CWE-552— Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.— MITRE CWE catalog
526 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-552page 6 of 11
- CVE-2023-2976MEDIUMCVSS 5.5EG 5.52023-06-14
Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the defau…
- CVE-2023-29820MEDIUMCVSS 5.5EG 5.52023-05-12
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to access sensitive information via the EXE installer. NOTE: the vendor's perspective is that this is not a separate vulner…
- CVE-2023-29931CRITICALCVSS 9.8EG 9.82023-06-22
laravel-s 3.7.35 is vulnerable to Local File Inclusion via /src/Illuminate/Laravel.php.
- CVE-2023-31017HIGHCVSS 7.8EG 7.82023-11-02
NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may be able to write arbitrary data to privileged locations by using reparse points. A successful exploit of this vulnerability may lead to code execution, de…
- CVE-2023-31064HIGHCVSS 7.5EG 7.52023-05-22
Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. the user in InLong could cancel an application that doesn't belongs …
- CVE-2023-31066CRITICALCVSS 9.1EG 9.12023-05-22
Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Different users in InLong could delete, edit, stop, and start others…
- CVE-2023-3155HIGHCVSS 7.2EG 7.22023-10-16
The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the…
- CVE-2023-32226HIGHCVSS 8.3EG 8.32023-07-30
Sysaid - CWE-552: Files or Directories Accessible to External Parties - Authenticated users may exfiltrate files from the server via an unspecified method.
- CVE-2023-32684LOWCVSS 2.7EG 2.72023-05-30
Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to version 0.16.0, a virtual machine instance with a malicious disk image could read a single file on the host filesystem, even when no filesystem is m…
- CVE-2023-33517HIGHCVSS 7.5EG 7.52023-10-23
carRental 1.0 is vulnerable to Incorrect Access Control (Arbitrary File Read on the Back-end System).
- CVE-2023-33568HIGHCVSS 7.5EG 7.52023-06-13
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.
- CVE-2023-34316MEDIUMCVSS 6.5EG 6.52023-07-10
An attacker could bypass the latest Delta Electronics InfraSuite Device Master (versions prior to 1.0.7) patch, which could allow an attacker to retrieve file contents.
- CVE-2023-34645HIGHCVSS 7.5EG 7.52023-06-16
jfinal CMS 5.1.0 has an arbitrary file read vulnerability.
- CVE-2023-34834MEDIUMCVSS 5.3EG 5.32023-06-29
A Directory Browsing vulnerability in MCL-Net version 4.3.5.8788 webserver running on default port 5080, allows attackers to gain sensitive information about the configured databases via the "/file" endpoint.
- CVE-2023-36664CRITICALCVSS 7.8EG 9.82023-06-25
Artifex Ghostscript before 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
- CVE-2023-3712MEDIUMCVSS 6.6EG 6.62023-09-12
Files or Directories Accessible to External Parties vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Privilege Escalation.This issue affects PM43 versions prior to P10.19.050004. Update to the latest avai…
- CVE-2023-37551MEDIUMCVSS 6.5EG 6.52023-08-03
In multiple Codesys products in multiple versions, after successful authentication as a user, specially crafted network communication requests can utilize the CmpApp component to download files with any file extensions to the controller. I…
- CVE-2023-38948HIGHCVSS 7.2EG 7.22023-08-03
An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers to execute arbitrary code via downloading a crafted plugin.
- CVE-2023-38952HIGHCVSS 7.5EG 7.52023-08-03
Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that session ids are not validated for the type of user accessing the application by default. Privilege res…
- CVE-2023-39479HIGHCVSS 8.8EG 8.82024-05-03
Softing Secure Integration Server OPC UA Gateway Directory Creation Vulnerability. This vulnerability allows remote attackers to create directories on affected installations of Softing Secure Integration Server. Although authentication is …
- CVE-2023-39480MEDIUMCVSS 6.5EG 6.52024-05-03
Softing Secure Integration Server FileDirectory OPC UA Object Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Softing Secure Integration Server. Altho…
- CVE-2023-39545HIGHCVSS 8.8EG 8.82023-11-17
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary comm…
- CVE-2023-41566HIGHCVSS 8.1EG 8.12025-07-17
OA EKP v16 was discovered to contain an arbitrary download vulnerability via the component /ui/sys_ui_extend/sysUiExtend.do. This vulnerability allows attackers to obtain the password of the background administrator and further obtain data…
- CVE-2023-41717MEDIUMCVSS 5.5EG 5.52023-08-31
Inappropriate file type control in Zscaler Proxy versions 3.6.1.25 and prior allows local attackers to bypass file download/upload restrictions.
- CVE-2023-41916MEDIUMCVSS 6.5EG 6.52024-07-15
In Apache Linkis =1.4.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will trigger arbitrary file reading. Therefore, the parameters in the…
- CVE-2023-42534MEDIUMCVSS 5.5EG 5.52023-11-07
Improper input validation vulnerability in ChooserActivity prior to SMR Nov-2023 Release 1 allows local attackers to read arbitrary files with system privilege.
- CVE-2023-43856HIGHCVSS 7.5EG 7.52023-09-27
Dreamer CMS v4.1.3 was discovered to contain an arbitrary file read vulnerability via the component /admin/TemplateController.java.
- CVE-2023-4475HIGHCVSS 5.5EG 7.52023-08-22
An Arbitrary File Movement vulnerability was found in ASUSTOR Data Master (ADM) allows an attacker to exploit the file renaming feature to move files to unintended directories. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 …
- CVE-2023-45160CRITICALCVSS 8.8EG 10.02023-10-05
In the affected version of the 1E Client, an ordinary user could subvert downloaded instruction resource files, e.g., to substitute a harmful script. by replacing a resource script file created by an instruction at run time with a maliciou…
- CVE-2023-4550HIGHCVSS 7.5EG 7.52024-01-29
Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An unauthenticated or authenticated user can abuse a page of AppBuilder to re…
- CVE-2023-45594MEDIUMCVSS 6.8EG 6.82024-03-05
A CWE-552 “Files or Directories Accessible to External Parties” vulnerability in the embedded Chromium browser allows a physical attacker to arbitrarily download/upload files to/from the file system, with unspecified impacts to the con…
- CVE-2023-4588MEDIUMCVSS 4.9EG 6.82023-09-06
File accessibility vulnerability in Delinea Secret Server, in its v10.9.000002 and v11.4.000002 versions. Exploitation of this vulnerability could allow an authenticated user with administrative privileges to create a backup file in the ap…
- CVE-2023-47202HIGHCVSS 7.8EG 7.82024-01-23
A local file inclusion vulnerability on the Trend Micro Apex One management server could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-priv…
- CVE-2023-4743MEDIUMCVSS 4.8EG 4.82023-09-03
A vulnerability was found in Dreamer CMS up to 4.1.3. It has been classified as problematic. Affected is an unknown function of the file /upload/ueditorConfig?action=config. The manipulation leads to files or directories accessible. It is …
- CVE-2023-47612MEDIUMCVSS 6.1EG 6.82023-11-09
A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that could allow an attacker w…
- CVE-2023-48661MEDIUMCVSS 4.9EG 4.92023-12-14
Dell vApp Manager, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability to read arbitrary files from the target system.
- CVE-2023-48710CRITICALCVSS 9.8EG 9.82024-04-15
iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they should have restricted access. Hopefully, there is no sensitive files stored in that folder natively, but there could be …
- CVE-2023-49198HIGHCVSS 7.5EG 7.52024-08-21
Mysql security vulnerability in Apache SeaTunnel. Attackers can read files on the MySQL server by modifying the information in the MySQL URL allowLoadLocalInfile=true&allowUrlInLocalInfile=true&allowLoadLocalInfileInPath=/&maxAllowedPac…
- CVE-2023-4930MEDIUMCVSS 6.5EG 6.52023-11-06
The Front End PM WordPress plugin before 11.4.3 does not block listing the contents of the directories where it stores attachments to private messages, allowing unauthenticated visitors to list and download private attachments if the autoi…
- CVE-2023-4933MEDIUMCVSS 5.3EG 5.32023-10-16
The WP Job Openings WordPress plugin before 3.4.3 does not block listing the contents of the directories where it stores attachments to job applications, allowing unauthenticated visitors to list and download private attachments if the aut…
- CVE-2023-50164CRITICALCVSS 9.8EG 9.82023-12-07
An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versio…
- CVE-2023-5099HIGHCVSS 8.8EG 8.82023-10-31
The HTML filter and csv-file search plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7 via the 'src' attribute of the 'csvsearch' shortcode. This allows authenticated attackers, with contributo…
- CVE-2023-5101MEDIUMCVSS 5.3EG 5.32023-10-09
Files or Directories Accessible to External Parties in RDT400 in SICK APU allows an unprivileged remote attacker to download various files from the server via HTTP requests.
- CVE-2023-5199CRITICALCVSS 8.8EG 9.92023-10-30
The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and including, 0.3 via the 'php-to-page' shortcode. This allows authenticated attackers with subscriber-level permissions o…
- CVE-2023-52112MEDIUMCVSS 5.3EG 5.32024-01-16
Unauthorized file access vulnerability in the wallpaper service module. Successful exploitation of this vulnerability may cause features to perform abnormally.
- CVE-2023-5297HIGHCVSS 7.5EG 7.52023-09-29
A vulnerability was found in Xinhu RockOA 2.3.2. It has been classified as problematic. This affects the function start of the file task.php?m=sys|runt&a=beifen. The manipulation leads to exposure of backup file to an unauthorized control …
- CVE-2023-5907MEDIUMCVSS 6.5EG 6.52023-12-11
The File Manager WordPress plugin before 6.3 does not restrict the file managers root directory, allowing an administrator to set a root outside of the WordPress root directory, giving access to system files and directories even in a multi…
- CVE-2023-6114HIGHCVSS 7.5EG 7.52023-12-26
The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup-pro/tmp` directory in the Pro version), which temporarily s…
- CVE-2023-6266HIGHCVSS 7.5EG 7.52024-01-11
The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP case of the handle_downloading function in all versions up to, and including, 1.3.6. This…
- CVE-2023-6375HIGHCVSS 7.5EG 7.52023-11-30
Tyler Technologies Court Case Management Plus may store backups in a location that can be accessed by a remote, unauthenticated attacker. Backups may contain sensitive information such as database credentials.
Map vulnerabilities like CWE-552 to your infrastructure
EchelonGraph correlates every CVE — across CWE-552 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →