CWE-552

Files or Directories Accessible to External Parties

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product makes files or directories accessible to unauthorized actors, even though they should not be.

434 vulnerabilities with CWE-552
CVE-2018-25164 HIGH
EverSync 0.5 - Info Disclosure
CVSS 7.5
CVE-2026-2331 CRITICAL
AppEngine Fileaccess - Info Disclosure
CVSS 9.8
CVE-2026-2330 CRITICAL
CROWN REST Interface - Path Traversal
CVSS 9.4
CVE-2026-24732
BlueSpice 5.1-5.1.3/5.2-5.2.0 - Auth Bypass
CVE-2026-25231 HIGH
FileRise <3.3.0 - Info Disclosure
CVSS 7.5
CVE-2020-37082 CRITICAL
webERP 4.15.1 - Info Disclosure
CVSS 9.8
CVE-2025-69875 HIGH
Quickheal Total Security - Privilege Escalation
CVSS 7.8
CVE-2026-25137 CRITICAL
NixOs Odoo <25.11-26.05 - Info Disclosure
CVSS 9.1
CVE-2025-37177 MEDIUM
Mobility Conductor - File Deletion
CVSS 6.5
CVE-2025-37168 HIGH
Mobility Conductors <AOS-8 - Privilege Escalation
CVSS 8.2
CVE-2025-69990 CRITICAL
phpgurukul News Portal Project V4.1 - Info Disclosure
CVSS 9.1
CVE-2025-66689 MEDIUM
Zen MCP Server <9.8.2 - Path Traversal
CVSS 6.5
CVE-2025-68719 HIGH
KAYSUS KS-WR3600 <1.0.5.9.1 - Info Disclosure
CVSS 8.8
CVE-2025-12648 MEDIUM
WP-Members Membership Plugin <3.5.4.4 - Info Disclosure
CVSS 5.3
CVE-2025-15065 MEDIUM
Kings Information & Network Co. KESS Enterprise <*.25.9.19.exe - Pr...
CVSS 6.3
CVE-2025-15153 LOW
PbootCMS <3.2.12 - Info Disclosure
CVSS 3.7
CVE-2019-25239 HIGH
V-SOL GPON/EPON OLT Platform 2.03 - Info Disclosure
CVSS 7.5
CVE-2018-25145 MEDIUM
Microhard Systems IPn4G 1.1.0 - Info Disclosure
CVSS 6.5
CVE-2025-14896 HIGH
Vega - Info Disclosure
CVSS 7.5
CVE-2025-68109 CRITICAL
Churchcrm < 6.5.3 - Remote Code Execution
CVSS 9.1
CVE-2025-14697 LOW
Shenzhen Sixun Software Sixun Shanghui Group Business Management Sy...
CVSS 3.7
CVE-2025-14442 MEDIUM
WordPress <4.9.2 - Info Disclosure
CVSS 5.3
CVE-2025-66625 MEDIUM
Umbraco <13.12.0 - Info Disclosure
CVSS 4.9
CVE-2025-12747 MEDIUM
Tainacan plugin - Info Disclosure
CVSS 5.3
CVE-2025-12894 MEDIUM
Import WP - Sensitive Information Exposure
CVSS 5.3
Details
Vulnerabilities 434