← Back
CWE-552

506 CVEs • Abstraction: Base

Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

JSON object

Loading...

CVEs (506)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Daeja Viewone
May 13, 2026
Jul 13, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0 could allow an authenticated attacker to download files they should not have access to due to improper access controls. IBM X-Force ID: 125462.
2Debian
Vmware
2Debian Linux
Spring Framework
May 13, 2026
May 25, 2017
N/A· v4
9.6 CRITICAL· v3
9.3 HIGH· v2
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user cra...Show more
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.Show less
6Canonical
ImagemagickOpensuse+3 more
30Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux For Ibm Z Systems+27 more
Apr 22, 2026
May 5, 2016
N/A· v4
5.5 MEDIUM· v3
5.8 MEDIUM· v2
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
2Linux
Redhat
3Enterprise Linux
Enterprise MrgLinux Kernel
May 6, 2026
May 2, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of servic...Show more
The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a failed invocation of a system call, as demonstrated by using chown to remove a capability from the ping or Wireshark dumpcap program.Show less
1Digitaldesign Cms Project
1Digitaldesign Cms
Apr 23, 2026
Oct 8, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Digitaldesign CMS 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for autoconfig.dd.
1Nextweb
1Nextweb (i)site
Apr 16, 2026
Jun 1, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
NEXTWEB (i)Site stores databases under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to databases/Users.mdb.