CWE-552— Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.— MITRE CWE catalog
535 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-552page 5 of 11
- CVE-2023-31064HIGHCVSS 7.5EG 7.52023-05-22
Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. the user in InLong could cancel an application that doesn't belongs …
- CVE-2022-45450HIGHCVSS 7.5EG 7.52023-05-18
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 28610, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 3…
- CVE-2023-2180HIGHCVSS 7.5EG 7.52023-05-15
The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unseria…
- CVE-2023-27180HIGHCVSS 7.5EG 7.52023-04-07
GDidees CMS v3.9.1 was discovered to contain a source code disclosure vulnerability by the backup feature which is accessible via /_admin/backup.php.
- CVE-2023-28375HIGHCVSS 7.5EG 7.52023-03-28
Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated file disclosure. Using a GET parameter, attackers can disclose arbitrary files on the affected device and disclose sensitive and system information.
- CVE-2023-25260HIGHCVSS 7.5EG 7.52023-03-28
Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.
- CVE-2023-23330HIGHCVSS 7.5EG 7.52023-03-28
amano Xparc parking solutions 7.1.3879 was discovered to be vulnerable to local file inclusion.
- CVE-2023-1246HIGHCVSS 7.5EG 7.52023-03-10
Files or Directories Accessible to External Parties vulnerability in Saysis Starcities allows Collect Data from Common Resource Locations. This issue affects Starcities: through 1.3.
- CVE-2023-26948HIGHCVSS 7.5EG 7.52023-03-09
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/file/download.
- CVE-2023-26956HIGHCVSS 7.5EG 7.52023-03-08
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/curd/code.
- CVE-2023-0331HIGHCVSS 7.5EG 7.52023-02-27
The Correos Oficial WordPress plugin through 1.2.0.2 does not have an authorization check user input validation when generating a file path, allowing unauthenticated attackers to download arbitrary files from the server.
- CVE-2023-22974HIGHCVSS 7.5EG 7.52023-02-22
A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controlling a connection to an attacker-controlled MySQL server.
- CVE-2022-44343HIGHCVSS 7.5EG 7.52023-02-06
CRMEB 4.4.4 is vulnerable to Any File download.
- CVE-2022-48161HIGHCVSS 7.5EG 7.52023-02-01
Easy Images v2.0 was discovered to contain an arbitrary file download vulnerability via the component /application/down.php. This vulnerability is exploited via a crafted GET request.
- CVE-2022-4140HIGHCVSS 7.5EG 7.52023-01-02
The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file, which could allow unauthenticated attacker to read arbitrary files on the server
- CVE-2022-4106HIGHCVSS 7.5EG 7.52022-12-19
The Wholesale Market for WooCommerce WordPress plugin before 1.0.7 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from …
- CVE-2022-45227HIGHCVSS 7.5EG 7.52022-12-12
The web portal of Dragino Lora LG01 18ed40 IoT v4.3.4 has the directory listing at the URL https://10.10.20.74/lib/. This address has a backup file which can be downloaded without any authentication.
- CVE-2022-44356HIGHCVSS 7.5EG 7.52022-11-29
WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data and log files.
- CVE-2022-3691HIGHCVSS 7.5EG 7.52022-11-21
The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor.
- CVE-2022-44583HIGHCVSS 7.5EG 7.52022-11-18
Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.
- CVE-2022-45129HIGHCVSS 7.5EG 7.52022-11-10
Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, an…
- CVE-2022-41343HIGHCVSS 7.5EG 7.52022-09-25
registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demonstrated by a @font-face rule.
- CVE-2022-39208HIGHCVSS 7.5EG 7.52022-09-13
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. All files in the /opt/onedev/sites/ directory are exposed and can be read by unauthenticated users. This directory contains all projects, including their bare git repo…
- CVE-2022-36552HIGHCVSS 7.5EG 7.52022-08-30
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which allows attackers to steal all data such as source code and system files via a crafted GET request.
- CVE-2022-2357HIGHCVSS 7.5EG 7.52022-08-08
The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file download feature to download any local files, including sensitive ones like wp-config.php.
- CVE-2022-1585HIGHCVSS 7.5EG 7.52022-08-01
The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download functionalities, which may allow any visitors on the site to download the entire site, including sensitive files like wp-co…
- CVE-2021-40150HIGHCVSS 7.5EG 7.52022-07-17
The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. In this way an attacker can download the entire NGINX/FastCGI configurations by query…
- CVE-2022-29720HIGHCVSS 7.5EG 7.52022-05-26
74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Download.php.
- CVE-2022-30428HIGHCVSS 7.5EG 7.52022-05-25
In ginadmin through 05-10-2022, the incoming path value is not filtered, resulting in arbitrary file reading.
- CVE-2022-28462HIGHCVSS 7.5EG 7.52022-05-05
novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.
- CVE-2022-0656HIGHCVSS 7.5EG 7.52022-04-25
The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url_to_base64 AJAX action (available to both unauthenticated and authenticated users) before using it in the file_get_cont…
- CVE-2022-28002HIGHCVSS 7.5EG 7.52022-04-08
Movie Seat Reservation v1 was discovered to contain an unauthenticated file disclosure vulnerability via /index.php?page=home.
- CVE-2022-26271HIGHCVSS 7.5EG 7.52022-03-28
74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php.
- CVE-2022-23377HIGHCVSS 7.5EG 7.52022-03-01
Archeevo below 5.0 is affected by local file inclusion through file=~/web.config to allow an attacker to retrieve local files.
- CVE-2022-25104HIGHCVSS 7.5EG 7.52022-02-24
HorizontCMS v1.0.0-beta.2 was discovered to contain an arbitrary file download vulnerability via the component /admin/file-manager/.
- CVE-2022-25297HIGHCVSS 7.5EG 7.52022-02-21
This affects the package drogonframework/drogon before 1.7.5. The unsafe handling of file names during upload using HttpFile::save() method may enable attackers to write files to arbitrary locations outside the designated target folder.
- CVE-2022-21236HIGHCVSS 7.5EG 7.52022-01-28
An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HT…
- CVE-2021-44315HIGHCVSS 7.5EG 7.52021-12-16
In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to view the sensitive files of the application, for example: Any file which contains sensitive information of the user or …
- CVE-2021-41573HIGHCVSS 7.5EG 7.52021-09-29
Hitachi Content Platform Anywhere (HCP-AW) 4.4.5 and later allows information disclosure. If authenticated user creates a link to a file or folder while the system was running version 4.3.x or earlier and then shares the link and then late…
- CVE-2020-35340HIGHCVSS 7.5EG 7.52021-09-15
A local file inclusion vulnerability in ExpertPDF 9.5.0 through 14.1.0 allows attackers to read the file contents from files that the running ExpertPDF process has access to read.
- CVE-2020-22124HIGHCVSS 7.5EG 7.52021-08-18
A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information.
- CVE-2021-38711HIGHCVSS 7.5EG 7.52021-08-16
In gitit before 0.15.0.0, the Export feature can be exploited to leak information from files.
- CVE-2021-37348HIGHCVSS 7.5EG 7.52021-08-13
Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation of a pathname in index.php.
- CVE-2021-36763HIGHCVSS 7.5EG 7.52021-08-03
In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.
- CVE-2021-33359HIGHCVSS 7.5EG 7.52021-06-09
A vulnerability exists in gowitness < 2.3.6 that allows an unauthenticated attacker to perform an arbitrary file read using the file:// scheme in the url parameter to get an image of any file.
- CVE-2018-10863HIGHCVSS 7.5EG 7.52021-05-26
It was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer directory, through the /rhcert-transfer URL. An unauthorized attacker may use this flaw t…
- CVE-2021-29024HIGHCVSS 7.5EG 7.52021-05-17
In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.
- CVE-2020-26549HIGHCVSS 7.5EG 7.52020-11-17
An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests to directories can be bypassed for file downloading.
- CVE-2020-24312HIGHCVSS 7.5EG 7.52020-08-26
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes…
- CVE-2020-11976HIGHCVSS 7.5EG 7.52020-08-11
By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Ap…
Map vulnerabilities like CWE-552 to your infrastructure
EchelonGraph correlates every CVE — across CWE-552 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →