← Back
CWE-552

479 CVEs • Abstraction: Base

Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

JSON object

Loading...

CVEs (479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
7Rational Collaborative Lifecycle Management
Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 more
Nov 21, 2024
Mar 23, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM RSA DM (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to access settings that they should not be able to using a specially crafted URL. IBM X-Force ID: 132625.
1Cisco
1Elastic Services Controller
Nov 21, 2024
Jan 18, 2018
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an unauthenticated, local attacker to access sensitive information on a targeted system. The vulnerability is due to insuffic...Show more
A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an unauthenticated, local attacker to access sensitive information on a targeted system. The vulnerability is due to insufficient security restrictions. An attacker could exploit this vulnerability by accessing unauthorized information within the ConfD directory and file structure. Successful exploitation could allow the attacker to view sensitive information. Cisco Bug IDs: CSCvg00221.Show less
2Heketi Project
Redhat
2Enterprise Linux
Heketi
May 13, 2026
Dec 18, 2017
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
1Synology
1Photo Station
May 13, 2026
Dec 4, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain arbitrary files via prog_id field.
2Debian
Roundcube
2Debian Linux
Webmail
Apr 21, 2026
Nov 9, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017...Show more
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.Show less
1Apple
1Itunes
May 13, 2026
Oct 23, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in certain Apple products. iTunes before 12.7 is affected. The issue involves the "Data Sync" component. It allows attackers to access iOS backups (written by iTunes) via a crafted app.
1Microsoft
2Windows 10
Windows Server 2016
May 13, 2026
Oct 13, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Microsoft Windows 10 allows an elevation of privilege vulnerability when the Windows Update Delivery Optimization does not properly enforce file share permissions.
1Intelbras
1Wrn 150 Firmware
May 13, 2026
Sep 30, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg containing an admin:language=pt cookie.
1Inpsyde
1Backwpup
May 13, 2026
Sep 28, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Vulnerability in Wordpress plugin BackWPup before v3.4.2 allows possible brute forcing of backup file for download.
1Zte
4Zxr10 160 Firmware
Zxr10 1800 2s FirmwareZxr10 2800 4 Firmware+1 more
May 13, 2026
Sep 19, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being able to download configuration files to steal information like administrator acco...Show more
The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being able to download configuration files to steal information like administrator accounts and passwords.Show less
1Cisco
1Asr 5000 Software
May 13, 2026
Aug 17, 2017
N/A· v4
5.0 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticated, remote attacker to overwrite or modify sensitive system files. The vulnerabilit...Show more
A vulnerability in Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticated, remote attacker to overwrite or modify sensitive system files. The vulnerability is due to the inclusion of sensitive system files within specific FTP subdirectories. An attacker could exploit this vulnerability by overwriting sensitive configuration files through FTP. An exploit could allow the attacker to overwrite configuration files on an affected system. Cisco Bug IDs: CSCvd47739. Known Affected Releases: 21.0.v0.65839.Show less
1Fortinet
1Fortiweb
May 13, 2026
Aug 10, 2017
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An information disclosure vulnerability in Fortinet FortiWeb 5.8.2 and below versions allows logged-in admin user to view SNMPv3 user password in cleartext in webui via the HTML source code.
1Inversepath
1Tenshi
May 13, 2026
Jul 30, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Tenshi 0.15 creates a tenshi.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for tenshi.pid modification b...Show more
Tenshi 0.15 creates a tenshi.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for tenshi.pid modification before a root script executes a "kill `cat /pathname/tenshi.pid`" command.Show less
1Ibm
1Daeja Viewone
May 13, 2026
Jul 13, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0 could allow an authenticated attacker to download files they should not have access to due to improper access controls. IBM X-Force ID: 125462.
2Debian
Vmware
2Debian Linux
Spring Framework
May 13, 2026
May 25, 2017
N/A· v4
9.6 CRITICAL· v3
9.3 HIGH· v2
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user cra...Show more
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.Show less
6Canonical
ImagemagickOpensuse+3 more
30Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux For Ibm Z Systems+27 more
Apr 22, 2026
May 5, 2016
N/A· v4
5.5 MEDIUM· v3
5.8 MEDIUM· v2
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
2Linux
Redhat
3Enterprise Linux
Enterprise MrgLinux Kernel
May 6, 2026
May 2, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of servic...Show more
The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a failed invocation of a system call, as demonstrated by using chown to remove a capability from the ping or Wireshark dumpcap program.Show less
1Digitaldesign Cms Project
1Digitaldesign Cms
Apr 23, 2026
Oct 8, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Digitaldesign CMS 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for autoconfig.dd.
1Nextweb
1Nextweb (i)site
Apr 16, 2026
Jun 1, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
NEXTWEB (i)Site stores databases under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to databases/Users.mdb.