CWE-552
507 CVEs • Abstraction: Base
Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
CVEs (507)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Markdownify version 1.4.1 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious markdown file through Markdownify. This is possible because the application d...Show more |
An improper cache key vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to access private repository files through a public repository. To exploit this, an actor would need to al...Show more |
Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery. |
Jenkins NUnit Plugin 0.27 and earlier implements an agent-to-controller message that parses files inside a user-specified directory as test results, allowing attackers able to control agent processes to obtain test resul...Show more |
The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such...Show more |
There is a file inclusion vulnerability in the template management module in UCMS 1.6 |
The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or...Show more |
A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows attackers to escalate privileges and execute arbitrary commands when Service Mode is activated. |
When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuratio...Show more |
registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demonstrated by a @font-face rule. |
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. All files in the /opt/onedev/sites/ directory are exposed and can be read by unauthenticated users. This directory contains all projects, including...Show more |
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which allows attackers to steal all data such as source code and system files via a crafted GET request. |
A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how glibc names the runtime linker, a build time regular expression may not correctly detect the runtime linker. The consequence is...Show more |
ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, th...Show more |
1Redhat 4Ansible Automation Platform Ansible Automation Platform Early AccessAnsible Automation Platform Text Only Advisories+1 moreJun 17, 2026 Aug 25, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the iso...Show more |
2Fedoraproject Kernel2Fedora Util LinuxJun 17, 2026 Aug 23, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' fi...Show more |
2Fedoraproject Kernel2Fedora Util LinuxJun 17, 2026 Aug 23, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local attacker to unmount FUSE filesystems tha...Show more |
1Xplodedthemes 1Wpide File Manager & Code Editor Jun 17, 2026 Aug 23, 2022 N/A· v4 4.9 MEDIUM· v3 N/A· v2 Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress. |
3Debian GnomeNetapp3Active Iq Unified Manager Debian LinuxGlibJun 17, 2026 Aug 23, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivileged ones under the right condition. |
The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that can be exploited by users with "Contributor" permissions or higher. |