← Back
CWE-552

479 CVEs • Abstraction: Base

Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

JSON object

Loading...

CVEs (479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fwupd
1Fwupd
Jun 17, 2026
Sep 28, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuratio...Show more
When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.Show less
1Dompdf Project
1Dompdf
Jun 17, 2026
Sep 25, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demonstrated by a @font-face rule.
1Onedev Project
1Onedev
Jun 17, 2026
Sep 13, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. All files in the /opt/onedev/sites/ directory are exposed and can be read by unauthenticated users. This directory contains all projects, including...Show more
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. All files in the /opt/onedev/sites/ directory are exposed and can be read by unauthenticated users. This directory contains all projects, including their bare git repos and build artifacts. This file disclosure vulnerability can be used by unauthenticated attackers to leak all project files of any project. Since project IDs are incremental, an attacker could iterate through them and leak all project data. This issue has been resolved in version 7.3.0 and users are advised to upgrade. There are no known workarounds for this issue.Show less
1Tendacn
1Ac6 Firmware
Jul 9, 2026
Aug 30, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which allows attackers to steal all data such as source code and system files via a crafted GET request.
1Fapolicyd Project
1Fapolicyd
Jun 17, 2026
Aug 29, 2022
N/A· v4
8.4 HIGH· v3
N/A· v2
A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how glibc names the runtime linker, a build time regular expression may not correctly detect the runtime linker. The consequence is...Show more
A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how glibc names the runtime linker, a build time regular expression may not correctly detect the runtime linker. The consequence is that the pattern detection for applications launched by the run time linker may fail to detect the pattern and allow execution.Show less
1Redhat
1Keycloak
Jun 17, 2026
Aug 26, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, th...Show more
ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, the client will receive the content of random files if available.Show less
1Redhat
4Ansible Automation Platform
Ansible Automation Platform Early AccessAnsible Automation Platform Text Only Advisories+1 more
Jun 17, 2026
Aug 25, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the iso...Show more
A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment.Show less
2Fedoraproject
Kernel
2Fedora
Util Linux
Jun 17, 2026
Aug 23, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' fi...Show more
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are either world-writable themselves (like /tmp) or mounted in a world-writable directory. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.Show less
2Fedoraproject
Kernel
2Fedora
Util Linux
Jun 17, 2026
Aug 23, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local attacker to unmount FUSE filesystems tha...Show more
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local attacker to unmount FUSE filesystems that belong to certain other users who have a UID that is a prefix of the UID of the attacker in its string form. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.Show less
1Xplodedthemes
1Wpide File Manager & Code Editor
Jun 17, 2026
Aug 23, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.
3Debian
GnomeNetapp
3Active Iq Unified Manager
Debian LinuxGlib
Jun 17, 2026
Aug 23, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivileged ones under the right condition.
1Lana
1Lana Downloads Manager
Jun 17, 2026
Aug 22, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that can be exploited by users with "Contributor" permissions or higher.
1Airspan
1Airvelocity 1500 Firmware
Jun 17, 2026
Aug 16, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web server binary, and the web server configuration file. These vulnerabilities were f...Show more
An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web server binary, and the web server configuration file. These vulnerabilities were found in AirVelocity 1500 running software version 9.3.0.01249, were still present in 15.18.00.2511, and may affect other AirVelocity and AirSpeed models.Show less
1Ibm
3Robotic Process Automation
Robotic Process Automation As A ServiceRobotic Process Automation For Cloud Pak
Jun 17, 2026
Aug 10, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information. IBM X-Force ID: 226342.
1Wsm Downloader Project
1Wsm Downloader
Jun 17, 2026
Aug 8, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file download feature to download any local files, including sensitive ones like wp-config.php.
1Project Source Code Download Project
1Project Source Code Download
Jun 17, 2026
Aug 1, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download functionalities, which may allow any visitors on the site to download the entire site, including sensiti...Show more
The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download functionalities, which may allow any visitors on the site to download the entire site, including sensitive files like wp-config.php.Show less
1Trendmicro
1Vpn Proxy One Pro
Jun 17, 2026
Jul 30, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Trend Micro VPN Proxy Pro version 5.2.1026 and below contains a vulnerability involving some overly permissive folders in a key directory which could allow a local attacker to obtain privilege escalation on an affected s...Show more
Trend Micro VPN Proxy Pro version 5.2.1026 and below contains a vulnerability involving some overly permissive folders in a key directory which could allow a local attacker to obtain privilege escalation on an affected system.Show less
1Multisafepay
1Multisafepay Plugin For Woocommerce
Jun 17, 2026
Jul 22, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin <= 4.13.1 at WordPress.
1Givewp
1Givewp
Jun 17, 2026
Jul 21, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.
1Wavlink
1Wl Wn530hg4 Firmware
Jun 17, 2026
Jul 20, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.