CWE-552— Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.— MITRE CWE catalog
536 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-552page 8 of 11
- CVE-2022-26877MEDIUMCVSS 6.5EG 6.52022-04-09
Asana Desktop before 1.6.0 allows remote attackers to exfiltrate local files if they can trick the Asana desktop app into loading a malicious web page.
- CVE-2022-24075MEDIUMCVSS 6.5EG 6.52022-03-17
Whale browser before 3.12.129.18 allowed extensions to replace JavaScript files of the HWP viewer website which could access to local HWP files. When the HWP files were opened, the replaced script could read the files.
- CVE-2021-24947MEDIUMCVSS 6.5EG 6.52022-02-07
The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any authenticated user, such as subscriber, …
- CVE-2021-36233MEDIUMCVSS 6.5EG 6.52021-08-31
The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary files from the filesystem by specifying the file path.
- CVE-2020-25351MEDIUMCVSS 6.5EG 6.52021-08-20
An information disclosure vulnerability in rConfig 3.9.5 has been fixed for version 3.9.6. This vulnerability allowed remote authenticated attackers to read files on the system via a crafted request sent to to the /lib/crud/configcompare.c…
- CVE-2019-17130MEDIUMCVSS 6.5EG 6.52019-10-04
vBulletin through 5.5.4 mishandles external URLs within the /core/vb/vurl.php file and the /core/vb/vurl directories.
- CVE-2019-13140MEDIUMCVSS 6.5EG 6.52019-09-16
Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers have a JUCI ACL misconfiguration that allows the "user" account to extract the 3DES key via JSON commands to ubus. The 3DES key is used to decrypt the provisioning file provided by …
- CVE-2016-10829MEDIUMCVSS 6.5EG 6.52019-08-01
cPanel before 55.9999.141 allows arbitrary file-read operations because of a multipart form processing error (SEC-99).
- CVE-2017-6922MEDIUMCVSS 6.5EG 6.52019-01-22
In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous user that uploaded …
- CVE-2017-1308MEDIUMCVSS 6.5EG 6.52017-07-13
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0 could allow an authenticated attacker to download files they should not have access to due to improper access controls. IBM X-Force ID: 125462.
- CVE-2025-51818MEDIUMCVSS 5.4EG 6.52025-08-21
MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute arbitrary commands
- CVE-2025-23421MEDIUMCVSS 6.4EG 6.42025-02-13
An attacker could obtain firmware files and reverse engineer their intended use leading to loss of confidentiality and integrity of the hardware devices enabled by the Qardio iOS and Android applications.
- CVE-2024-47518MEDIUMCVSS 6.4EG 6.42025-01-10
Specially constructed queries targeting ETM could discover active remote access sessions
- CVE-2026-33380MEDIUMCVSS 6.3EG 6.32026-05-13
A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.
- CVE-2025-15065MEDIUMCVSS 6.3EG 6.32025-12-29
Exposure of Sensitive Information to an Unauthorized Actor, Missing Encryption of Sensitive Data, Files or Directories Accessible to External Parties vulnerability in Kings Information & Network Co. KESS Enterprise on Windows allows Privil…
- CVE-2022-34464MEDIUMCVSS 6.3EG 6.32022-07-12
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.7.3). The affected application uses an improperly protected file to import SSH keys. This could allow attackers with access to the filesystem of the host on…
- CVE-2019-12375MEDIUMCVSS 6.3EG 6.32019-06-03
Open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to remote information disclosure and arbitrary code execution.
- CVE-2023-2538MEDIUMCVSS 5.8EG 6.32023-07-05
A CWE-552 "Files or Directories Accessible to External Parties” in the web interface of the Tyan S5552 BMC version 3.00 allows an unauthenticated remote attacker to retrieve the private key of the TLS certificate in use by the BMC via fo…
- CVE-2026-6544MEDIUMCVSS 6.2EG 6.22026-09-24
IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface.
- CVE-2026-15915MEDIUMCVSS 6.2EG 6.22026-09-22
IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images.
- CVE-2026-29066MEDIUMCVSS 6.2EG 6.22026-03-12
Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables Vite's built-in filesystem access restriction. This allows any unauthenticated attacker w…
- CVE-2025-25267MEDIUMCVSS 6.2EG 6.22025-03-11
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant Simulation V2404 (All versions < V2404.0010). The affected application does not properly restrict the scope of files acc…
- CVE-2024-51058MEDIUMCVSS 6.2EG 6.22024-11-26
Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read arbitrary files from the server's file system through <img> src tag, potentially exposing sensitive information.
- CVE-2022-43449MEDIUMCVSS 6.2EG 6.22022-11-03
OpenHarmony-v3.1.2 and prior versions had an Arbitrary file read vulnerability via download_server. Local attackers can install an malicious application on the device and reveal any file from the filesystem that is accessible to download_s…
- CVE-2022-22268MEDIUMCVSS 6.1EG 6.12022-01-10
Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox Guard via Samsung DeX mode.
- CVE-2021-31850MEDIUMCVSS 6.1EG 6.12021-12-08
A denial-of-service vulnerability in Database Security (DBS) prior to 4.8.4 allows a remote authenticated administrator to trigger a denial-of-service attack against the DBS server. The configuration of Archiving through the User interface…
- CVE-2025-25799MEDIUMCVSS 6.0EG 6.02025-02-26
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php.
- CVE-2021-1512MEDIUMCVSS 6.0EG 6.02021-05-06
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying file system of an affected system. This vulnerability is due to insufficient validation of the …
- CVE-2021-1256MEDIUMCVSS 6.0EG 6.02021-04-29
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite files on the file system of an affected device by using directory traversal techniques. A successful expl…
- CVE-2020-3476MEDIUMCVSS 6.0EG 6.02020-09-24
A vulnerability in the CLI implementation of a specific command of Cisco IOS XE Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying host file system. The vulnerability is due to insufficient…
- CVE-2024-45627MEDIUMCVSS 5.9EG 5.92025-01-14
In Apache Linkis <1.7.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will allow the attacker to read arbitrary files from the Linkis serve…
- CVE-2021-40149MEDIUMCVSS 5.9EG 5.92022-07-17
The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the /self.key URI.
- CVE-2021-29969MEDIUMCVSS 5.9EG 5.92021-08-05
If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS handshake, then Thunderbird didn't ignore the injected data. This could have resul…
- CVE-2020-1726MEDIUMCVSS 5.9EG 5.92020-02-11
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious i…
- CVE-2017-2622MEDIUMCVSS 5.9EG 5.92018-07-27
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.
- CVE-2019-7305MEDIUMCVSS 5.8EG 5.82020-04-10
Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible over HTTP. Introduced in the Makefile patch file debian/patches/debian-changes-2.1.0b6+dfsg-1 or debian/patches/adds-a-…
- CVE-2022-23738MEDIUMCVSS 5.7EG 5.72022-11-01
An improper cache key vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to access private repository files through a public repository. To exploit this, an actor would need to already be authorized…
- CVE-2021-35203MEDIUMCVSS 5.7EG 5.72021-09-30
NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Arbitrary File Read operations via the FDSQueryService endpoint.
- CVE-2026-40425MEDIUMCVSS 4.9EG 5.72026-05-29
The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password.
- CVE-2025-13225MEDIUMCVSS 5.6EG 5.62025-11-19
Tanium addressed an arbitrary file deletion vulnerability in TanOS.
- CVE-2026-68831MEDIUMCVSS 5.5EG 5.52026-09-08
Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.
- CVE-2026-35440MEDIUMCVSS 5.5EG 5.52026-05-12
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2026-32185MEDIUMCVSS 5.5EG 5.52026-05-12
Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.
- CVE-2025-30103MEDIUMCVSS 5.5EG 5.52025-07-30
Dell SmartFabric OS10 Software, versions prior to 10.6.0.5 contains a Files or Directories Accessible to External Parties vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to F…
- CVE-2023-20039MEDIUMCVSS 5.5EG 5.52024-11-15
A vulnerability in Cisco IND could allow an authenticated, local attacker to read application data. This vulnerability is due to insufficient default file permissions that are applied to the application data directory. An attacker could…
- CVE-2024-23282MEDIUMCVSS 5.5EG 5.52024-06-10
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, watchOS 10.5. A maliciously crafted email may be able to initiate FaceTime calls without user a…
- CVE-2023-42534MEDIUMCVSS 5.5EG 5.52023-11-07
Improper input validation vulnerability in ChooserActivity prior to SMR Nov-2023 Release 1 allows local attackers to read arbitrary files with system privilege.
- CVE-2023-41717MEDIUMCVSS 5.5EG 5.52023-08-31
Inappropriate file type control in Zscaler Proxy versions 3.6.1.25 and prior allows local attackers to bypass file download/upload restrictions.
- CVE-2023-2976MEDIUMCVSS 5.5EG 5.52023-06-14
Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the defau…
- CVE-2023-29820MEDIUMCVSS 5.5EG 5.52023-05-12
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to access sensitive information via the EXE installer. NOTE: the vendor's perspective is that this is not a separate vulner…
Map vulnerabilities like CWE-552 to your infrastructure
EchelonGraph correlates every CVE — across CWE-552 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →