CWE-552— Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.— MITRE CWE catalog
511 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-552page 4 of 11
- CVE-2022-1585HIGHCVSS 7.5EG 7.52022-08-01
The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download functionalities, which may allow any visitors on the site to download the entire site, including sensitive files like wp-co…
- CVE-2022-21236HIGHCVSS 7.5EG 7.52022-01-28
An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HT…
- CVE-2022-2222MEDIUMCVSS 4.9EG 4.92022-07-17
The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even i…
- CVE-2022-22267MEDIUMCVSS 4.0EG 4.02022-01-10
Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running application information.
- CVE-2022-22268MEDIUMCVSS 6.1EG 6.12022-01-10
Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox Guard via Samsung DeX mode.
- CVE-2022-22269MEDIUMCVSS 4.0EG 4.02022-01-10
Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applications to get a local Bluetooth MAC address.
- CVE-2022-22270MEDIUMCVSS 4.4EG 4.42022-01-10
An implicit Intent hijacking vulnerability in Dialer prior to SMR Jan-2022 Release 1 allows unprivileged applications to access contact information.
- CVE-2022-22490MEDIUMCVSS 4.9EG 4.92022-08-10
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information. IBM X-Force ID: 226342.
- CVE-2022-23316MEDIUMCVSS 4.9EG 4.92022-02-04
An issue was discovered in taoCMS v3.0.2. There is an arbitrary file read vulnerability that can read any files via admin.php?action=file&ctrl=download&path=../../1.txt.
- CVE-2022-23377HIGHCVSS 7.5EG 7.52022-03-01
Archeevo below 5.0 is affected by local file inclusion through file=~/web.config to allow an attacker to retrieve local files.
- CVE-2022-23508HIGHCVSS 8.8EG 8.82023-01-09
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in GitOps run could allow a local user or process to alter a Kubernetes cluster's…
- CVE-2022-2357HIGHCVSS 7.5EG 7.52022-08-08
The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file download feature to download any local files, including sensitive ones like wp-config.php.
- CVE-2022-23621MEDIUMCVSS 5.5EG 5.52022-02-09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT right can read any file located in the XWiki WAR (for example xwiki.cfg and xwiki.properties…
- CVE-2022-23738MEDIUMCVSS 5.7EG 5.72022-11-01
An improper cache key vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to access private repository files through a public repository. To exploit this, an actor would need to already be authorized…
- CVE-2022-2392MEDIUMCVSS 6.5EG 6.52022-08-22
The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that can be exploited by users with "Contributor" permissions or higher.
- CVE-2022-24075MEDIUMCVSS 6.5EG 6.52022-03-17
Whale browser before 3.12.129.18 allowed extensions to replace JavaScript files of the HWP viewer website which could access to local HWP files. When the HWP files were opened, the replaced script could read the files.
- CVE-2022-24138HIGHCVSS 7.8EG 7.82022-07-06
IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramData folder, ProgramData folder has "rwx" permissions for unprivileged users. Low privilege users can use SetOpLock to w…
- CVE-2022-24694MEDIUMCVSS 4.3EG 4.32022-02-09
In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1, the names of folders in the Files area can be seen by a person not owning the folders. (Only folder names are affected. Neither file names nor file contents ar…
- CVE-2022-25104HIGHCVSS 7.5EG 7.52022-02-24
HorizontCMS v1.0.0-beta.2 was discovered to contain an arbitrary file download vulnerability via the component /admin/file-manager/.
- CVE-2022-25297HIGHCVSS 7.5EG 7.52022-02-21
This affects the package drogonframework/drogon before 1.7.5. The unsafe handling of file names during upload using HttpFile::save() method may enable attackers to write files to arbitrary locations outside the designated target folder.
- CVE-2022-25299CRITICALCVSS 9.8EG 9.82022-02-18
This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder.
- CVE-2022-25497MEDIUMCVSS 5.3EG 5.32022-03-15
CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.
- CVE-2022-26271HIGHCVSS 7.5EG 7.52022-03-28
74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php.
- CVE-2022-26877MEDIUMCVSS 6.5EG 6.52022-04-09
Asana Desktop before 1.6.0 allows remote attackers to exfiltrate local files if they can trick the Asana desktop app into loading a malicious web page.
- CVE-2022-27837HIGHCVSS 4.4EG 7.82022-04-11
A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Android S(12.0) allows attacker to access the file with system privilege.
- CVE-2022-28002HIGHCVSS 7.5EG 7.52022-04-08
Movie Seat Reservation v1 was discovered to contain an unauthenticated file disclosure vulnerability via /index.php?page=home.
- CVE-2022-28283MEDIUMCVSS 6.5EG 6.52022-12-22
The sourceMapURL feature in devtools was missing security checks that would have allowed a webpage to attempt to include local files or other files that should have been inaccessible. This vulnerability affects Firefox < 99.
- CVE-2022-2834MEDIUMCVSS 5.3EG 5.32022-10-17
The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Em…
- CVE-2022-28445MEDIUMCVSS 6.5EG 6.52022-04-21
KiteCMS v1.1.1 was discovered to contain an arbitrary file read vulnerability via the background management module.
- CVE-2022-28462HIGHCVSS 7.5EG 7.52022-05-05
novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.
- CVE-2022-29302MEDIUMCVSS 5.5EG 5.52022-05-12
SolarView Compact ver.6.00 was discovered to contain a local file disclosure via /html/Solar_Ftp.php.
- CVE-2022-29446HIGHCVSS 6.8EG 7.22022-05-19
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugin <= 1.1.1 at WordPress.
- CVE-2022-29447HIGHCVSS 6.8EG 7.22022-05-20
Authenticated (administrator or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Hover Effects plugin <= 2.1 at WordPress.
- CVE-2022-29720HIGHCVSS 7.5EG 7.52022-05-26
74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Download.php.
- CVE-2022-2981MEDIUMCVSS 4.9EG 4.92022-10-10
The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even i…
- CVE-2022-30428HIGHCVSS 7.5EG 7.52022-05-25
In ginadmin through 05-10-2022, the incoming path value is not filtered, resulting in arbitrary file reading.
- CVE-2022-31475MEDIUMCVSS 5.5EG 5.52022-07-21
Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.
- CVE-2022-32143HIGHCVSS 8.8EG 8.82022-06-24
In multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the PLC. All requests are processed on the controller only if no level 1 password is configured…
- CVE-2022-3287MEDIUMCVSS 6.5EG 6.52022-09-28
When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.
- CVE-2022-33158HIGHCVSS 7.8EG 7.82022-07-30
Trend Micro VPN Proxy Pro version 5.2.1026 and below contains a vulnerability involving some overly permissive folders in a key directory which could allow a local attacker to obtain privilege escalation on an affected system.
- CVE-2022-33686LOWCVSS 2.3EG 2.32022-07-12
Exposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.
- CVE-2022-33901HIGHCVSS 5.3EG 7.52022-07-22
Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin <= 4.13.1 at WordPress.
- CVE-2022-34049MEDIUMCVSS 5.3EG 5.32022-07-20
An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.
- CVE-2022-34464MEDIUMCVSS 6.3EG 6.32022-07-12
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.7.3). The affected application uses an improperly protected file to import SSH keys. This could allow attackers with access to the filesystem of the host on…
- CVE-2022-35235MEDIUMCVSS 4.9EG 4.92022-08-23
Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.
- CVE-2022-36306MEDIUMCVSS 6.5EG 6.52022-08-16
An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web server binary, and the web server configuration file. These vulnerabilities were found in AirVelocity…
- CVE-2022-36552HIGHCVSS 7.5EG 7.52022-08-30
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which allows attackers to steal all data such as source code and system files via a crafted GET request.
- CVE-2022-3691HIGHCVSS 7.5EG 7.52022-11-21
The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor.
- CVE-2022-37424MEDIUMCVSS 6.5EG 6.52022-10-28
Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery.
- CVE-2022-39208HIGHCVSS 7.5EG 7.52022-09-13
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. All files in the /opt/onedev/sites/ directory are exposed and can be read by unauthenticated users. This directory contains all projects, including their bare git repo…
Map vulnerabilities like CWE-552 to your infrastructure
EchelonGraph correlates every CVE — across CWE-552 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →