CWE-552
507 CVEs • Abstraction: Base
Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
CVEs (507)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Airspan 1Airvelocity 1500 Firmware Jun 17, 2026 Aug 16, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web server binary, and the web server configuration file. These vulnerabilities were f...Show more |
1Ibm 3Robotic Process Automation Robotic Process Automation As A ServiceRobotic Process Automation For Cloud PakJun 17, 2026 Aug 10, 2022 N/A· v4 4.9 MEDIUM· v3 N/A· v2 IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information. IBM X-Force ID: 226342. |
1Wsm Downloader Project 1Wsm Downloader Jun 17, 2026 Aug 8, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file download feature to download any local files, including sensitive ones like wp-config.php. |
1Project Source Code Download Project 1Project Source Code Download Jun 17, 2026 Aug 1, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download functionalities, which may allow any visitors on the site to download the entire site, including sensiti...Show more |
Trend Micro VPN Proxy Pro version 5.2.1026 and below contains a vulnerability involving some overly permissive folders in a key directory which could allow a local attacker to obtain privilege escalation on an affected s...Show more |
1Multisafepay 1Multisafepay Plugin For Woocommerce Jun 17, 2026 Jul 22, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin <= 4.13.1 at WordPress. |
Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress. |
An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data. |
The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. In this way an attacker can download the entire NGINX/FastCGI conf...Show more |
The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the /self.key URI. |
The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or...Show more |
Exposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log. |
1Siemens 4Sicam Gridedge Essential Arm Sicam Gridedge Essential Gds ArmSicam Gridedge Essential Gds Intel+1 moreJun 17, 2026 Jul 12, 2022 5.3 MEDIUM· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.7.3). The affected application uses an improperly protected file to import SSH keys. This could allow attackers with access to the filesy...Show more |
IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramData folder, ProgramData folder has "rwx" permissions for unprivileged users. Low privilege users can...Show more |
1Codesys 2Plcwinnt Runtime ToolkitJun 17, 2026 Jun 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the PLC. All requests are processed on the controller only if no level 1 pas...Show more |
74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Download.php. |
In ginadmin through 05-10-2022, the incoming path value is not filtered, resulting in arbitrary file reading. |
1Redhat 3Jboss Enterprise Application Platform Single Sign OnWildfly CoreJun 17, 2026 May 24, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerabili...Show more |
Authenticated (administrator or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Hover Effects plugin <= 2.1 at WordPress. |
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugin <= 1.1.1 at WordPress. |