CWE-552— Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.— MITRE CWE catalog
511 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-552page 3 of 11
- CVE-2021-21429MEDIUMCVSS 4.0EG 4.02021-04-27
OpenAPI Generator allows generation of API client libraries, server stubs, documentation and configuration automatically given an OpenAPI Spec. Using `File.createTempFile` in JDK will result in creating and using insecure temporary files t…
- CVE-2021-22015HIGHCVSS 7.8EG 7.82021-09-23
The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administrative privilege may exploit these issues to elevate their p…
- CVE-2021-22769MEDIUMCVSS 4.3EG 4.32021-06-11
A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an attacker is not restricted or incorrectly r…
- CVE-2021-24154MEDIUMCVSS 4.9EG 4.92021-04-05
The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd
- CVE-2021-24947MEDIUMCVSS 6.5EG 6.52022-02-07
The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any authenticated user, such as subscriber, …
- CVE-2021-25004MEDIUMCVSS 4.9EG 4.92022-02-07
The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is used for support purposes, it allows to download any file from the web server without restriction after knowing the URL …
- CVE-2021-25459MEDIUMCVSS 4.0EG 5.52021-09-09
An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZService.
- CVE-2021-25521MEDIUMCVSS 4.0EG 4.02021-12-08
Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet.
- CVE-2021-25741HIGHCVSS 8.8EG 8.82021-09-20
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.
- CVE-2021-29024HIGHCVSS 7.5EG 7.52021-05-17
In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.
- CVE-2021-29969MEDIUMCVSS 5.9EG 5.92021-08-05
If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS handshake, then Thunderbird didn't ignore the injected data. This could have resul…
- CVE-2021-31600MEDIUMCVSS 4.3EG 4.32021-11-08
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An…
- CVE-2021-31831MEDIUMCVSS 4.9EG 5.52021-06-03
Incorrect access to deleted scripts vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to gain access to signed SQL scripts which have been marked as deleted or expired within the admini…
- CVE-2021-31850MEDIUMCVSS 6.1EG 6.12021-12-08
A denial-of-service vulnerability in Database Security (DBS) prior to 4.8.4 allows a remote authenticated administrator to trigger a denial-of-service attack against the DBS server. The configuration of Archiving through the User interface…
- CVE-2021-32008CRITICALCVSS 9.9EG 9.92022-03-04
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories.
- CVE-2021-32688HIGHCVSS 8.8EG 8.82021-07-12
Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes. These tokens are supposed to be granted to a specific applications (e.g. DAV sync clients…
- CVE-2021-32752HIGHCVSS 7.2EG 7.22021-07-09
Ether Logs is a package that allows one to check one's logs in the Craft 3 utilities section. A vulnerability was found in versions prior to 3.0.4 that allowed authenticated admin users to access any file on the server. The vulnerability h…
- CVE-2021-32833HIGHCVSS 8.6EG 8.62021-09-09
Emby Server is a personal media server with apps on many devices. In Emby Server on Windows there is a set of arbitrary file read vulnerabilities. This vulnerability is known to exist in version 4.6.4.0 and may not be patched in later vers…
- CVE-2021-33359HIGHCVSS 7.5EG 7.52021-06-09
A vulnerability exists in gowitness < 2.3.6 that allows an unauthenticated attacker to perform an arbitrary file read using the file:// scheme in the url parameter to get an image of any file.
- CVE-2021-33843MEDIUMCVSS 5.3EG 5.32022-01-21
Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An attacker may use this functionality to change the exposed configuration values such as network settings.
- CVE-2021-34765MEDIUMCVSS 4.3EG 4.32021-09-02
A vulnerability in the web UI for Cisco Nexus Insights could allow an authenticated, remote attacker to view and download files related to the web application. The attacker requires valid device credentials. This vulnerability exists becau…
- CVE-2021-35203MEDIUMCVSS 5.7EG 5.72021-09-30
NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Arbitrary File Read operations via the FDSQueryService endpoint.
- CVE-2021-36233MEDIUMCVSS 6.5EG 6.52021-08-31
The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary files from the filesystem by specifying the file path.
- CVE-2021-36276HIGHCVSS 8.8EG 8.82021-08-09
Dell DBUtilDrv2.sys driver (versions 2.5 and 2.6) contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.
- CVE-2021-36763HIGHCVSS 7.5EG 7.52021-08-03
In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.
- CVE-2021-3717HIGHCVSS 7.8EG 7.82022-05-24
A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidenti…
- CVE-2021-37348HIGHCVSS 7.5EG 7.52021-08-13
Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation of a pathname in index.php.
- CVE-2021-3800HIGHCVSS 5.5EG 7.52022-08-23
A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivileged ones under the right condition.
- CVE-2021-3856MEDIUMCVSS 4.3EG 4.32022-08-26
ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, the client will recei…
- CVE-2021-38711HIGHCVSS 7.5EG 7.52021-08-16
In gitit before 0.15.0.0, the Export feature can be exploited to leak information from files.
- CVE-2021-39316HIGHCVSS 7.5EG 8.52021-08-31
The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the `dzsap_download` action using directory traversal in the `link` parameter.
- CVE-2021-3995MEDIUMCVSS 5.5EG 5.52022-08-23
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local attacker to unmount FUSE filesystems that belong to certain…
- CVE-2021-3996MEDIUMCVSS 5.5EG 5.52022-08-23
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are …
- CVE-2021-40149MEDIUMCVSS 5.9EG 5.92022-07-17
The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the /self.key URI.
- CVE-2021-40150HIGHCVSS 7.5EG 7.52022-07-17
The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. In this way an attacker can download the entire NGINX/FastCGI configurations by query…
- CVE-2021-4112HIGHCVSS 8.8EG 8.82022-08-25
A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment.
- CVE-2021-41573HIGHCVSS 7.5EG 7.52021-09-29
Hitachi Content Platform Anywhere (HCP-AW) 4.4.5 and later allows information disclosure. If authenticated user creates a link to a file or folder while the system was running version 4.3.x or earlier and then shares the link and then late…
- CVE-2021-42644MEDIUMCVSS 6.5EG 6.52022-05-17
cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_database) can be read through this vulnera…
- CVE-2021-42744MEDIUMCVSS 5.5EG 5.52021-11-19
Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
- CVE-2021-43772MEDIUMCVSS 5.5EG 5.52021-12-03
Trend Micro Security 2021 v17.0 (Consumer) contains a vulnerability that allows files inside the protected folder to be modified without any detection.
- CVE-2021-43821CRITICALCVSS 9.9EG 9.92021-12-14
Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast before version 9.10 or 10.6 allows references to local file URLs in ingested media packages, allowing attackers to include local files from Opencast's ho…
- CVE-2021-44315HIGHCVSS 7.5EG 7.52021-12-16
In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to view the sensitive files of the application, for example: Any file which contains sensitive information of the user or …
- CVE-2021-4463HIGHCVSS 8.7EG 8.72025-11-12
Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulnerability in the 'downloads' endpoint. The 'fileName' parameter is not properly sanitized, allowing attackers to craft t…
- CVE-2021-44719HIGHCVSS 8.4EG 8.42022-05-25
Docker Desktop 4.3.0 has Incorrect Access Control.
- CVE-2021-4474MEDIUMCVSS 4.9EG 4.92026-03-26
Ruckus Access Point products contain an arbitrary file read vulnerability in the command-line interface that allows authenticated remote attackers with administrative privileges to read arbitrary files from the underlying filesystem. Attac…
- CVE-2021-44983MEDIUMCVSS 4.9EG 4.92022-02-04
In taocms 3.0.1 after logging in to the background, there is an Arbitrary file download vulnerability at the File Management column.
- CVE-2021-47960MEDIUMCVSS 6.5EG 6.52026-04-10
A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interf…
- CVE-2022-0244HIGHCVSS 8.6EG 8.62022-01-18
An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.
- CVE-2022-0656HIGHCVSS 7.5EG 7.52022-04-25
The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url_to_base64 AJAX action (available to both unauthenticated and authenticated users) before using it in the file_get_cont…
- CVE-2022-1117HIGHCVSS 8.4EG 8.42022-08-29
A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how glibc names the runtime linker, a build time regular expression may not correctly detect the runtime linker. The consequence is that the pattern d…
Map vulnerabilities like CWE-552 to your infrastructure
EchelonGraph correlates every CVE — across CWE-552 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →