CWE-552
479 CVEs • Abstraction: Base
Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
CVEs (479)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Jan 3, 2022 N/A· v4 4.3 MEDIUM· v3 3.5 LOW· v2 ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web root with a predictable filename based on the domain name. When ADSSP is configured with multiple Windo...Show more |
1Phpgurukul 1Bus Pass Management System Jun 17, 2026 Dec 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to view the sensitive files of the application, for example: Any file which contains sensitive informat...Show more |
Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast before version 9.10 or 10.6 allows references to local file URLs in ingested media packages, allowing attackers to include local files...Show more |
Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet. |
A denial-of-service vulnerability in Database Security (DBS) prior to 4.8.4 allows a remote authenticated administrator to trigger a denial-of-service attack against the DBS server. The configuration of Archiving through...Show more |
1Trendmicro 4Antivirus+ Security Internet SecurityMaximum Security+1 moreJun 17, 2026 Dec 3, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Trend Micro Security 2021 v17.0 (Consumer) contains a vulnerability that allows files inside the protected folder to be modified without any detection. |
1Philips 2Mri 1.5t Firmware Mri 3t FirmwareJun 17, 2026 Nov 19, 2021 5.9 MEDIUM· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
1Hitachi 2Vantara Pentaho Vantara Pentaho Business Intelligence ServerJun 17, 2026 Nov 8, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the...Show more |
NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Arbitrary File Read operations via the FDSQueryService endpoint. |
1Hitachi 1Content Platform Anywhere Jun 17, 2026 Sep 29, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Hitachi Content Platform Anywhere (HCP-AW) 4.4.5 and later allows information disclosure. If authenticated user creates a link to a file or folder while the system was running version 4.3.x or earlier and then shares the...Show more |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 Sep 23, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administrative privilege may exploit these issues...Show more |
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem. |
A local file inclusion vulnerability in ExpertPDF 9.5.0 through 14.1.0 allows attackers to read the file contents from files that the running ExpertPDF process has access to read. |
Emby Server is a personal media server with apps on many devices. In Emby Server on Windows there is a set of arbitrary file read vulnerabilities. This vulnerability is known to exist in version 4.6.4.0 and may not be pa...Show more |
A vulnerability in the web UI for Cisco Nexus Insights could allow an authenticated, remote attacker to view and download files related to the web application. The attacker requires valid device credentials. This vulnera...Show more |
The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary files from the filesystem by specifying the file path. |
1Digitalzoomstudio 1Zoomsounds Jun 17, 2026 Aug 31, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the `dzsap_download` action using directory traversal in the `link`...Show more |
An information disclosure vulnerability in rConfig 3.9.5 has been fixed for version 3.9.6. This vulnerability allowed remote authenticated attackers to read files on the system via a crafted request sent to to the /lib/c...Show more |
1Joyplus Cms Project 1Joyplus Cms Jun 17, 2026 Aug 18, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information. |
In gitit before 0.15.0.0, the Export feature can be exploited to leak information from files. |