CWE-552
479 CVEs • Abstraction: Base
Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
CVEs (479)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuratio...Show more |
registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demonstrated by a @font-face rule. |
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. All files in the /opt/onedev/sites/ directory are exposed and can be read by unauthenticated users. This directory contains all projects, including...Show more |
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which allows attackers to steal all data such as source code and system files via a crafted GET request. |
A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how glibc names the runtime linker, a build time regular expression may not correctly detect the runtime linker. The consequence is...Show more |
ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, th...Show more |
1Redhat 4Ansible Automation Platform Ansible Automation Platform Early AccessAnsible Automation Platform Text Only Advisories+1 moreJun 17, 2026 Aug 25, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the iso...Show more |
2Fedoraproject Kernel2Fedora Util LinuxJun 17, 2026 Aug 23, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' fi...Show more |
2Fedoraproject Kernel2Fedora Util LinuxJun 17, 2026 Aug 23, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local attacker to unmount FUSE filesystems tha...Show more |
1Xplodedthemes 1Wpide File Manager & Code Editor Jun 17, 2026 Aug 23, 2022 N/A· v4 4.9 MEDIUM· v3 N/A· v2 Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress. |
3Debian GnomeNetapp3Active Iq Unified Manager Debian LinuxGlibJun 17, 2026 Aug 23, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivileged ones under the right condition. |
The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that can be exploited by users with "Contributor" permissions or higher. |
1Airspan 1Airvelocity 1500 Firmware Jun 17, 2026 Aug 16, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web server binary, and the web server configuration file. These vulnerabilities were f...Show more |
1Ibm 3Robotic Process Automation Robotic Process Automation As A ServiceRobotic Process Automation For Cloud PakJun 17, 2026 Aug 10, 2022 N/A· v4 4.9 MEDIUM· v3 N/A· v2 IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information. IBM X-Force ID: 226342. |
1Wsm Downloader Project 1Wsm Downloader Jun 17, 2026 Aug 8, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file download feature to download any local files, including sensitive ones like wp-config.php. |
1Project Source Code Download Project 1Project Source Code Download Jun 17, 2026 Aug 1, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download functionalities, which may allow any visitors on the site to download the entire site, including sensiti...Show more |
Trend Micro VPN Proxy Pro version 5.2.1026 and below contains a vulnerability involving some overly permissive folders in a key directory which could allow a local attacker to obtain privilege escalation on an affected s...Show more |
1Multisafepay 1Multisafepay Plugin For Woocommerce Jun 17, 2026 Jul 22, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin <= 4.13.1 at WordPress. |
Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress. |
An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data. |