CWE-552— Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.— MITRE CWE catalog
511 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-552page 2 of 11
- CVE-2019-25709CRITICALCVSS 9.8EG 9.82026-04-12
CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deser…
- CVE-2019-3569HIGHCVSS 7.5EG 7.52019-06-26
HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in information disclosure. This issue affects…
- CVE-2019-3622HIGHCVSS 8.2EG 8.22019-07-24
Files or Directories Accessible to External Parties in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows authenticated user to redirect DLPe log files to arbitrary locations via incorrect access control applied to …
- CVE-2019-3811MEDIUMCVSS 5.2EG 5.22019-01-15
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's fi…
- CVE-2019-3897MEDIUMCVSS 5.3EG 5.32021-03-16
It has been discovered in redhat-certification that any unauthorized user may download any file under /var/www/rhcert, provided they know its name. Red Hat Certification 6 and 7 is vulnerable to this issue.
- CVE-2019-4398LOWCVSS 3.3EG 3.32019-10-24
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 could allow a local user to obtain sensitive information from SessionManagement cookies. IBM X-Force ID: 162259.
- CVE-2019-7305MEDIUMCVSS 5.8EG 5.82020-04-10
Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible over HTTP. Introduced in the Makefile patch file debian/patches/debian-changes-2.1.0b6+dfsg-1 or debian/patches/adds-a-…
- CVE-2019-7306MEDIUMCVSS 4.3EG 4.32020-04-17
Byobu Apport hook may disclose sensitive information since it automatically uploads the local user's .screenrc which may contain private hostnames, usernames and passwords. This issue affects: byobu
- CVE-2020-10105MEDIUMCVSS 5.3EG 5.32020-03-05
An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS request, rather than a GET request. Disclosure of source code allows for an attacker to formulate more precise attacks…
- CVE-2020-10516CRITICALCVSS 9.8EG 9.82020-06-03
An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization member to escalate permissions and gain access to unauthorized repositories within an organization. This vulnerability…
- CVE-2020-11469HIGHCVSS 7.8EG 7.82020-04-01
Zoom Client for Meetings through 4.6.8 on macOS copies runwithroot to a user-writable temporary directory during installation, which allows a local process (with the user's privileges) to obtain root access by replacing runwithroot.
- CVE-2020-11641HIGHCVSS 7.7EG 7.72020-10-15
A local file inclusion vulnerability in B&R SiteManager versions <9.2.620236042 allows authenticated users to read sensitive files from SiteManager instances.
- CVE-2020-11642HIGHCVSS 7.7EG 7.72020-10-15
The local file inclusion vulnerability present in B&R SiteManager versions <9.2.620236042 allows authenticated users to impact availability of SiteManager instances.
- CVE-2020-11976HIGHCVSS 7.5EG 7.52020-08-11
By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Ap…
- CVE-2020-12470HIGHCVSS 7.2EG 7.22020-04-29
MonoX through 5.1.40.5152 allows administrators to execute arbitrary code by modifying an ASPX template.
- CVE-2020-12743CRITICALCVSS 9.8EG 9.82020-05-11
An issue was discovered in Gazie 7.32. A successful installation does not remove or block (or in any other way prevent use of) its own file /setup/install/setup.php, meaning that anyone can request it without authentication. This file allo…
- CVE-2020-13953MEDIUMCVSS 5.3EG 5.32020-09-30
In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.
- CVE-2020-15175HIGHCVSS 7.4EG 8.62020-10-07
In GLPI before version 9.5.2, the `pluginimage.send.php` endpoint allows a user to specify an image from a plugin. The parameters can be maliciously crafted to instead delete the .htaccess file for the files directory. Any user becom…
- CVE-2020-15224MEDIUMCVSS 6.8EG 6.82020-10-14
In Open Enclave before version 0.12.0, an information disclosure vulnerability exists when an enclave application using the syscalls provided by the sockets.edl is loaded by a malicious host application. An attacker who successfully exploi…
- CVE-2020-1726MEDIUMCVSS 5.9EG 5.92020-02-11
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious i…
- CVE-2020-17519CRITICALCVSS 7.5EG 9.0⚠ KEV2021-01-05
A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted t…
- CVE-2020-1908MEDIUMCVSS 4.6EG 4.62020-11-03
Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could have permitted use of Siri to interact with the WhatsApp application even after the phone was locked.
- CVE-2020-22124HIGHCVSS 7.5EG 7.52021-08-18
A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information.
- CVE-2020-24312HIGHCVSS 7.5EG 7.52020-08-26
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes…
- CVE-2020-25351MEDIUMCVSS 6.5EG 6.52021-08-20
An information disclosure vulnerability in rConfig 3.9.5 has been fixed for version 3.9.6. This vulnerability allowed remote authenticated attackers to read files on the system via a crafted request sent to to the /lib/crud/configcompare.c…
- CVE-2020-25636MEDIUMCVSS 6.6EG 6.62020-10-05
A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers. Files are written directly to the root bucket, making possible to have collisions when running multiple ansib…
- CVE-2020-26182MEDIUMCVSS 6.8EG 6.82020-10-16
Dell EMC NetWorker versions prior to 19.3.0.2 contain an incorrect privilege assignment vulnerability. A non-LDAP remote user with low privileges may exploit this vulnerability to perform 'saveset' related operations in an unintended manne…
- CVE-2020-26183MEDIUMCVSS 6.8EG 6.82020-10-16
Dell EMC NetWorker versions prior to 19.3.0.2 contain an improper authorization vulnerability. Certain remote users with low privileges may exploit this vulnerability to perform 'nsrmmdbd' operations in an unintended manner.
- CVE-2020-26549HIGHCVSS 7.5EG 7.52020-11-17
An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests to directories can be bypassed for file downloading.
- CVE-2020-27368MEDIUMCVSS 5.5EG 5.52021-01-14
Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /icons/ directories via GET Parameter.
- CVE-2020-3267HIGHCVSS 7.1EG 7.12020-06-03
A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to change the availability state of any agent. The vulnerability is due to insufficient authorization …
- CVE-2020-3476MEDIUMCVSS 6.0EG 6.02020-09-24
A vulnerability in the CLI implementation of a specific command of Cisco IOS XE Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying host file system. The vulnerability is due to insufficient…
- CVE-2020-35340HIGHCVSS 7.5EG 7.52021-09-15
A local file inclusion vulnerability in ExpertPDF 9.5.0 through 14.1.0 allows attackers to read the file contents from files that the running ExpertPDF process has access to read.
- CVE-2020-35658MEDIUMCVSS 5.3EG 5.32020-12-23
SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted.
- CVE-2020-37082CRITICALCVSS 7.5EG 9.82026-02-03
webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database backup files without authentication. Attackers can directly access generated backup files in the companies/weberp/ direct…
- CVE-2020-3926HIGHCVSS 6.1EG 7.52020-02-03
An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter.
- CVE-2020-3927HIGHCVSS 8.3EG 8.32020-02-03
An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter.
- CVE-2020-4075MEDIUMCVSS 6.8EG 6.82020-07-07
In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, arbitrary local file read is possible by defining unsafe window options on a child window opened via window.open. As a workaround, ensure you are calling `event.preventDefault()` …
- CVE-2020-5250HIGHCVSS 7.6EG 7.62020-03-05
In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the form, and thus steal someone else's address. It is the same with CustomerForm, you are able to change the id_customer a…
- CVE-2020-5289MEDIUMCVSS 6.8EG 6.82020-03-30
In Elide before 4.5.14, it is possible for an adversary to "guess and check" the value of a model field they do not have access to assuming they can read at least one other field in the model. The adversary can construct filter expressions…
- CVE-2020-5356HIGHCVSS 7.7EG 7.72020-07-06
Dell PowerProtect Data Manager (PPDM) versions prior to 19.4 and Dell PowerProtect X400 versions prior to 3.2 contain an improper authorization vulnerability. A remote authenticated malicious user may download any file from the affected Po…
- CVE-2020-7241HIGHCVSS 7.5EG 7.52020-01-20
The WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory wp-content/uploads/db-backup/. This might allow attackers to read ZIP archives by guessing random ID numbers, guessing date string…
- CVE-2021-1256MEDIUMCVSS 6.0EG 6.02021-04-29
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite files on the file system of an affected device by using directory traversal techniques. A successful expl…
- CVE-2021-1361CRITICALCVSS 9.8EG 9.82021-02-24
A vulnerability in the implementation of an internal file management service for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode that are running Cisco NX-OS Software could allow an unauthenti…
- CVE-2021-1434MEDIUMCVSS 4.4EG 4.42021-03-24
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying file system. This vulnerability is due to insufficient validation of the parameters of a…
- CVE-2021-1512MEDIUMCVSS 6.0EG 6.02021-05-06
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying file system of an affected system. This vulnerability is due to insufficient validation of the …
- CVE-2021-20148MEDIUMCVSS 4.3EG 4.32022-01-03
ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web root with a predictable filename based on the domain name. When ADSSP is configured with multiple Windows domains, a user …
- CVE-2021-20182HIGHCVSS 8.8EG 8.82021-02-23
A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs with high privileges using a chrooted environment instead of runc. If an attacker can gain access to this build container, they can potentiall…
- CVE-2021-20253MEDIUMCVSS 6.7EG 6.72021-03-09
A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker to elevate the privilege from a low privileged user to the awx user from outside the isolated environment. The highest t…
- CVE-2021-21355HIGHCVSS 8.6EG 8.62021-03-23
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1, due to the lack of ensuring file extensions belong to configured allowed mime-types, attackers can upload arbitrary …
Map vulnerabilities like CWE-552 to your infrastructure
EchelonGraph correlates every CVE — across CWE-552 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →