CWE-552— Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.— MITRE CWE catalog
536 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-552page 9 of 11
- CVE-2022-41710MEDIUMCVSS 5.5EG 5.52022-11-03
Markdownify version 1.4.1 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious markdown file through Markdownify. This is possible because the application does not have a CSP …
- CVE-2021-3996MEDIUMCVSS 5.5EG 5.52022-08-23
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are …
- CVE-2021-3995MEDIUMCVSS 5.5EG 5.52022-08-23
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local attacker to unmount FUSE filesystems that belong to certain…
- CVE-2022-31475MEDIUMCVSS 5.5EG 5.52022-07-21
Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.
- CVE-2022-29302MEDIUMCVSS 5.5EG 5.52022-05-12
SolarView Compact ver.6.00 was discovered to contain a local file disclosure via /html/Solar_Ftp.php.
- CVE-2022-23621MEDIUMCVSS 5.5EG 5.52022-02-09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT right can read any file located in the XWiki WAR (for example xwiki.cfg and xwiki.properties…
- CVE-2021-43772MEDIUMCVSS 5.5EG 5.52021-12-03
Trend Micro Security 2021 v17.0 (Consumer) contains a vulnerability that allows files inside the protected folder to be modified without any detection.
- CVE-2021-42744MEDIUMCVSS 5.5EG 5.52021-11-19
Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
- CVE-2020-27368MEDIUMCVSS 5.5EG 5.52021-01-14
Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /icons/ directories via GET Parameter.
- CVE-2019-0381MEDIUMCVSS 5.5EG 5.52019-10-08
A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in directories outside of the paths specified…
- CVE-2017-2621MEDIUMCVSS 5.5EG 5.52018-07-27
An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensit…
- CVE-2017-7079MEDIUMCVSS 5.5EG 5.52017-10-23
An issue was discovered in certain Apple products. iTunes before 12.7 is affected. The issue involves the "Data Sync" component. It allows attackers to access iOS backups (written by iTunes) via a crafted app.
- CVE-2017-11829MEDIUMCVSS 5.5EG 5.52017-10-13
Microsoft Windows 10 allows an elevation of privilege vulnerability when the Windows Update Delivery Optimization does not properly enforce file share permissions.
- CVE-2015-1350MEDIUMCVSS 5.5EG 5.52016-05-02
The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability strip…
- CVE-2021-31831MEDIUMCVSS 4.9EG 5.52021-06-03
Incorrect access to deleted scripts vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to gain access to signed SQL scripts which have been marked as deleted or expired within the admini…
- CVE-2021-25459MEDIUMCVSS 4.0EG 5.52021-09-09
An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZService.
- CVE-2026-73735MEDIUMCVSS 5.4EG 5.42026-09-01
Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to access some information beyond their privilege level. Successful exploitation could allow an attacker to obtain limite…
- CVE-2026-35169MEDIUMCVSS 5.4EG 5.42026-04-08
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From to before 27.0.3 and 28.0.1, the help_editor module of LORIS did not prope…
- CVE-2024-48019MEDIUMCVSS 5.4EG 5.42025-02-04
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in Apache Doris. Application administrators can read arbitrary files from the server filesy…
- CVE-2023-20184MEDIUMCVSS 5.4EG 5.42023-05-18
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted conta…
- CVE-2023-20183MEDIUMCVSS 5.4EG 5.42023-05-18
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted conta…
- CVE-2026-94375MEDIUMCVSS 5.3EG 5.32026-10-10
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8 via the get_file_path. This makes it possible for unauthenticated attackers to…
- CVE-2026-100727MEDIUMCVSS 5.3EG 5.32026-10-05
An improper access control vulnerability exists in GROWI, which allow an unauthenticated attacker to read files contained in non-public pages of the affected product when the file upload setting is configured as "Local".
- CVE-2026-58415MEDIUMCVSS 5.3EG 5.32026-10-01
Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET…
- CVE-2026-73736MEDIUMCVSS 5.3EG 5.32026-09-01
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some system files. Successful exploitation could allow an attacker to read files within the affe…
- CVE-2026-78051MEDIUMCVSS 5.3EG 5.32026-08-22
A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the file /download/.metube/cookies.txt of the component Cookie File Handler. This manipulation causes files or directories a…
- CVE-2026-76799MEDIUMCVSS 5.3EG 5.32026-08-20
A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the file /loginsystem/database/login_registration_system.sql of the component SQL Database Backup Handler. This manipulation…
- CVE-2026-19987MEDIUMCVSS 5.3EG 5.32026-08-17
A security vulnerability has been detected in SourceCodester Best Employee Management System 1.0. This affects an unknown function of the file /assets/uploadImage/Profile/. Such manipulation leads to exposure of information through directo…
- CVE-2026-19903MEDIUMCVSS 5.3EG 5.32026-08-15
A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db/shopping.sql of the component SQL Database Backup. The manipulation leads to files or directories accessible. Remote e…
- CVE-2026-13533MEDIUMCVSS 5.3EG 5.32026-06-29
A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function Spyc::YAMLLoad of the file /config/config.yaml of the component htaccess Handler. Such manipulation leads to files or d…
- CVE-2026-45543MEDIUMCVSS 5.3EG 5.32026-06-01
Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent files for the affected form. The scope is limited to upl…
- CVE-2026-5335MEDIUMCVSS 5.3EG 5.32026-05-04
The Magic Export & Import WordPress plugin before 1.2.0 stores exported CSV files at a publicly accessible location, making it possible for any visitors to leak sensitive user information.
- CVE-2026-4900MEDIUMCVSS 5.3EG 5.32026-03-26
A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the file /dbfood/localhost.sql. This manipulation causes files or directories accessible. The attack can be initiated remotely…
- CVE-2025-12648MEDIUMCVSS 5.3EG 5.32026-01-07
The WP-Members Membership Plugin for WordPress is vulnerable to unauthorized file access in versions up to, and including, 3.5.4.4. This is due to storing user-uploaded files in predictable directories (wp-content/uploads/wpmembers/user_fi…
- CVE-2025-14442MEDIUMCVSS 5.3EG 5.32025-12-12
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to sensitive information exposure due to storage of exported CSV files in a publicly accessible directory with predictable filenames in all versions …
- CVE-2025-12747MEDIUMCVSS 5.3EG 5.32025-11-21
The Tainacan plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.0 via uploaded files marked as private being exposed in wp-content without adequate protection. This makes it possible for u…
- CVE-2025-12894MEDIUMCVSS 5.3EG 5.32025-11-21
The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.14.17 via the import/export functionality and a lack of .htacce…
- CVE-2025-13200MEDIUMCVSS 5.3EG 5.32025-11-15
A vulnerability was determined in SourceCodester Farm Management System 1.0. Affected by this vulnerability is an unknown functionality. This manipulation causes exposure of information through directory listing. The attack is possible to …
- CVE-2025-33150MEDIUMCVSS 5.3EG 5.32025-11-10
IBM Cognos Analytics Certified Containers 12.1.0 could disclose package parameter information due to the presence of hidden pages.
- CVE-2025-58152MEDIUMCVSS 5.3EG 5.32025-10-31
FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and the garbage collection information on the internal web page. With some crafted HTTP request, they can be accessed without authentication.
- CVE-2025-52460MEDIUMCVSS 5.3EG 5.32025-08-28
Files or directories accessible to external parties issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If exploited, uploaded files and SS1 configuration files may be accessed by a remote unauthenticated att…
- CVE-2025-43758MEDIUMCVSS 5.3EG 5.32025-08-22
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows …
- CVE-2025-43749MEDIUMCVSS 5.3EG 5.32025-08-20
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows …
- CVE-2025-4807MEDIUMCVSS 5.3EG 5.32025-05-16
A vulnerability, which was classified as problematic, was found in SourceCodester Online Student Clearance System 1.0. This affects an unknown part. The manipulation leads to exposure of information through directory listing. It is possibl…
- CVE-2025-2652MEDIUMCVSS 5.3EG 5.32025-03-23
A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to exposure of information…
- CVE-2025-2651MEDIUMCVSS 5.3EG 5.32025-03-23
A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /oews/admin/. The manipulation leads to exposure of information through directory listin…
- CVE-2025-2147MEDIUMCVSS 5.3EG 5.32025-03-10
A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to files or dir…
- CVE-2024-47106MEDIUMCVSS 5.3EG 5.32025-01-18
IBM Jazz for Service Management 1.1.3 through 1.1.3.22 could allow a remote attacker to obtain sensitive information from improper access restrictions that could aid in further attacks against the system.
- CVE-2024-9945MEDIUMCVSS 5.3EG 5.32024-12-13
An information-disclosure vulnerability exists in Fortra's GoAnywhere MFT application prior to version 7.7.0 that allows external access to the resources in certain admin root folders.
- CVE-2024-49756MEDIUMCVSS 5.3EG 5.32024-10-23
AshPostgres is the PostgreSQL data layer for Ash Framework. Starting in version 2.0.0 and prior to version 2.4.10, in certain very specific situations, it was possible for the policies of an update action to be skipped. This occurred only …
Map vulnerabilities like CWE-552 to your infrastructure
EchelonGraph correlates every CVE — across CWE-552 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →