CWE-552— Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.— MITRE CWE catalog
526 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-552page 5 of 11
- CVE-2022-40126HIGHCVSS 7.8EG 7.82022-09-29
A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows attackers to escalate privileges and execute arbitrary commands when Service Mode is activated.
- CVE-2022-4106HIGHCVSS 7.5EG 7.52022-12-19
The Wholesale Market for WooCommerce WordPress plugin before 1.0.7 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from …
- CVE-2022-4108MEDIUMCVSS 4.9EG 4.92022-12-19
The Wholesale Market for WooCommerce WordPress plugin before 1.0.8 does not validate user input used to generate system path, allowing high privilege users such as admin to download arbitrary file from the server even when they should not …
- CVE-2022-41343HIGHCVSS 7.5EG 7.52022-09-25
registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demonstrated by a @font-face rule.
- CVE-2022-4140HIGHCVSS 7.5EG 7.52023-01-02
The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file, which could allow unauthenticated attacker to read arbitrary files on the server
- CVE-2022-41710MEDIUMCVSS 5.5EG 5.52022-11-03
Markdownify version 1.4.1 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious markdown file through Markdownify. This is possible because the application does not have a CSP …
- CVE-2022-42234HIGHCVSS 8.8EG 8.82022-10-14
There is a file inclusion vulnerability in the template management module in UCMS 1.6
- CVE-2022-4236MEDIUMCVSS 6.5EG 6.52023-01-02
The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file via an AJAX action available to any authenticated users, which could allow users with a role as low as subscr…
- CVE-2022-42834LOWCVSS 3.3EG 3.32023-06-23
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13, macOS Big Sur 11.7.3. An app may be able to access mail folder attachments through a temporary directory used …
- CVE-2022-43414MEDIUMCVSS 5.3EG 5.32022-10-19
Jenkins NUnit Plugin 0.27 and earlier implements an agent-to-controller message that parses files inside a user-specified directory as test results, allowing attackers able to control agent processes to obtain test results from files in an…
- CVE-2022-43449MEDIUMCVSS 6.2EG 6.22022-11-03
OpenHarmony-v3.1.2 and prior versions had an Arbitrary file read vulnerability via download_server. Local attackers can install an malicious application on the device and reveal any file from the filesystem that is accessible to download_s…
- CVE-2022-4346MEDIUMCVSS 5.3EG 5.32023-01-23
The All-In-One Security (AIOS) WordPress plugin before 5.1.3 leaked settings of the plugin publicly, including the used email address.
- CVE-2022-44343HIGHCVSS 7.5EG 7.52023-02-06
CRMEB 4.4.4 is vulnerable to Any File download.
- CVE-2022-44356HIGHCVSS 7.5EG 7.52022-11-29
WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data and log files.
- CVE-2022-44583HIGHCVSS 7.5EG 7.52022-11-18
Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.
- CVE-2022-44634MEDIUMCVSS 4.9EG 4.92022-11-18
Auth. (admin+) Arbitrary File Read vulnerability in S2W – Import Shopify to WooCommerce plugin <= 1.1.12 on WordPress.
- CVE-2022-45052HIGHCVSS 8.8EG 8.82023-01-04
A Local File Inclusion vulnerability has been found in Axiell Iguana CMS. Due to insufficient neutralisation of user input on the url parameter on the Proxy.type.php endpoint, external users are capable of accessing files on the server.
- CVE-2022-45129HIGHCVSS 7.5EG 7.52022-11-10
Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, an…
- CVE-2022-45227HIGHCVSS 7.5EG 7.52022-12-12
The web portal of Dragino Lora LG01 18ed40 IoT v4.3.4 has the directory listing at the URL https://10.10.20.74/lib/. This address has a backup file which can be downloaded without any authentication.
- CVE-2022-45426MEDIUMCVSS 6.5EG 6.52022-12-27
Some Dahua software products have a vulnerability of unrestricted download of file. After obtaining the permissions of ordinary users, by sending a specific crafted packet to the vulnerable interface, an attacker can download arbitrary fil…
- CVE-2022-45440MEDIUMCVSS 4.4EG 4.42023-01-17
A vulnerability exists in the FTP server of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0, which processes symbolic links on external storage media. A local authenticated attacker with administrator privileges could abuse this vuln…
- CVE-2022-45450HIGHCVSS 7.5EG 7.52023-05-18
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 28610, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 3…
- CVE-2022-47950MEDIUMCVSS 6.5EG 6.52023-01-18
An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting …
- CVE-2022-48094MEDIUMCVSS 4.9EG 4.92023-02-01
lmxcms v1.41 was discovered to contain an arbitrary file read vulnerability via TemplateAction.class.php.
- CVE-2022-48161HIGHCVSS 7.5EG 7.52023-02-01
Easy Images v2.0 was discovered to contain an arbitrary file download vulnerability via the component /application/down.php. This vulnerability is exploited via a crafted GET request.
- CVE-2023-0331HIGHCVSS 7.5EG 7.52023-02-27
The Correos Oficial WordPress plugin through 1.2.0.2 does not have an authorization check user input validation when generating a file path, allowing unauthenticated attackers to download arbitrary files from the server.
- CVE-2023-0822HIGHCVSS 8.8EG 8.82023-02-17
The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization, which could allow an unauthorized user to bypass authorization and access privileged functionality.
- CVE-2023-1124HIGHCVSS 7.2EG 7.22023-04-03
The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticated users with admin privileges to perform LFI attacks.
- CVE-2023-1246HIGHCVSS 7.5EG 7.52023-03-10
Files or Directories Accessible to External Parties vulnerability in Saysis Starcities allows Collect Data from Common Resource Locations. This issue affects Starcities: through 1.3.
- CVE-2023-20039MEDIUMCVSS 5.5EG 5.52024-11-15
A vulnerability in Cisco IND could allow an authenticated, local attacker to read application data. This vulnerability is due to insufficient default file permissions that are applied to the application data directory. An attacker could…
- CVE-2023-20183MEDIUMCVSS 5.4EG 5.42023-05-18
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted conta…
- CVE-2023-20184MEDIUMCVSS 5.4EG 5.42023-05-18
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted conta…
- CVE-2023-20235MEDIUMCVSS 6.5EG 6.52023-10-04
A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an authenticated, remote attacker to access the underlying operating system…
- CVE-2023-2180HIGHCVSS 7.5EG 7.52023-05-15
The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unseria…
- CVE-2023-22858MEDIUMCVSS 5.3EG 5.32023-03-06
An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files of unpublished blogs.
- CVE-2023-22974HIGHCVSS 7.5EG 7.52023-02-22
A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controlling a connection to an attacker-controlled MySQL server.
- CVE-2023-23330HIGHCVSS 7.5EG 7.52023-03-28
amano Xparc parking solutions 7.1.3879 was discovered to be vulnerable to local file inclusion.
- CVE-2023-23365HIGHCVSS 7.7EG 7.72023-10-06
A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the contents of unexpected files and expose sensitive data via a network. We have already fi…
- CVE-2023-23366HIGHCVSS 7.7EG 7.72023-10-06
A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the contents of unexpected files and expose sensitive data via a network. We have already fi…
- CVE-2023-25260HIGHCVSS 7.5EG 7.52023-03-28
Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.
- CVE-2023-2538MEDIUMCVSS 5.8EG 6.32023-07-05
A CWE-552 "Files or Directories Accessible to External Parties” in the web interface of the Tyan S5552 BMC version 3.00 allows an unauthenticated remote attacker to retrieve the private key of the TLS certificate in use by the BMC via fo…
- CVE-2023-26580HIGHCVSS 7.5EG 7.52023-10-25
Unauthenticated arbitrary file read in the IDAttend’s IDWeb application 3.1.013 allows the retrieval of any file present on the web server by unauthenticated attackers.
- CVE-2023-26948HIGHCVSS 7.5EG 7.52023-03-09
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/file/download.
- CVE-2023-26956HIGHCVSS 7.5EG 7.52023-03-08
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/curd/code.
- CVE-2023-27180HIGHCVSS 7.5EG 7.52023-04-07
GDidees CMS v3.9.1 was discovered to contain a source code disclosure vulnerability by the backup feature which is accessible via /_admin/backup.php.
- CVE-2023-2766MEDIUMCVSS 5.3EG 6.92023-05-17
A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini. The manipulation leads to files or directories …
- CVE-2023-28375HIGHCVSS 7.5EG 7.52023-03-28
Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated file disclosure. Using a GET parameter, attackers can disclose arbitrary files on the affected device and disclose sensitive and system information.
- CVE-2023-29080HIGHCVSS 8.5EG 8.52025-01-30
Potential privilege escalation vulnerability in Revenera InstallShield versions 2022 R2 and 2021 R2 due to adding InstallScript custom action to a Basic MSI or InstallScript MSI project extracting few binaries to a predefined writable fo…
- CVE-2023-29107MEDIUMCVSS 5.3EG 5.32023-05-09
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The export endpoint discloses some undocumented files. This could allow an una…
- CVE-2023-29450HIGHCVSS 8.5EG 8.52023-07-13
JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.
Map vulnerabilities like CWE-552 to your infrastructure
EchelonGraph correlates every CVE — across CWE-552 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →