← Back
CWE-552

479 CVEs • Abstraction: Base

Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

JSON object

Loading...

CVEs (479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Reolink
1E1 Zoom Firmware
Jun 17, 2026
Jul 17, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. In this way an attacker can download the entire NGINX/FastCGI conf...Show more
The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. In this way an attacker can download the entire NGINX/FastCGI configurations by querying the /conf/nginx.conf or /conf/fastcgi.conf URI.Show less
1Reolink
1E1 Zoom Firmware
Jun 17, 2026
Jul 17, 2022
N/A· v4
5.9 MEDIUM· v3
N/A· v2
The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the /self.key URI.
1Wpchill
1Download Monitor
Jun 17, 2026
Jul 17, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or...Show more
The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.Show less
1Google
1Android
Jun 17, 2026
Jul 12, 2022
N/A· v4
2.3 LOW· v3
2.1 LOW· v2
Exposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.
1Siemens
4Sicam Gridedge Essential Arm
Sicam Gridedge Essential Gds ArmSicam Gridedge Essential Gds Intel+1 more
Jun 17, 2026
Jul 12, 2022
5.3 MEDIUM· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.7.3). The affected application uses an improperly protected file to import SSH keys. This could allow attackers with access to the filesy...Show more
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.7.3). The affected application uses an improperly protected file to import SSH keys. This could allow attackers with access to the filesystem of the host on which SICAM GridEdge runs to inject a custom SSH key to that file.Show less
1Iobit
1Advanced Systemcare
Jul 9, 2026
Jul 6, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramData folder, ProgramData folder has "rwx" permissions for unprivileged users. Low privilege users can...Show more
IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramData folder, ProgramData folder has "rwx" permissions for unprivileged users. Low privilege users can use SetOpLock to wait for CreateProcess and switch the genuine component with a malicious executable thus gaining code execution as a high privilege user (Low Privilege -> high integrity ADMIN).Show less
1Codesys
2Plcwinnt
Runtime Toolkit
Jun 17, 2026
Jun 24, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the PLC. All requests are processed on the controller only if no level 1 pas...Show more
In multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the PLC. All requests are processed on the controller only if no level 1 password is configured on the controller or if remote attacker has previously successfully authenticated himself to the controller. A successful Attack may lead to a denial of service, change of local files, or drain of confidential Information. User interaction is not requiredShow less
174cms
174cmsse
Jun 17, 2026
May 26, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Download.php.
1Ginadmin Project
1Ginadmin
Jun 17, 2026
May 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In ginadmin through 05-10-2022, the incoming path value is not filtered, resulting in arbitrary file reading.
1Redhat
3Jboss Enterprise Application Platform
Single Sign OnWildfly Core
Jun 17, 2026
May 24, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerabili...Show more
A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, integrity, and availability. This flaw affects wildfly-core versions prior to 17.0.Show less
1Wow Company
1Hover Effects
Jun 17, 2026
May 20, 2022
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
Authenticated (administrator or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Hover Effects plugin <= 2.1 at WordPress.
1Wow Company
1Counter Box
Jun 17, 2026
May 19, 2022
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugin <= 1.1.1 at WordPress.
1Cmseasy
1Cmseasy
Jun 17, 2026
May 17, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_database) can be read t...Show more
cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_database) can be read through this vulnerability.Show less
1Contec
1Sv Cpt Mc310 Firmware
Jun 17, 2026
May 12, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
SolarView Compact ver.6.00 was discovered to contain a local file disclosure via /html/Solar_Ftp.php.
1Xxyopen
1Novel Plus
Jun 17, 2026
May 5, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.
1Webtoprint
1Web To Print Shop\
Jun 17, 2026
Apr 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url_to_base64 AJAX action (available to both unauthenticated and authenticated users) before using it i...Show more
The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url_to_base64 AJAX action (available to both unauthenticated and authenticated users) before using it in the file_get_contents function and returning its content base64 encoded in the response. As a result, unauthenticated users could read arbitrary files on the web server (such as /etc/passwd, wp-config.php etc)Show less
1Kitesky
1Kitecms
Jun 17, 2026
Apr 21, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
KiteCMS v1.1.1 was discovered to contain an arbitrary file read vulnerability via the background management module.
1Samsung
1Accessibility
Jun 17, 2026
Apr 11, 2022
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Android S(12.0) allows attacker to access the file with system privilege.
1Asana
1Desktop
Jun 17, 2026
Apr 9, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Asana Desktop before 1.6.0 allows remote attackers to exfiltrate local files if they can trick the Asana desktop app into loading a malicious web page.
1Movie Seat Reservation Project
1Movie Seat Reservation
Jun 17, 2026
Apr 8, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Movie Seat Reservation v1 was discovered to contain an unauthenticated file disclosure vulnerability via /index.php?page=home.