CWE-552
479 CVEs • Abstraction: Base
Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
CVEs (479)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. In this way an attacker can download the entire NGINX/FastCGI conf...Show more |
The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the /self.key URI. |
The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or...Show more |
Exposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log. |
1Siemens 4Sicam Gridedge Essential Arm Sicam Gridedge Essential Gds ArmSicam Gridedge Essential Gds Intel+1 moreJun 17, 2026 Jul 12, 2022 5.3 MEDIUM· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.7.3). The affected application uses an improperly protected file to import SSH keys. This could allow attackers with access to the filesy...Show more |
IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramData folder, ProgramData folder has "rwx" permissions for unprivileged users. Low privilege users can...Show more |
1Codesys 2Plcwinnt Runtime ToolkitJun 17, 2026 Jun 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the PLC. All requests are processed on the controller only if no level 1 pas...Show more |
74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Download.php. |
In ginadmin through 05-10-2022, the incoming path value is not filtered, resulting in arbitrary file reading. |
1Redhat 3Jboss Enterprise Application Platform Single Sign OnWildfly CoreJun 17, 2026 May 24, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerabili...Show more |
Authenticated (administrator or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Hover Effects plugin <= 2.1 at WordPress. |
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugin <= 1.1.1 at WordPress. |
cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_database) can be read t...Show more |
SolarView Compact ver.6.00 was discovered to contain a local file disclosure via /html/Solar_Ftp.php. |
novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability. |
1Webtoprint 1Web To Print Shop\ Jun 17, 2026 Apr 25, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url_to_base64 AJAX action (available to both unauthenticated and authenticated users) before using it i...Show more |
KiteCMS v1.1.1 was discovered to contain an arbitrary file read vulnerability via the background management module. |
A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Android S(12.0) allows attacker to access the file with system privilege. |
Asana Desktop before 1.6.0 allows remote attackers to exfiltrate local files if they can trick the Asana desktop app into loading a malicious web page. |
1Movie Seat Reservation Project 1Movie Seat Reservation Jun 17, 2026 Apr 8, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Movie Seat Reservation v1 was discovered to contain an unauthenticated file disclosure vulnerability via /index.php?page=home. |