← Back
CWE-552

507 CVEs • Abstraction: Base

Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

JSON object

Loading...

CVEs (507)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Taogogo
1Taocms
Jun 17, 2026
Feb 4, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in taoCMS v3.0.2. There is an arbitrary file read vulnerability that can read any files via admin.php?action=file&ctrl=download&path=../../1.txt.
1Reolink
1Rlc 410w Firmware
Jun 17, 2026
Jan 28, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An atta...Show more
An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.Show less
1Fresenius Kabi
1Agilia Sp Mc Wifi Firmware
Jun 17, 2026
Jan 21, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An attacker may use this functionality to change the exposed configuration values such as network settin...Show more
Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An attacker may use this functionality to change the exposed configuration values such as network settings.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jan 18, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.
1Google
1Android
Jun 17, 2026
Jan 10, 2022
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
An implicit Intent hijacking vulnerability in Dialer prior to SMR Jan-2022 Release 1 allows unprivileged applications to access contact information.
1Google
1Android
Jun 17, 2026
Jan 10, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applications to get a local Bluetooth MAC address.
1Google
1Android
Jun 17, 2026
Jan 10, 2022
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox Guard via Samsung DeX mode.
1Google
1Android
Jun 17, 2026
Jan 10, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running application information.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Jan 3, 2022
N/A· v4
4.3 MEDIUM· v3
3.5 LOW· v2
ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web root with a predictable filename based on the domain name. When ADSSP is configured with multiple Windo...Show more
ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web root with a predictable filename based on the domain name. When ADSSP is configured with multiple Windows domains, a user from one domain can obtain the password policy for another domain by authenticating to the service and then sending a request specifying the password policy file of the other domain.Show less
1Phpgurukul
1Bus Pass Management System
Jun 17, 2026
Dec 16, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to view the sensitive files of the application, for example: Any file which contains sensitive informat...Show more
In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to view the sensitive files of the application, for example: Any file which contains sensitive information of the user or server.Show less
1Apereo
1Opencast
Jun 17, 2026
Dec 14, 2021
N/A· v4
7.7 HIGH· v3
4.0 MEDIUM· v2
Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast before version 9.10 or 10.6 allows references to local file URLs in ingested media packages, allowing attackers to include local files...Show more
Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast before version 9.10 or 10.6 allows references to local file URLs in ingested media packages, allowing attackers to include local files from Opencast's host machines and making them available via the web interface. Before Opencast 9.10 and 10.6, Opencast would open and include local files during ingests. Attackers could exploit this to include most local files the process has read access to, extracting secrets from the host machine. An attacker would need to have the privileges required to add new media to exploit this. But these are often widely given. The issue has been fixed in Opencast 10.6 and 11.0. You can mitigate this issue by narrowing down the read access Opencast has to files on the file system using UNIX permissions or mandatory access control systems like SELinux. This cannot prevent access to files Opencast needs to read though and we highly recommend updating.Show less
1Samsung
1Internet
Jun 17, 2026
Dec 8, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet.
1Mcafee
1Database Security
Jun 17, 2026
Dec 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.9 MEDIUM· v2
A denial-of-service vulnerability in Database Security (DBS) prior to 4.8.4 allows a remote authenticated administrator to trigger a denial-of-service attack against the DBS server. The configuration of Archiving through...Show more
A denial-of-service vulnerability in Database Security (DBS) prior to 4.8.4 allows a remote authenticated administrator to trigger a denial-of-service attack against the DBS server. The configuration of Archiving through the User interface incorrectly allowed the creation of directories and files in Windows system directories and other locations where sensitive data could be overwritten. The former could lead to a DoS, whilst the latter could lead to data destruction on the DBS server.Show less
1Trendmicro
4Antivirus+ Security
Internet SecurityMaximum Security+1 more
Jun 17, 2026
Dec 3, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Trend Micro Security 2021 v17.0 (Consumer) contains a vulnerability that allows files inside the protected folder to be modified without any detection.
1Philips
2Mri 1.5t Firmware
Mri 3t Firmware
Jun 17, 2026
Nov 19, 2021
5.9 MEDIUM· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
1Hitachi
2Vantara Pentaho
Vantara Pentaho Business Intelligence Server
Jun 17, 2026
Nov 8, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the...Show more
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An authenticated user (regardless of privileges) can list all valid usernames.Show less
1Netscout
1Ngeniusone
Jun 17, 2026
Sep 30, 2021
N/A· v4
5.7 MEDIUM· v3
3.5 LOW· v2
NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Arbitrary File Read operations via the FDSQueryService endpoint.
1Hitachi
1Content Platform Anywhere
Jun 17, 2026
Sep 29, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Hitachi Content Platform Anywhere (HCP-AW) 4.4.5 and later allows information disclosure. If authenticated user creates a link to a file or folder while the system was running version 4.3.x or earlier and then shares the...Show more
Hitachi Content Platform Anywhere (HCP-AW) 4.4.5 and later allows information disclosure. If authenticated user creates a link to a file or folder while the system was running version 4.3.x or earlier and then shares the link and then later deletes the file or folder without deleting the link and before the link expires. If the system has been upgraded to version 4.4.5 or 4.5.0 a malicious user with the link could browse and download all files of the authenticated user that created the link .Show less
1Vmware
2Cloud Foundation
Vcenter Server
Jun 17, 2026
Sep 23, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administrative privilege may exploit these issues...Show more
The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administrative privilege may exploit these issues to elevate their privileges to root on vCenter Server Appliance.Show less
1Kubernetes
1Kubernetes
Jun 17, 2026
Sep 20, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.