CWE-552— Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.— MITRE CWE catalog
535 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-552page 1 of 11
- CVE-2017-16651CRITICALCVSS 7.8EG 9.0⚠ KEV2017-11-09
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must…
- CVE-2025-11371CRITICALCVSS 7.5EG 9.0⚠ KEV2025-10-09
In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observe…
- CVE-2020-17519CRITICALCVSS 7.5EG 9.0⚠ KEV2021-01-05
A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted t…
- CVE-2016-3715CRITICALCVSS 5.5EG 9.0⚠ KEV2016-05-05
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
- CVE-2025-48928CRITICALCVSS 4.0EG 9.0⚠ KEV2025-05-28
The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wil…
- CVE-2026-71379CRITICALCVSS 10.0EG 10.02026-09-29
The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.
- CVE-2025-41240CRITICALCVSS 10.0EG 10.02025-07-24
Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document root. In affected versions, this can lead to unauthenticated access to sensitive credential…
- CVE-2024-56731CRITICALCVSS 10.0EG 10.02025-06-24
Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .git directory and achieve remote command execution due to an insufficient patch for CVE-2024-39931. Unprivileged user a…
- CVE-2024-6209CRITICALCVSS 10.0EG 10.02024-07-05
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to access files unauthorized
- CVE-2023-45160CRITICALCVSS 8.8EG 10.02023-10-05
In the affected version of the 1E Client, an ordinary user could subvert downloaded instruction resource files, e.g., to substitute a harmful script. by replacing a resource script file created by an instruction at run time with a maliciou…
- CVE-2025-14771CRITICALCVSS 9.9EG 9.92026-06-03
Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.
- CVE-2024-39931CRITICALCVSS 9.9EG 9.92024-07-04
Gogs through 0.13.0 allows deletion of internal files.
- CVE-2021-32008CRITICALCVSS 9.9EG 9.92022-03-04
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories.
- CVE-2021-43821CRITICALCVSS 9.9EG 9.92021-12-14
Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast before version 9.10 or 10.6 allows references to local file URLs in ingested media packages, allowing attackers to include local files from Opencast's ho…
- CVE-2023-5199CRITICALCVSS 8.8EG 9.92023-10-30
The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and including, 0.3 via the 'php-to-page' shortcode. This allows authenticated attackers with subscriber-level permissions o…
- CVE-2026-40624CRITICALCVSS 9.8EG 9.82026-06-19
Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated attacker to achieve arbitrary code execution via a specially crafted web request.
- CVE-2019-25709CRITICALCVSS 9.8EG 9.82026-04-12
CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deser…
- CVE-2026-33698CRITICALCVSS 9.8EG 9.82026-04-10
Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ directory and allow an unauthenticated attacker to modify existing files or create new files where…
- CVE-2026-2331CRITICALCVSS 9.8EG 9.82026-03-06
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through…
- CVE-2024-53676CRITICALCVSS 9.8EG 9.82024-11-27
A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.
- CVE-2024-0949CRITICALCVSS 9.8EG 9.82024-06-27
Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass. This issue affects Elektraweb: before v17.0.68.
- CVE-2024-4098CRITICALCVSS 9.8EG 9.82024-06-20
The Shariff Wrapper plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6.13 via the shariff3uu_fetch_sharecounts function. This allows unauthenticated attackers to include and execute arbitrary f…
- CVE-2024-5262CRITICALCVSS 9.8EG 9.82024-06-05
Files or Directories Accessible to External Parties vulnerability in smb server in ProjectDiscovery Interactsh allows remote attackers to read/write any files in the directory and subdirectories of where the victim runs interactsh-server v…
- CVE-2023-48710CRITICALCVSS 9.8EG 9.82024-04-15
iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they should have restricted access. Hopefully, there is no sensitive files stored in that folder natively, but there could be …
- CVE-2024-2056CRITICALCVSS 9.8EG 9.82024-03-05
Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service is running, running as the root user, is bound to the loopback interface, and i…
- CVE-2024-2055CRITICALCVSS 9.8EG 9.82024-03-05
The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by default, and runs as the root user.
- CVE-2023-50164CRITICALCVSS 9.8EG 9.82023-12-07
An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versio…
- CVE-2023-29931CRITICALCVSS 9.8EG 9.82023-06-22
laravel-s 3.7.35 is vulnerable to Local File Inclusion via /src/Illuminate/Laravel.php.
- CVE-2022-25299CRITICALCVSS 9.8EG 9.82022-02-18
This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder.
- CVE-2021-1361CRITICALCVSS 9.8EG 9.82021-02-24
A vulnerability in the implementation of an internal file management service for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode that are running Cisco NX-OS Software could allow an unauthenti…
- CVE-2020-10516CRITICALCVSS 9.8EG 9.82020-06-03
An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization member to escalate permissions and gain access to unauthorized repositories within an organization. This vulnerability…
- CVE-2020-12743CRITICALCVSS 9.8EG 9.82020-05-11
An issue was discovered in Gazie 7.32. A successful installation does not remove or block (or in any other way prevent use of) its own file /setup/install/setup.php, meaning that anyone can request it without authentication. This file allo…
- CVE-2019-19843CRITICALCVSS 9.8EG 9.82020-01-22
Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credential fetch via an unauthenticated HTTP request involving a symlink with /tmp and web/user/wps_tool_cache.
- CVE-2017-14942CRITICALCVSS 9.8EG 9.82017-09-30
Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg containing an admin:language=pt cookie.
- CVE-2017-10930CRITICALCVSS 9.8EG 9.82017-09-19
The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being able to download configuration files to steal information like administrator accounts and passwords.
- CVE-2023-36664CRITICALCVSS 7.8EG 9.82023-06-25
Artifex Ghostscript before 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
- CVE-2020-37082CRITICALCVSS 7.5EG 9.82026-02-03
webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database backup files without authentication. Attackers can directly access generated backup files in the companies/weberp/ direct…
- CVE-2026-8715CRITICALCVSS 9.6EG 9.62026-08-13
Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files f…
- CVE-2015-5211CRITICALCVSS 9.6EG 9.62017-05-25
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a …
- CVE-2026-73653CRITICALCVSS 9.4EG 9.42026-08-13
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept …
- CVE-2026-11841CRITICALCVSS 9.4EG 9.42026-07-28
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through…
- CVE-2026-2330CRITICALCVSS 9.4EG 9.42026-03-06
An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain directories intended for internal testing were not covered by the whitelist and are accessible w…
- CVE-2026-21589CRITICALCVSS 9.3EG 9.32026-10-05
This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability…
- CVE-2026-34361CRITICALCVSS 9.3EG 9.32026-03-31
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that makes outbound HTTP request…
- CVE-2025-34110CRITICALCVSS 9.3EG 9.32025-07-15
A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated attackers to read or write arbitrary files outside the configured FTP root directory. The flaw is due to insufficient sa…
- CVE-2026-67402CRITICALCVSS 9.2EG 9.22026-09-03
An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and …
- CVE-2024-6878CRITICALCVSS 9.2EG 9.22024-09-18
Files or Directories Accessible to External Parties vulnerability in Eliz Software Panel allows Collect Data from Common Resource Locations. This issue affects Panel: before v2.3.24.
- CVE-2026-37065CRITICALCVSS 9.1EG 9.12026-08-27
Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&action=update&remove=.
- CVE-2026-31216CRITICALCVSS 9.1EG 9.12026-05-12
The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its file management API. The DELETE /storage/{object_name:path} endpoint lacks authentication, authorization, and input validatio…
- CVE-2026-31215CRITICALCVSS 9.1EG 9.12026-05-12
The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticSearch service interface. The DELETE /{index_name}/documents endpoint lacks proper authentication and authorization controls a…
Map vulnerabilities like CWE-552 to your infrastructure
EchelonGraph correlates every CVE — across CWE-552 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →