CWE-552— Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.— MITRE CWE catalog
535 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-552page 3 of 11
- CVE-2024-27894HIGHCVSS 8.5EG 8.52024-03-12
The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referenced by a URL. The supported URL schemes include "file", "http", and "https". When a functi…
- CVE-2023-29450HIGHCVSS 8.5EG 8.52023-07-13
JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.
- CVE-2021-39316HIGHCVSS 7.5EG 8.52021-08-31
The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the `dzsap_download` action using directory traversal in the `link` parameter.
- CVE-2024-34066HIGHCVSS 8.4EG 8.42024-05-03
Pterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the node configuration or posting it accidentally somewhere, an attacker can use it to gain arbitrary file write and read a…
- CVE-2022-1117HIGHCVSS 8.4EG 8.42022-08-29
A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how glibc names the runtime linker, a build time regular expression may not correctly detect the runtime linker. The consequence is that the pattern d…
- CVE-2021-44719HIGHCVSS 8.4EG 8.42022-05-25
Docker Desktop 4.3.0 has Incorrect Access Control.
- CVE-2024-12917HIGHCVSS 8.3EG 8.32025-02-24
Files or Directories Accessible to External Parties vulnerability in Agito Computer Health4All allows Exploiting Incorrectly Configured Access Control Security Levels, Authentication Abuse. This issue affects Health4All: before 10.01.2025.
- CVE-2023-32226HIGHCVSS 8.3EG 8.32023-07-30
Sysaid - CWE-552: Files or Directories Accessible to External Parties - Authenticated users may exfiltrate files from the server via an unspecified method.
- CVE-2020-3927HIGHCVSS 8.3EG 8.32020-02-03
An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter.
- CVE-2025-7389HIGHCVSS 8.2EG 8.22026-04-14
A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-level access to the server through the adopted authority of the AdminServer process itself. The delegated authority of…
- CVE-2025-27147HIGHCVSS 8.2EG 8.22025-03-25
The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNMP), software deployment, VMWare ESX host remote inventory, and data collection (files, Windows registry, WMI). Versions…
- CVE-2024-51542HIGHCVSS 8.2EG 8.22024-12-05
Configuration Download vulnerabilities allow access to dependency configuration information. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
- CVE-2019-3622HIGHCVSS 8.2EG 8.22019-07-24
Files or Directories Accessible to External Parties in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows authenticated user to redirect DLPe log files to arbitrary locations via incorrect access control applied to …
- CVE-2026-53580HIGHCVSS 8.1EG 8.12026-08-27
Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the automatic image-download feature accepts file:// URLs in a note's img tags and reads the referenced local file with no path validation, allow…
- CVE-2026-75464HIGHCVSS 8.1EG 8.12026-08-24
OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().
- CVE-2026-63042HIGHCVSS 8.1EG 8.12026-08-20
Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the manager can create, modify and delete Data Node definitions. This issue affects Apache InLong: from 2.0.0 before 2.4.…
- CVE-2026-63040HIGHCVSS 8.1EG 8.12026-08-20
Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources. This issue affects Apache InLong: from 2…
- CVE-2025-11959HIGHCVSS 8.1EG 8.12025-11-11
Files or Directories Accessible to External Parties, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Premierturk Information Technologies Inc. Excavation Management Information System allows Footprinting,…
- CVE-2023-41566HIGHCVSS 8.1EG 8.12025-07-17
OA EKP v16 was discovered to contain an arbitrary download vulnerability via the component /ui/sys_ui_extend/sysUiExtend.do. This vulnerability allows attackers to obtain the password of the background administrator and further obtain data…
- CVE-2025-53536HIGHCVSS 8.1EG 8.12025-07-07
Roo Code is an AI-powered autonomous coding agent. Prior to 3.22.6, if the victim had "Write" auto-approved, an attacker with the ability to submit prompts to the agent could write to VS Code settings files and trigger code execution. Ther…
- CVE-2024-55214HIGHCVSS 6.5EG 8.02025-02-07
Local File Inclusion vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the file download functionality.
- CVE-2024-55213HIGHCVSS 6.5EG 8.02025-02-07
Directory Traversal vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the File Listing function.
- CVE-2025-69875HIGHCVSS 7.8EG 7.82026-02-03
A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and improper permission handling allow a low-privileged local user to restore quarantined file…
- CVE-2025-23276HIGHCVSS 7.8EG 7.82025-08-02
NVIDIA Installer for Windows contains a vulnerability where an attacker may be able to escalate privileges. A successful exploit of this vulnerability may lead to escalation of privileges, denial of service, code execution, information dis…
- CVE-2025-49797HIGHCVSS 7.8EG 7.82025-06-25
Multiple Brother driver installers for Windows contain a privilege escalation vulnerability. If exploited, an arbitrary program may be executed with the administrative privilege. As for the details of affected product names, model numbers,…
- CVE-2025-2222HIGHCVSS 7.8EG 7.82025-04-09
CWE-552: Files or Directories Accessible to External Parties vulnerability over https exists that could leak information and potential privilege escalation following man in the middle attack.
- CVE-2024-38876HIGHCVSS 7.8EG 7.82024-08-02
A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All versions), Omnivise T3000 Product Data Management (PDM) R9.2 (All versions), Omnivise T3000 R8.2 SP3 (…
- CVE-2024-3037HIGHCVSS 7.8EG 7.82024-05-14
An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting…
- CVE-2023-47202HIGHCVSS 7.8EG 7.82024-01-23
A local file inclusion vulnerability on the Trend Micro Apex One management server could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-priv…
- CVE-2023-31017HIGHCVSS 7.8EG 7.82023-11-02
NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may be able to write arbitrary data to privileged locations by using reparse points. A successful exploit of this vulnerability may lead to code execution, de…
- CVE-2022-40126HIGHCVSS 7.8EG 7.82022-09-29
A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows attackers to escalate privileges and execute arbitrary commands when Service Mode is activated.
- CVE-2022-33158HIGHCVSS 7.8EG 7.82022-07-30
Trend Micro VPN Proxy Pro version 5.2.1026 and below contains a vulnerability involving some overly permissive folders in a key directory which could allow a local attacker to obtain privilege escalation on an affected system.
- CVE-2022-24138HIGHCVSS 7.8EG 7.82022-07-06
IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramData folder, ProgramData folder has "rwx" permissions for unprivileged users. Low privilege users can use SetOpLock to w…
- CVE-2021-3717HIGHCVSS 7.8EG 7.82022-05-24
A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidenti…
- CVE-2021-22015HIGHCVSS 7.8EG 7.82021-09-23
The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administrative privilege may exploit these issues to elevate their p…
- CVE-2020-11469HIGHCVSS 7.8EG 7.82020-04-01
Zoom Client for Meetings through 4.6.8 on macOS copies runwithroot to a user-writable temporary directory during installation, which allows a local process (with the user's privileges) to obtain root access by replacing runwithroot.
- CVE-2019-13404HIGHCVSS 7.8EG 7.82019-07-08
The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for local users to deploy Trojan horse code. (This also affects old 3.x releases before 3.5.) NOTE: the vendor's position i…
- CVE-2017-15104HIGHCVSS 7.8EG 7.82017-12-18
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
- CVE-2022-27837HIGHCVSS 4.4EG 7.82022-04-11
A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Android S(12.0) allows attacker to access the file with system privilege.
- CVE-2026-77259HIGHCVSS 7.7EG 7.72026-09-22
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment opens a caller-selected server-local file without checking that the resolved path remains in…
- CVE-2026-75889HIGHCVSS 7.7EG 7.72026-08-27
Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor resources in a watched namespace to specify an arbitrary local file through bearerTokenFile. Alloy reads the file and sen…
- CVE-2026-54457HIGHCVSS 7.7EG 7.72026-07-15
TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied J…
- CVE-2026-4760HIGHCVSS 7.7EG 7.72026-03-25
From Panorama Web HMI, an attacker can gain read access to certain Web HMI server files, if he knows their paths and if these files are accessible to the Servin process execution account. * Installations based on Panorama Suite 2022-SP1…
- CVE-2024-52292HIGHCVSS 7.7EG 7.72024-11-13
Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions on system notification templates. This function accepts an absolute file path, reads the file's content, and converts it…
- CVE-2023-23366HIGHCVSS 7.7EG 7.72023-10-06
A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the contents of unexpected files and expose sensitive data via a network. We have already fi…
- CVE-2023-23365HIGHCVSS 7.7EG 7.72023-10-06
A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the contents of unexpected files and expose sensitive data via a network. We have already fi…
- CVE-2020-11642HIGHCVSS 7.7EG 7.72020-10-15
The local file inclusion vulnerability present in B&R SiteManager versions <9.2.620236042 allows authenticated users to impact availability of SiteManager instances.
- CVE-2020-11641HIGHCVSS 7.7EG 7.72020-10-15
A local file inclusion vulnerability in B&R SiteManager versions <9.2.620236042 allows authenticated users to read sensitive files from SiteManager instances.
- CVE-2020-5356HIGHCVSS 7.7EG 7.72020-07-06
Dell PowerProtect Data Manager (PPDM) versions prior to 19.4 and Dell PowerProtect X400 versions prior to 3.2 contain an improper authorization vulnerability. A remote authenticated malicious user may download any file from the affected Po…
- CVE-2024-4981HIGHCVSS 7.6EG 7.62025-05-12
A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make visible content from outside the git repo.
Map vulnerabilities like CWE-552 to your infrastructure
EchelonGraph correlates every CVE — across CWE-552 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →