CWE-552— Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.— MITRE CWE catalog
535 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-552page 7 of 11
- CVE-2020-26183MEDIUMCVSS 6.8EG 6.82020-10-16
Dell EMC NetWorker versions prior to 19.3.0.2 contain an improper authorization vulnerability. Certain remote users with low privileges may exploit this vulnerability to perform 'nsrmmdbd' operations in an unintended manner.
- CVE-2020-26182MEDIUMCVSS 6.8EG 6.82020-10-16
Dell EMC NetWorker versions prior to 19.3.0.2 contain an incorrect privilege assignment vulnerability. A non-LDAP remote user with low privileges may exploit this vulnerability to perform 'saveset' related operations in an unintended manne…
- CVE-2020-15224MEDIUMCVSS 6.8EG 6.82020-10-14
In Open Enclave before version 0.12.0, an information disclosure vulnerability exists when an enclave application using the syscalls provided by the sockets.edl is loaded by a malicious host application. An attacker who successfully exploi…
- CVE-2020-4075MEDIUMCVSS 6.8EG 6.82020-07-07
In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, arbitrary local file read is possible by defining unsafe window options on a child window opened via window.open. As a workaround, ensure you are calling `event.preventDefault()` …
- CVE-2020-5289MEDIUMCVSS 6.8EG 6.82020-03-30
In Elide before 4.5.14, it is possible for an adversary to "guess and check" the value of a model field they do not have access to assuming they can read at least one other field in the model. The adversary can construct filter expressions…
- CVE-2023-47612MEDIUMCVSS 6.1EG 6.82023-11-09
A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that could allow an attacker w…
- CVE-2023-4588MEDIUMCVSS 4.9EG 6.82023-09-06
File accessibility vulnerability in Delinea Secret Server, in its v10.9.000002 and v11.4.000002 versions. Exploitation of this vulnerability could allow an authenticated user with administrative privileges to create a backup file in the ap…
- CVE-2024-54099MEDIUMCVSS 6.7EG 6.72024-12-12
File replacement vulnerability on some devices Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
- CVE-2021-20253MEDIUMCVSS 6.7EG 6.72021-03-09
A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker to elevate the privilege from a low privileged user to the awx user from outside the isolated environment. The highest t…
- CVE-2026-24732MEDIUMCVSS 6.6EG 6.62026-03-04
Files or Directories Accessible to External Parties, Incorrect Permission Assignment for Critical Resource vulnerability in Hallo Welt! GmbH BlueSpice (Extension:NSFileRepo modules) allows Accessing Functionality Not Properly Constrained b…
- CVE-2025-44779MEDIUMCVSS 6.6EG 6.62025-08-07
An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.
- CVE-2023-3712MEDIUMCVSS 6.6EG 6.62023-09-12
Files or Directories Accessible to External Parties vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Privilege Escalation.This issue affects PM43 versions prior to P10.19.050004. Update to the latest avai…
- CVE-2020-25636MEDIUMCVSS 6.6EG 6.62020-10-05
A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers. Files are written directly to the root bucket, making possible to have collisions when running multiple ansib…
- CVE-2025-0620MEDIUMCVSS 4.9EG 6.62025-06-06
A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.
- CVE-2026-75164MEDIUMCVSS 6.5EG 6.52026-09-04
An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to retrieve arbitrary files from the device filesy…
- CVE-2026-15342MEDIUMCVSS 6.5EG 6.52026-07-21
Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspac…
- CVE-2026-40564MEDIUMCVSS 6.5EG 6.52026-05-26
Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI is currently not validated so that it points to user-owned files or addr…
- CVE-2026-8704MEDIUMCVSS 6.5EG 6.52026-05-15
Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified.
- CVE-2026-7817MEDIUMCVSS 6.5EG 6.52026-05-11
Local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities in pgAdmin 4 LLM API configuration endpoints. User-supplied api_key_file and api_url preferences were passed to the LLM provider clients without validation.…
- CVE-2021-47960MEDIUMCVSS 6.5EG 6.52026-04-10
A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interf…
- CVE-2025-66955MEDIUMCVSS 6.5EG 6.52026-03-12
Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenticated users to access files on the host via "path" parameter in the downloadAttachment and downloadAttachmentFromPath API cal…
- CVE-2025-37177MEDIUMCVSS 6.5EG 6.52026-01-13
An arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation of this vulnerability could allow an authenticated …
- CVE-2025-66689MEDIUMCVSS 6.5EG 6.52026-01-12
A path traversal vulnerability exists in Zen MCP Server before 9.8.2 that allows authenticated attackers to read arbitrary files on the system. The vulnerability is caused by flawed logic in the is_dangerous_path() validation function that…
- CVE-2018-25145MEDIUMCVSS 6.5EG 6.52025-12-24
Microhard Systems IPn4G 1.1.0 contains a configuration file disclosure vulnerability that allows authenticated attackers to download sensitive system configuration files. Attackers can retrieve configuration files from multiple directories…
- CVE-2025-59976MEDIUMCVSS 6.5EG 6.52025-10-09
An arbitrary file download vulnerability in the web interface of Juniper Networks Junos Space allows a network-based authenticated attacker using a crafted GET method to access any file on the file system. Using specially crafted GET metho…
- CVE-2025-37130MEDIUMCVSS 6.5EG 6.52025-09-16
A vulnerability in the command-line interface of EdgeConnect SD-WAN could allow an authenticated attacker to read arbitrary files within the system. Successful exploitation could allow an attacker to read sensitive data from the underlying…
- CVE-2025-5273MEDIUMCVSS 6.5EG 6.52025-05-29
Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Files or Directories Accessible to External Parties via the get-markdown-file tool. An attacker can craft a prompt that, once accessed by the MCP host, will allo…
- CVE-2024-8031MEDIUMCVSS 6.5EG 6.52025-05-15
The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloaded. This makes it possible for authenticated attackers, with admin-level access and above, to download arbitrary files t…
- CVE-2024-53649MEDIUMCVSS 6.5EG 6.52025-01-14
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.80), SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 6MD86 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 6MD89 (CP300) (All versi…
- CVE-2024-31141MEDIUMCVSS 6.5EG 6.52024-11-19
Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accept configuration data for customizing behavior, and includes ConfigProvider plugins in orde…
- CVE-2024-40767MEDIUMCVSS 6.5EG 6.52024-07-24
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user …
- CVE-2023-41916MEDIUMCVSS 6.5EG 6.52024-07-15
In Apache Linkis =1.4.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will trigger arbitrary file reading. Therefore, the parameters in the…
- CVE-2024-32498MEDIUMCVSS 6.5EG 6.52024-07-05
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data fi…
- CVE-2024-5056MEDIUMCVSS 6.5EG 6.52024-06-12
CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the device firmware and prevent proper behavior of the webserver when specific files or directories are removed from the fil…
- CVE-2023-39480MEDIUMCVSS 6.5EG 6.52024-05-03
Softing Secure Integration Server FileDirectory OPC UA Object Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Softing Secure Integration Server. Altho…
- CVE-2023-5907MEDIUMCVSS 6.5EG 6.52023-12-11
The File Manager WordPress plugin before 6.3 does not restrict the file managers root directory, allowing an administrator to set a root outside of the WordPress root directory, giving access to system files and directories even in a multi…
- CVE-2023-4930MEDIUMCVSS 6.5EG 6.52023-11-06
The Front End PM WordPress plugin before 11.4.3 does not block listing the contents of the directories where it stores attachments to private messages, allowing unauthenticated visitors to list and download private attachments if the autoi…
- CVE-2023-20235MEDIUMCVSS 6.5EG 6.52023-10-04
A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an authenticated, remote attacker to access the underlying operating system…
- CVE-2023-37551MEDIUMCVSS 6.5EG 6.52023-08-03
In multiple Codesys products in multiple versions, after successful authentication as a user, specially crafted network communication requests can utilize the CmpApp component to download files with any file extensions to the controller. I…
- CVE-2023-34316MEDIUMCVSS 6.5EG 6.52023-07-10
An attacker could bypass the latest Delta Electronics InfraSuite Device Master (versions prior to 1.0.7) patch, which could allow an attacker to retrieve file contents.
- CVE-2022-47950MEDIUMCVSS 6.5EG 6.52023-01-18
An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting …
- CVE-2022-4236MEDIUMCVSS 6.5EG 6.52023-01-02
The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file via an AJAX action available to any authenticated users, which could allow users with a role as low as subscr…
- CVE-2022-45426MEDIUMCVSS 6.5EG 6.52022-12-27
Some Dahua software products have a vulnerability of unrestricted download of file. After obtaining the permissions of ordinary users, by sending a specific crafted packet to the vulnerable interface, an attacker can download arbitrary fil…
- CVE-2022-28283MEDIUMCVSS 6.5EG 6.52022-12-22
The sourceMapURL feature in devtools was missing security checks that would have allowed a webpage to attempt to include local files or other files that should have been inaccessible. This vulnerability affects Firefox < 99.
- CVE-2022-37424MEDIUMCVSS 6.5EG 6.52022-10-28
Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery.
- CVE-2022-3287MEDIUMCVSS 6.5EG 6.52022-09-28
When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.
- CVE-2022-2392MEDIUMCVSS 6.5EG 6.52022-08-22
The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that can be exploited by users with "Contributor" permissions or higher.
- CVE-2022-36306MEDIUMCVSS 6.5EG 6.52022-08-16
An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web server binary, and the web server configuration file. These vulnerabilities were found in AirVelocity…
- CVE-2021-42644MEDIUMCVSS 6.5EG 6.52022-05-17
cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_database) can be read through this vulnera…
- CVE-2022-28445MEDIUMCVSS 6.5EG 6.52022-04-21
KiteCMS v1.1.1 was discovered to contain an arbitrary file read vulnerability via the background management module.
Map vulnerabilities like CWE-552 to your infrastructure
EchelonGraph correlates every CVE — across CWE-552 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →