CWE-552
506 CVEs • Abstraction: Base
Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
CVEs (506)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Siemens 2Ozw672 Firmware Ozw772 FirmwareJun 17, 2026 Feb 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in OZW672 (All versions < V10.00), OZW772 (All versions < V10.00). Vulnerable versions of OZW Web Server use predictable path names for project files that legitimately authenticated us...Show more |
An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter. |
An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter. |
1Ruckuswireless 2Unleashed Zonedirector 1200 FirmwareJun 17, 2026 Jan 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credential fetch via an unauthenticated HTTP request involving a symlink with /tmp and web/user/wps_tool_ca...Show more |
An issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfig.ini in the web administration interface, revealing what database the web application is using. |
PhantomJS through 2.1.1 has an arbitrary file read vulnerability, as demonstrated by an XMLHttpRequest for a file:// URI. The vulnerability exists in the page.open() function of the webpage module, which loads a specifie...Show more |
1Ibm 2Cloud Orchestrator Cloud Orchestrator EnterpriseJun 17, 2026 Oct 24, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 could allow a local user to obtain sensitive information from SessionManagement cookies. IBM X-Force ID: 162259. |
1Zohocorp 1Manageengine Datasecurity Plus Jun 17, 2026 Oct 9, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user ("Operator" access level) to access the configuration file of the mail server (except for the passw...Show more |
1Sap 3Dynamic Tier Sap IqSql AnywhereJun 17, 2026 Oct 8, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in directories outside of...Show more |
vBulletin through 5.5.4 mishandles external URLs within the /core/vb/vurl.php file and the /core/vb/vurl directories. |
In SilverStripe assets 4.0, there is broken access control on files. |
1Intenogroup 1Eg200 Firmware Jun 17, 2026 Sep 16, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers have a JUCI ACL misconfiguration that allows the "user" account to extract the 3DES key via JSON commands to ubus. The 3DES key is used to decrypt the provisionin...Show more |
cPanel before 55.9999.141 allows arbitrary file-read operations because of a multipart form processing error (SEC-99). |
1Mcafee 1Data Loss Prevention Endpoint Jun 17, 2026 Jul 24, 2019 N/A· v4 8.2 HIGH· v3 4.6 MEDIUM· v2 Files or Directories Accessible to External Parties in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows authenticated user to redirect DLPe log files to arbitrary locations via incorrect access...Show more |
1Siemens 2Digsi 5 Engineering Software Siprotec 5 Digsi Device DriverJun 17, 2026 Jul 11, 2019 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 A vulnerability has been identified in All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respective Ethernet communication modules (All versions ), DIGSI 5 engineering software (All versions < V...Show more |
The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for local users to deploy Trojan horse code. (This also affects old 3.x releases before 3.5.) NOTE: the...Show more |
HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in information disclosure....Show more |
1Ivanti 1Landesk Management Suite Jun 17, 2026 Jun 3, 2019 N/A· v4 6.3 MEDIUM· v3 4.1 MEDIUM· v2 Open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to remote information disclosure and arbitrary code execution. |
In savePhotoFromUriToUri of ContactPhotoUtils.java in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is possible unauthorized access to files within the contact app due to a conf...Show more |
2Debian Drupal2Debian Linux DrupalNov 21, 2024 Jan 22, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous...Show more |