← Back
CWE-552

507 CVEs • Abstraction: Base

Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

JSON object

Loading...

CVEs (507)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Airspan
1Airvelocity 1500 Firmware
Jun 17, 2026
Aug 16, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web server binary, and the web server configuration file. These vulnerabilities were f...Show more
An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web server binary, and the web server configuration file. These vulnerabilities were found in AirVelocity 1500 running software version 9.3.0.01249, were still present in 15.18.00.2511, and may affect other AirVelocity and AirSpeed models.Show less
1Ibm
3Robotic Process Automation
Robotic Process Automation As A ServiceRobotic Process Automation For Cloud Pak
Jun 17, 2026
Aug 10, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information. IBM X-Force ID: 226342.
1Wsm Downloader Project
1Wsm Downloader
Jun 17, 2026
Aug 8, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file download feature to download any local files, including sensitive ones like wp-config.php.
1Project Source Code Download Project
1Project Source Code Download
Jun 17, 2026
Aug 1, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download functionalities, which may allow any visitors on the site to download the entire site, including sensiti...Show more
The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download functionalities, which may allow any visitors on the site to download the entire site, including sensitive files like wp-config.php.Show less
1Trendmicro
1Vpn Proxy One Pro
Jun 17, 2026
Jul 30, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Trend Micro VPN Proxy Pro version 5.2.1026 and below contains a vulnerability involving some overly permissive folders in a key directory which could allow a local attacker to obtain privilege escalation on an affected s...Show more
Trend Micro VPN Proxy Pro version 5.2.1026 and below contains a vulnerability involving some overly permissive folders in a key directory which could allow a local attacker to obtain privilege escalation on an affected system.Show less
1Multisafepay
1Multisafepay Plugin For Woocommerce
Jun 17, 2026
Jul 22, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin <= 4.13.1 at WordPress.
1Givewp
1Givewp
Jun 17, 2026
Jul 21, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.
1Wavlink
1Wl Wn530hg4 Firmware
Jun 17, 2026
Jul 20, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.
1Reolink
1E1 Zoom Firmware
Jun 17, 2026
Jul 17, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. In this way an attacker can download the entire NGINX/FastCGI conf...Show more
The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. In this way an attacker can download the entire NGINX/FastCGI configurations by querying the /conf/nginx.conf or /conf/fastcgi.conf URI.Show less
1Reolink
1E1 Zoom Firmware
Jun 17, 2026
Jul 17, 2022
N/A· v4
5.9 MEDIUM· v3
N/A· v2
The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the /self.key URI.
1Wpchill
1Download Monitor
Jun 17, 2026
Jul 17, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or...Show more
The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.Show less
1Google
1Android
Jun 17, 2026
Jul 12, 2022
N/A· v4
2.3 LOW· v3
2.1 LOW· v2
Exposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.
1Siemens
4Sicam Gridedge Essential Arm
Sicam Gridedge Essential Gds ArmSicam Gridedge Essential Gds Intel+1 more
Jun 17, 2026
Jul 12, 2022
5.3 MEDIUM· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.7.3). The affected application uses an improperly protected file to import SSH keys. This could allow attackers with access to the filesy...Show more
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.7.3). The affected application uses an improperly protected file to import SSH keys. This could allow attackers with access to the filesystem of the host on which SICAM GridEdge runs to inject a custom SSH key to that file.Show less
1Iobit
1Advanced Systemcare
Jul 9, 2026
Jul 6, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramData folder, ProgramData folder has "rwx" permissions for unprivileged users. Low privilege users can...Show more
IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramData folder, ProgramData folder has "rwx" permissions for unprivileged users. Low privilege users can use SetOpLock to wait for CreateProcess and switch the genuine component with a malicious executable thus gaining code execution as a high privilege user (Low Privilege -> high integrity ADMIN).Show less
1Codesys
2Plcwinnt
Runtime Toolkit
Jun 17, 2026
Jun 24, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the PLC. All requests are processed on the controller only if no level 1 pas...Show more
In multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the PLC. All requests are processed on the controller only if no level 1 password is configured on the controller or if remote attacker has previously successfully authenticated himself to the controller. A successful Attack may lead to a denial of service, change of local files, or drain of confidential Information. User interaction is not requiredShow less
174cms
174cmsse
Jun 17, 2026
May 26, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Download.php.
1Ginadmin Project
1Ginadmin
Jun 17, 2026
May 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In ginadmin through 05-10-2022, the incoming path value is not filtered, resulting in arbitrary file reading.
1Redhat
3Jboss Enterprise Application Platform
Single Sign OnWildfly Core
Jun 17, 2026
May 24, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerabili...Show more
A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, integrity, and availability. This flaw affects wildfly-core versions prior to 17.0.Show less
1Wow Company
1Hover Effects
Jun 17, 2026
May 20, 2022
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
Authenticated (administrator or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Hover Effects plugin <= 2.1 at WordPress.
1Wow Company
1Counter Box
Jun 17, 2026
May 19, 2022
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugin <= 1.1.1 at WordPress.