CWE-552— Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.— MITRE CWE catalog
535 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-552page 6 of 11
- CVE-2019-20529HIGHCVSS 7.5EG 7.52020-03-18
In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (no authentication is required to access; having a link is sufficient) instead of private f…
- CVE-2019-13941HIGHCVSS 7.5EG 7.52020-02-11
A vulnerability has been identified in OZW672 (All versions < V10.00), OZW772 (All versions < V10.00). Vulnerable versions of OZW Web Server use predictable path names for project files that legitimately authenticated users have created by…
- CVE-2020-7241HIGHCVSS 7.5EG 7.52020-01-20
The WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory wp-content/uploads/db-backup/. This might allow attackers to read ZIP archives by guessing random ID numbers, guessing date string…
- CVE-2019-17221HIGHCVSS 7.5EG 7.52019-11-05
PhantomJS through 2.1.1 has an arbitrary file read vulnerability, as demonstrated by an XMLHttpRequest for a file:// URI. The vulnerability exists in the page.open() function of the webpage module, which loads a specified URL and calls a g…
- CVE-2019-10930HIGHCVSS 7.5EG 7.52019-07-11
A vulnerability has been identified in All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respective Ethernet communication modules (All versions ), DIGSI 5 engineering software (All versions < V7.90), SIPROTEC 5 d…
- CVE-2019-3569HIGHCVSS 7.5EG 7.52019-06-26
HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in information disclosure. This issue affects…
- CVE-2018-16946HIGHCVSS 7.5EG 7.52018-09-12
LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via download.php) without authenticating. These …
- CVE-2018-10869HIGHCVSS 7.5EG 7.52018-07-19
redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file accessible by the user running httpd.
- CVE-2018-5112HIGHCVSS 7.5EG 7.52018-06-11
Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but this requirement was not enforced in all instances. This could allow the development tools panel for th…
- CVE-2017-12079HIGHCVSS 7.5EG 7.52017-12-04
Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain arbitrary files via prog_id field.
- CVE-2017-2551HIGHCVSS 7.5EG 7.52017-09-28
Vulnerability in Wordpress plugin BackWPup before v3.4.2 allows possible brute forcing of backup file for download.
- CVE-2017-11746HIGHCVSS 7.5EG 7.52017-07-30
Tenshi 0.15 creates a tenshi.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for tenshi.pid modification before a root script…
- CVE-2020-3926HIGHCVSS 6.1EG 7.52020-02-03
An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter.
- CVE-2024-3913HIGHCVSS 5.9EG 7.52024-08-13
An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup.
- CVE-2023-4475HIGHCVSS 5.5EG 7.52023-08-22
An Arbitrary File Movement vulnerability was found in ASUSTOR Data Master (ADM) allows an attacker to exploit the file renaming feature to move files to unintended directories. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 …
- CVE-2021-3800HIGHCVSS 5.5EG 7.52022-08-23
A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivileged ones under the right condition.
- CVE-2022-33901HIGHCVSS 5.3EG 7.52022-07-22
Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin <= 4.13.1 at WordPress.
- CVE-2026-57990HIGHCVSS 7.4EG 7.42026-07-26
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
- CVE-2025-3025HIGHCVSS 7.3EG 7.32025-09-15
Elevation of Privileges in the cleaning feature of Gen Digital CCleaner version 6.33.11465 on Windows allows a local user to gain SYSTEM privileges via exploiting insecure file delete operations. Reported in CCleaner v. 6.33.11465. This is…
- CVE-2025-4134HIGHCVSS 7.3EG 7.32025-05-28
Lack of file validation in do_update_vps in Avast Business Antivirus for Linux 4.5 on Linux allows local user to spoof or tamper with the update file via an unverified file write.
- CVE-2025-4909HIGHCVSS 7.3EG 7.32025-05-19
A vulnerability classified as critical was found in SourceCodester Client Database Management System 1.0. This vulnerability affects unknown code. The manipulation leads to exposure of information through directory listing. The attack can …
- CVE-2025-2038HIGHCVSS 7.3EG 7.32025-03-06
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /upload/. The manipulation leads to exposure of information through director…
- CVE-2025-0509HIGHCVSS 7.3EG 7.32025-02-04
A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.
- CVE-2024-39581HIGHCVSS 7.3EG 7.32024-09-10
Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to read, modify, …
- CVE-2018-9587HIGHCVSS 7.3EG 7.32019-02-11
In savePhotoFromUriToUri of ContactPhotoUtils.java in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is possible unauthorized access to files within the contact app due to a confused deputy scenari…
- CVE-2025-68109HIGHCVSS 7.2EG 7.22025-12-17
ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality does not validate the content or file extension of uploaded files. As a result, an attacker can upload a web shell file an…
- CVE-2024-48647HIGHCVSS 7.2EG 7.22024-10-30
A file disclosure vulnerability exists in Sage 1000 v7.0.0. This vulnerability allows remote attackers to retrieve arbitrary files from the server's file system by manipulating the URL parameter in HTTP requests. The attacker can exploit t…
- CVE-2023-3155HIGHCVSS 7.2EG 7.22023-10-16
The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the…
- CVE-2023-38948HIGHCVSS 7.2EG 7.22023-08-03
An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers to execute arbitrary code via downloading a crafted plugin.
- CVE-2023-1124HIGHCVSS 7.2EG 7.22023-04-03
The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticated users with admin privileges to perform LFI attacks.
- CVE-2021-32752HIGHCVSS 7.2EG 7.22021-07-09
Ether Logs is a package that allows one to check one's logs in the Craft 3 utilities section. A vulnerability was found in versions prior to 3.0.4 that allowed authenticated admin users to access any file on the server. The vulnerability h…
- CVE-2020-12470HIGHCVSS 7.2EG 7.22020-04-29
MonoX through 5.1.40.5152 allows administrators to execute arbitrary code by modifying an ASPX template.
- CVE-2022-29447HIGHCVSS 6.8EG 7.22022-05-20
Authenticated (administrator or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Hover Effects plugin <= 2.1 at WordPress.
- CVE-2022-29446HIGHCVSS 6.8EG 7.22022-05-19
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugin <= 1.1.1 at WordPress.
- CVE-2026-77884HIGHCVSS 7.1EG 7.12026-09-14
Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage.
- CVE-2025-45529HIGHCVSS 7.1EG 7.12025-05-27
An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor.
- CVE-2025-21264HIGHCVSS 7.1EG 7.12025-05-13
Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
- CVE-2025-1982HIGHCVSS 7.1EG 7.12025-04-16
Local File Inclusion vulnerability in Ready's attachment upload panel allows low privileged user to provide link to a local file using the file:// protocol thus allowing the attacker to read content of the file. This vulnerability can be u…
- CVE-2025-22369HIGHCVSS 7.1EG 7.12025-03-11
The ReadFile endpoint of the firmware for Mennekes Smart / Premium Chargingpoints can be abused to read arbitrary files from the underlying OS.
- CVE-2024-11629HIGHCVSS 7.1EG 7.12025-02-12
In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, the contents of a file at an arbitrary path can be exported to RTF.
- CVE-2020-3267HIGHCVSS 7.1EG 7.12020-06-03
A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to change the availability state of any agent. The vulnerability is due to insufficient authorization …
- CVE-2025-64185MEDIUMCVSS 6.9EG 6.92025-11-20
Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations in the GEM_PATH. Open OnDemand versions 4.0.8 and 3.1.16 have been patched for this vulnerability.
- CVE-2023-2766MEDIUMCVSS 5.3EG 6.92023-05-17
A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini. The manipulation leads to files or directories …
- CVE-2026-74853MEDIUMCVSS 6.8EG 6.82026-09-04
The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitrary files from the server, including files outside the web root. Onl…
- CVE-2026-82020MEDIUMCVSS 6.8EG 6.82026-08-28
Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential store by bypassing sensitive-path guards that excluded the…
- CVE-2026-19093MEDIUMCVSS 6.8EG 6.82026-08-22
The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor role to read arbitrary files on the server, including files outside the web root. The re…
- CVE-2024-11399MEDIUMCVSS 6.8EG 6.82026-05-27
Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to conduct denial-of-service attacks via unspecified vectors.
- CVE-2026-32750MEDIUMCVSS 6.8EG 6.82026-03-19
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importStdMd passes the localPath parameter directly to model.ImportFromLocalPath with zero path validation. The function recursively reads ever…
- CVE-2025-25266MEDIUMCVSS 6.8EG 6.82025-03-11
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant Simulation V2404 (All versions < V2404.0010). The affected application does not properly restrict access to the file del…
- CVE-2023-45594MEDIUMCVSS 6.8EG 6.82024-03-05
A CWE-552 “Files or Directories Accessible to External Parties” vulnerability in the embedded Chromium browser allows a physical attacker to arbitrarily download/upload files to/from the file system, with unspecified impacts to the con…
Map vulnerabilities like CWE-552 to your infrastructure
EchelonGraph correlates every CVE — across CWE-552 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →