

JSON object

Loading...

CVEs (507)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jflyfox
1Jfinal Cms
Jun 17, 2026
Jun 16, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
jfinal CMS 5.1.0 has an arbitrary file read vulnerability.
1Google
1Guava
Jun 17, 2026
Jun 14, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with...Show more
Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class. Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.Show less
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Jun 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.
1Linuxfoundation
1Lima
Jun 17, 2026
May 30, 2023
N/A· v4
2.5 LOW· v3
N/A· v2
Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to version 0.16.0, a virtual machine instance with a malicious disk image could read a single file on the host filesystem, even when...Show more
Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to version 0.16.0, a virtual machine instance with a malicious disk image could read a single file on the host filesystem, even when no filesystem is mounted from the host. The official templates of Lima and the well-known third party products (Colima, Rancher Desktop, and Finch) are unlikely to be affected by this issue. To exploit this issue, the attacker has to embed the target file path (an absolute or a relative path from the instance directory) in a malicious disk image, as the qcow2 (or vmdk) backing file path string. As Lima refuses to run as the root, it is practically impossible for the attacker to read the entire host disk via `/dev/rdiskN`. Also, practically, the attacker cannot read at least the first 512 bytes (MBR) of the target file. The issue has been patched in Lima in version 0.16.0 by prohibiting using a backing file path in the VM base image.Show less
1Apache
1Inlong
Jun 17, 2026
May 22, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Different users in InLong could delete, edit, stop...Show more
Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Different users in InLong could delete, edit, stop, and start others' sources! Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7775 https://github.com/apache/inlong/pull/7775 to solve it. Show less
1Apache
1Inlong
Jun 17, 2026
May 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. the user in InLong could cancel an application tha...Show more
Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. the user in InLong could cancel an application that doesn't belongs to it. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7799 https://github.com/apache/inlong/pull/7799 to solve it. Show less
1Acronis
2Agent
Cyber Protect
Jun 17, 2026
May 18, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 28610, Acronis Cyber Protect 15 (Linux, macOS, Wind...Show more
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 28610, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 30984.Show less
1Cisco
1Catalyst Center
Jun 17, 2026
May 18, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in...Show more
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
1Catalyst Center
Jun 17, 2026
May 18, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in...Show more
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Weaver
1E Office
Jun 17, 2026
May 17, 2023
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini. The manipulation leads to fi...Show more
A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini. The manipulation leads to files or directories accessible. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-229271. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Webroot
1Secureanywhere
Jul 9, 2026
May 12, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to access sensitive information via the EXE installer. NOTE: the vendor's perspective is that this is no...Show more
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to access sensitive information via the EXE installer. NOTE: the vendor's perspective is that this is not a separate vulnerability relative to CVE-2023-29818 and CVE-2023-29819.Show less
1Siemens
26gk1411 1ac00 Firmware
6gk1411 5ac00 Firmware
Jun 17, 2026
May 9, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The export endpoint discloses some undocumented files. This...Show more
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The export endpoint discloses some undocumented files. This could allow an unauthenticated remote attacker to gain access to additional information resources.Show less
1Gdidees
1Gdidees Cms
Jun 17, 2026
Apr 7, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
GDidees CMS v3.9.1 was discovered to contain a source code disclosure vulnerability by the backup feature which is accessible via /_admin/backup.php.
1Wpeasycart
1Wp Easycart
Jun 17, 2026
Apr 3, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticated users with admin privileges to perform LFI attacks.
1Propumpservice
1Osprey Pump Controller Firmware
Jun 17, 2026
Mar 28, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated file disclosure. Using a GET parameter, attackers can disclose arbitrary files on the affected device and disclose sensitive and system information.
1Stimulsoft
1Designer
Jul 9, 2026
Mar 28, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.
1Amano
1Xoffice
Jun 17, 2026
Mar 28, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
amano Xparc parking solutions 7.1.3879 was discovered to be vulnerable to local file inclusion.
1Saysis
1Starcities
Jun 17, 2026
Mar 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Files or Directories Accessible to External Parties vulnerability in Saysis Starcities allows Collect Data from Common Resource Locations. This issue affects Starcities: through 1.3.
1Onekeyadmin
1Onekeyadmin
Jun 17, 2026
Mar 9, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/file/download.
1Onekeyadmin
1Onekeyadmin
Jun 17, 2026
Mar 8, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/curd/code.