CWE-552— Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.— MITRE CWE catalog
536 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-552page 11 of 11
- CVE-2024-13126MEDIUMCVSS 4.6EG 4.62025-03-16
The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.
- CVE-2020-1908MEDIUMCVSS 4.6EG 4.62020-11-03
Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could have permitted use of Siri to interact with the WhatsApp application even after the phone was locked.
- CVE-2024-3164MEDIUMCVSS 4.5EG 4.52024-04-01
In dotCMS dashboard, the Tools and Log Files tabs under System → Maintenance Portlet, which is and always has been an Admin portlet, is accessible to anyone with that portlet and not just to CMS Admins. Users that get site admin but not …
- CVE-2024-41699MEDIUMCVSS 4.4EG 4.42024-08-20
Priority – CWE-552: Files or Directories Accessible to External Parties
- CVE-2024-35183MEDIUMCVSS 4.4EG 4.42024-05-15
wolfictl is a command line tool for working with Wolfi. A git authentication issue in versions prior to 0.16.10 allows a local user’s GitHub token to be sent to remote servers other than `github.com`. Most git-dependent functionality in …
- CVE-2022-45440MEDIUMCVSS 4.4EG 4.42023-01-17
A vulnerability exists in the FTP server of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0, which processes symbolic links on external storage media. A local authenticated attacker with administrator privileges could abuse this vuln…
- CVE-2022-22270MEDIUMCVSS 4.4EG 4.42022-01-10
An implicit Intent hijacking vulnerability in Dialer prior to SMR Jan-2022 Release 1 allows unprivileged applications to access contact information.
- CVE-2021-1434MEDIUMCVSS 4.4EG 4.42021-03-24
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying file system. This vulnerability is due to insufficient validation of the parameters of a…
- CVE-2025-9273MEDIUMCVSS 4.3EG 4.32025-09-02
CData API Server MySQL Misconfiguration Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of CData API Server. Authentication is required to exploit…
- CVE-2024-10126MEDIUMCVSS 4.3EG 4.32024-11-20
Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7) allows an authenticated user to read server local files of a limited set of filetypes via document preview.
- CVE-2024-29225MEDIUMCVSS 4.3EG 4.32024-04-04
ELECOM wireless LAN routers allow a network-adjacent unauthenticated attacker to obtain the configuration file containing sensitive information by sending a specially crafted request.
- CVE-2021-3856MEDIUMCVSS 4.3EG 4.32022-08-26
ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, the client will recei…
- CVE-2022-24694MEDIUMCVSS 4.3EG 4.32022-02-09
In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1, the names of folders in the Files area can be seen by a person not owning the folders. (Only folder names are affected. Neither file names nor file contents ar…
- CVE-2021-20148MEDIUMCVSS 4.3EG 4.32022-01-03
ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web root with a predictable filename based on the domain name. When ADSSP is configured with multiple Windows domains, a user …
- CVE-2021-31600MEDIUMCVSS 4.3EG 4.32021-11-08
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An…
- CVE-2021-34765MEDIUMCVSS 4.3EG 4.32021-09-02
A vulnerability in the web UI for Cisco Nexus Insights could allow an authenticated, remote attacker to view and download files related to the web application. The attacker requires valid device credentials. This vulnerability exists becau…
- CVE-2021-22769MEDIUMCVSS 4.3EG 4.32021-06-11
A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an attacker is not restricted or incorrectly r…
- CVE-2019-7306MEDIUMCVSS 4.3EG 4.32020-04-17
Byobu Apport hook may disclose sensitive information since it automatically uploads the local user's .screenrc which may contain private hostnames, usernames and passwords. This issue affects: byobu
- CVE-2019-17112MEDIUMCVSS 4.3EG 4.32019-10-09
An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user ("Operator" access level) to access the configuration file of the mail server (except for the password).
- CVE-2017-1602MEDIUMCVSS 4.3EG 4.32018-03-23
IBM RSA DM (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to access settings that they should not be able to using a specially crafted URL. IBM X-Force ID: 132625.
- CVE-2025-4634MEDIUMCVSS 4.1EG 4.12025-05-30
The web portal on airpointer 2.4.107-2 was vulnerable local file inclusion. A malicious user with administrative privileges in the web portal would be able to manipulate requests to view files on the filesystem
- CVE-2022-22269MEDIUMCVSS 4.0EG 4.02022-01-10
Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applications to get a local Bluetooth MAC address.
- CVE-2022-22267MEDIUMCVSS 4.0EG 4.02022-01-10
Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running application information.
- CVE-2021-25521MEDIUMCVSS 4.0EG 4.02021-12-08
Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet.
- CVE-2021-21429MEDIUMCVSS 4.0EG 4.02021-04-27
OpenAPI Generator allows generation of API client libraries, server stubs, documentation and configuration automatically given an OpenAPI Spec. Using `File.createTempFile` in JDK will result in creating and using insecure temporary files t…
- CVE-2026-14849LOWCVSS 3.7EG 3.72026-07-31
The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the uploads directory, allowing unauthenticated users to download the exported mem…
- CVE-2025-15153LOWCVSS 3.7EG 3.72025-12-28
A weakness has been identified in PbootCMS up to 3.2.12. Impacted is an unknown function of the file /data/pbootcms.db of the component SQLite Database. Executing a manipulation can lead to files or directories accessible. It is possible t…
- CVE-2025-14697LOWCVSS 3.7EG 3.72025-12-15
A security flaw has been discovered in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Affected by this issue is some unknown functionality of the file /ExportFiles/. The manipulation results in files or …
- CVE-2024-48838LOWCVSS 3.3EG 3.32024-11-12
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a Files or Directories Accessible to External Parties vulnerability. A low privileged attacker with local access could potentially exploit this v…
- CVE-2022-42834LOWCVSS 3.3EG 3.32023-06-23
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13, macOS Big Sur 11.7.3. An app may be able to access mail folder attachments through a temporary directory used …
- CVE-2019-4398LOWCVSS 3.3EG 3.32019-10-24
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 could allow a local user to obtain sensitive information from SessionManagement cookies. IBM X-Force ID: 162259.
- CVE-2018-0106LOWCVSS 3.3EG 3.32018-01-18
A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an unauthenticated, local attacker to access sensitive information on a targeted system. The vulnerability is due to insufficient security restr…
- CVE-2023-32684LOWCVSS 2.7EG 2.72023-05-30
Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to version 0.16.0, a virtual machine instance with a malicious disk image could read a single file on the host filesystem, even when no filesystem is m…
- CVE-2019-19018LOWCVSS 2.7EG 2.72019-12-02
An issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfig.ini in the web administration interface, revealing what database the web application is using.
- CVE-2022-33686LOWCVSS 2.3EG 2.32022-07-12
Exposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.
- CVE-2024-2364LOWCVSS 1.8EG 1.82024-03-10
A vulnerability classified as problematic has been found in Musicshelf 1.0/1.1 on Android. Affected is an unknown function of the file androidmanifest.xml of the component Backup Handler. The manipulation leads to exposure of backup file t…
Map vulnerabilities like CWE-552 to your infrastructure
EchelonGraph correlates every CVE — across CWE-552 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →