CWE-552— Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.— MITRE CWE catalog
526 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-552page 10 of 11
- CVE-2025-68719HIGHCVSS 8.8EG 8.82026-01-08
KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 mishandle configuration management. Once any user is logged in and maintains an active session, an attacker can directly query the backup endpoint and download a full configuration archive. …
- CVE-2025-69428HIGHCVSS 7.5EG 7.52026-04-27
An issue in Pro-Bit before v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdirectories.
- CVE-2025-69875HIGHCVSS 7.8EG 7.82026-02-03
A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and improper permission handling allow a low-privileged local user to restore quarantined file…
- CVE-2025-69990CRITICALCVSS 9.1EG 9.12026-01-13
phpgurukul News Portal Project V4.1 has an Arbitrary File Deletion Vulnerability in remove_file.php. The parameter file can cause any file to be deleted.
- CVE-2025-7389HIGHCVSS 8.2EG 8.22026-04-14
A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-level access to the server through the adopted authority of the AdminServer process itself. The delegated authority of…
- CVE-2025-9273MEDIUMCVSS 4.3EG 4.32025-09-02
CData API Server MySQL Misconfiguration Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of CData API Server. Authentication is required to exploit…
- CVE-2026-11841CRITICALCVSS 9.4EG 9.42026-07-28
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through…
- CVE-2026-13533MEDIUMCVSS 5.3EG 5.32026-06-29
A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function Spyc::YAMLLoad of the file /config/config.yaml of the component htaccess Handler. Such manipulation leads to files or d…
- CVE-2026-14849LOWCVSS 3.7EG 3.72026-07-31
The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the uploads directory, allowing unauthenticated users to download the exported mem…
- CVE-2026-15342MEDIUMCVSS 6.5EG 6.52026-07-21
Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspac…
- CVE-2026-19093MEDIUMCVSS 6.8EG 6.82026-08-22
The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor role to read arbitrary files on the server, including files outside the web root. The re…
- CVE-2026-19903MEDIUMCVSS 5.3EG 5.32026-08-15
A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db/shopping.sql of the component SQL Database Backup. The manipulation leads to files or directories accessible. Remote e…
- CVE-2026-19987MEDIUMCVSS 5.3EG 5.32026-08-17
A security vulnerability has been detected in SourceCodester Best Employee Management System 1.0. This affects an unknown function of the file /assets/uploadImage/Profile/. Such manipulation leads to exposure of information through directo…
- CVE-2026-2330CRITICALCVSS 9.4EG 9.42026-03-06
An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain directories intended for internal testing were not covered by the whitelist and are accessible w…
- CVE-2026-2331CRITICALCVSS 9.8EG 9.82026-03-06
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through…
- CVE-2026-24732MEDIUMCVSS 6.6EG 6.62026-03-04
Files or Directories Accessible to External Parties, Incorrect Permission Assignment for Critical Resource vulnerability in Hallo Welt! GmbH BlueSpice (Extension:NSFileRepo modules) allows Accessing Functionality Not Properly Constrained b…
- CVE-2026-25137CRITICALCVSS 9.1EG 9.12026-02-02
The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the database manager without any authentication. This allows unauthorized actors to delete and…
- CVE-2026-25231HIGHCVSS 7.5EG 7.52026-02-09
FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 3.3.0, the application contains an unauthenticated file read vulnerability due to the lack of access control on the /uploads directory. Files uploaded to this di…
- CVE-2026-29066MEDIUMCVSS 6.2EG 6.22026-03-12
Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables Vite's built-in filesystem access restriction. This allows any unauthenticated attacker w…
- CVE-2026-31215CRITICALCVSS 9.1EG 9.12026-05-12
The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticSearch service interface. The DELETE /{index_name}/documents endpoint lacks proper authentication and authorization controls a…
- CVE-2026-31216CRITICALCVSS 9.1EG 9.12026-05-12
The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its file management API. The DELETE /storage/{object_name:path} endpoint lacks authentication, authorization, and input validatio…
- CVE-2026-32185MEDIUMCVSS 5.5EG 5.52026-05-12
Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.
- CVE-2026-32750MEDIUMCVSS 6.8EG 6.82026-03-19
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importStdMd passes the localPath parameter directly to model.ImportFromLocalPath with zero path validation. The function recursively reads ever…
- CVE-2026-33071HIGHCVSS 8.8EG 8.82026-03-20
FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, the WebDAV upload endpoint accepts any file extension including .phtml, .php5, .htaccess, and other server-side executable types, bypassing the filenam…
- CVE-2026-33380MEDIUMCVSS 6.3EG 6.32026-05-13
A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.
- CVE-2026-33698CRITICALCVSS 9.8EG 9.82026-04-10
Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ directory and allow an unauthenticated attacker to modify existing files or create new files where…
- CVE-2026-34361CRITICALCVSS 9.3EG 9.32026-03-31
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that makes outbound HTTP request…
- CVE-2026-34392HIGHCVSS 7.5EG 7.52026-04-08
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 20.0.0 to before 27.0.3 and 28.0.1, a bug in the static file router can all…
- CVE-2026-34785HIGHCVSS 7.5EG 7.52026-04-02
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served as a static file using a simple string prefix check. When configured with URL prefixes suc…
- CVE-2026-35169MEDIUMCVSS 5.4EG 5.42026-04-08
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From to before 27.0.3 and 28.0.1, the help_editor module of LORIS did not prope…
- CVE-2026-35440MEDIUMCVSS 5.5EG 5.52026-05-12
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2026-35446HIGHCVSS 8.6EG 8.62026-04-08
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 24.0.0 to before 27.0.3 and 28.0.1, an incorrect order of operations in the…
- CVE-2026-37065CRITICALCVSS 9.1EG 9.12026-08-27
Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&action=update&remove=.
- CVE-2026-39871HIGHCVSS 7.5EG 7.52026-05-11
A path handling issue was addressed with improved logic. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to observe unprotected user data.
- CVE-2026-40425MEDIUMCVSS 4.9EG 5.72026-05-29
The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password.
- CVE-2026-40484CRITICALCVSS 9.1EG 9.12026-04-18
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive contents and copies files from the Images/ directory into the web-accessible document roo…
- CVE-2026-40564MEDIUMCVSS 6.5EG 6.52026-05-26
Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI is currently not validated so that it points to user-owned files or addr…
- CVE-2026-40624CRITICALCVSS 9.8EG 9.82026-06-19
Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated attacker to achieve arbitrary code execution via a specially crafted web request.
- CVE-2026-40631HIGHCVSS 8.7EG 8.72026-05-13
An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation. Note: Software versions which have reached End of Technical Support…
- CVE-2026-42063MEDIUMCVSS 4.9EG 4.92026-05-13
A vulnerability exists in iControl SOAP where an authenticated attacker with the Resource Administrator or Administrator role can download sensitive files. Note: Software versions which have reached End of Technical Support (EoTS) are n…
- CVE-2026-45088HIGHCVSS 7.5EG 7.52026-05-27
Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the custom-payload-file field in model.Options is JSON-tagged and deserialized directly from the a…
- CVE-2026-4532HIGHCVSS 7.5EG 7.52026-03-22
A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /food/sql/food.sql of the component Database Backup Handler. The mani…
- CVE-2026-45543MEDIUMCVSS 5.3EG 5.32026-06-01
Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent files for the affected form. The scope is limited to upl…
- CVE-2026-45721CRITICALCVSS 9.0EG 9.02026-05-19
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that resolves to a directory without an index file, DirPage walks upward through parent directories — past the configured ser…
- CVE-2026-4760HIGHCVSS 7.7EG 7.72026-03-25
From Panorama Web HMI, an attacker can gain read access to certain Web HMI server files, if he knows their paths and if these files are accessible to the Servin process execution account. * Installations based on Panorama Suite 2022-SP1…
- CVE-2026-4900MEDIUMCVSS 5.3EG 5.32026-03-26
A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the file /dbfood/localhost.sql. This manipulation causes files or directories accessible. The attack can be initiated remotely…
- CVE-2026-5335MEDIUMCVSS 5.3EG 5.32026-05-04
The Magic Export & Import WordPress plugin before 1.2.0 stores exported CSV files at a publicly accessible location, making it possible for any visitors to leak sensitive user information.
- CVE-2026-53580HIGHCVSS 8.1EG 8.12026-08-27
Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the automatic image-download feature accepts file:// URLs in a note's img tags and reads the referenced local file with no path validation, allow…
- CVE-2026-54457HIGHCVSS 7.7EG 7.72026-07-15
TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied J…
- CVE-2026-54629HIGHCVSS 7.5EG 7.52026-07-14
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, aut…
Map vulnerabilities like CWE-552 to your infrastructure
EchelonGraph correlates every CVE — across CWE-552 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →