← Back
CWE-552

479 CVEs • Abstraction: Base

Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

JSON object

Loading...

CVEs (479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
174cms
174cms
Jun 17, 2026
Mar 28, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php.
1Navercorp
1Whale
Jun 17, 2026
Mar 17, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Whale browser before 3.12.129.18 allowed extensions to replace JavaScript files of the HWP viewer website which could access to local HWP files. When the HWP files were opened, the replaced script could read the files.
1Cuppacms
1Cuppacms
Jun 17, 2026
Mar 15, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.
1Secomea
1Gatemanager
Jun 17, 2026
Mar 4, 2022
N/A· v4
8.7 HIGH· v3
8.5 HIGH· v2
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories.
1Keep
1Archeevo
Jun 17, 2026
Mar 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Archeevo below 5.0 is affected by local file inclusion through file=~/web.config to allow an attacker to retrieve local files.
1Horizontcms Project
1Horizontcms
Jun 17, 2026
Feb 24, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HorizontCMS v1.0.0-beta.2 was discovered to contain an arbitrary file download vulnerability via the component /admin/file-manager/.
1Drogon
1Drogon
Jun 17, 2026
Feb 21, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
This affects the package drogonframework/drogon before 1.7.5. The unsafe handling of file names during upload using HttpFile::save() method may enable attackers to write files to arbitrary locations outside the designate...Show more
This affects the package drogonframework/drogon before 1.7.5. The unsafe handling of file names during upload using HttpFile::save() method may enable attackers to write files to arbitrary locations outside the designated target folder.Show less
1Cesanta
1Mongoose
Jun 17, 2026
Feb 18, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target...Show more
This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder.Show less
1Xwiki
1Xwiki
Jun 17, 2026
Feb 9, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT right can read any file located in the XWiki WAR (for example xwiki.cfg a...Show more
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT right can read any file located in the XWiki WAR (for example xwiki.cfg and xwiki.properties) through XWiki#invokeServletAndReturnAsString as `$xwiki.invokeServletAndReturnAsString("/WEB-INF/xwiki.cfg")`. This issue has been patched in XWiki versions 12.10.9, 13.4.3 and 13.7-rc-1. Users are advised to update. The only workaround is to limit SCRIPT right.Show less
1Mahara
1Mahara
Jun 17, 2026
Feb 9, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1, the names of folders in the Files area can be seen by a person not owning the folders. (Only folder names are affected. Neither file names n...Show more
In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1, the names of folders in the Files area can be seen by a person not owning the folders. (Only folder names are affected. Neither file names nor file contents are affected.)Show less
1Seur Oficial Project
1Seur Oficial
Jun 17, 2026
Feb 7, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is used for support purposes, it allows to download any file from the web server without restriction aft...Show more
The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is used for support purposes, it allows to download any file from the web server without restriction after knowing the URL and a password than an administrator can see in the plugin settings page.Show less
1Taogogo
1Taocms
Jun 17, 2026
Feb 4, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
In taocms 3.0.1 after logging in to the background, there is an Arbitrary file download vulnerability at the File Management column.
1Taogogo
1Taocms
Jun 17, 2026
Feb 4, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in taoCMS v3.0.2. There is an arbitrary file read vulnerability that can read any files via admin.php?action=file&ctrl=download&path=../../1.txt.
1Reolink
1Rlc 410w Firmware
Jun 17, 2026
Jan 28, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An atta...Show more
An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.Show less
1Fresenius Kabi
1Agilia Sp Mc Wifi Firmware
Jun 17, 2026
Jan 21, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An attacker may use this functionality to change the exposed configuration values such as network settin...Show more
Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An attacker may use this functionality to change the exposed configuration values such as network settings.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jan 18, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.
1Google
1Android
Jun 17, 2026
Jan 10, 2022
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
An implicit Intent hijacking vulnerability in Dialer prior to SMR Jan-2022 Release 1 allows unprivileged applications to access contact information.
1Google
1Android
Jun 17, 2026
Jan 10, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applications to get a local Bluetooth MAC address.
1Google
1Android
Jun 17, 2026
Jan 10, 2022
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox Guard via Samsung DeX mode.
1Google
1Android
Jun 17, 2026
Jan 10, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running application information.