CWE-552
506 CVEs • Abstraction: Base
Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
CVEs (506)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Emby Server is a personal media server with apps on many devices. In Emby Server on Windows there is a set of arbitrary file read vulnerabilities. This vulnerability is known to exist in version 4.6.4.0 and may not be pa...Show more |
A vulnerability in the web UI for Cisco Nexus Insights could allow an authenticated, remote attacker to view and download files related to the web application. The attacker requires valid device credentials. This vulnera...Show more |
The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary files from the filesystem by specifying the file path. |
1Digitalzoomstudio 1Zoomsounds Jun 17, 2026 Aug 31, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the `dzsap_download` action using directory traversal in the `link`...Show more |
An information disclosure vulnerability in rConfig 3.9.5 has been fixed for version 3.9.6. This vulnerability allowed remote authenticated attackers to read files on the system via a crafted request sent to to the /lib/c...Show more |
1Joyplus Cms Project 1Joyplus Cms Jun 17, 2026 Aug 18, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information. |
In gitit before 0.15.0.0, the Export feature can be exploited to leak information from files. |
Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation of a pathname in index.php. |
If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS handshake, then Thunderbird didn't ignore the injected data. Th...Show more |
1Codesys 7Control Control RteControl Runtime System Toolkit+4 moreJun 17, 2026 Aug 3, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties. |
2Fedoraproject Nextcloud2Fedora Nextcloud ServerJun 17, 2026 Jul 12, 2021 N/A· v4 8.8 HIGH· v3 7.5 HIGH· v2 Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes. These tokens are supposed to be granted to a specific applications (e....Show more |
Ether Logs is a package that allows one to check one's logs in the Craft 3 utilities section. A vulnerability was found in versions prior to 3.0.4 that allowed authenticated admin users to access any file on the server....Show more |
1Schneider Electric 1Easergy T300 Firmware Jun 29, 2026 Jun 11, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an attacker is not restrict...Show more |
A vulnerability exists in gowitness < 2.3.6 that allows an unauthenticated attacker to perform an arbitrary file read using the file:// scheme in the url parameter to get an image of any file. |
Incorrect access to deleted scripts vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to gain access to signed SQL scripts which have been marked as deleted or expire...Show more |
Files are accessible without restrictions from the /update/results page of redhat-certification 7 package, allowing an attacker to remove any file accessible by the apached user. |
It was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer directory, through the /rhcert-transfer URL. An unauthorized attacker...Show more |
In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication. |
1Cisco 12Catalyst Sd Wan Manager Sd Wan Vbond OrchestratorSd Wan Vmanage+9 moreJun 17, 2026 May 6, 2021 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying file system of an affected system. This vulnerability is due to insufficient...Show more |
1Cisco 2Firepower Threat Defense Secure Firewall Threat DefenseAug 11, 2026 Apr 29, 2021 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite files on the file system of an affected device by using directory traversal techniques...Show more |