CWE-552

Files or Directories Accessible to External Parties

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product makes files or directories accessible to unauthorized actors, even though they should not be.

474 vulnerabilities with CWE-552
CVE-2026-45543 MEDIUM
Nextcloud Forms 4.3.0-5.2.6 - Unauthorized Read Access to Uploaded Respondent Files
CVSS 5.3
CVE-2026-40425 MEDIUM
MacGregor Voyage Data Recorder (VDR) G4e Files or Directories Accessible to External Parties
CVSS 5.7
CVE-2026-45088 HIGH
Dalfox: Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file` in Dalfox Server Mode
CVSS 7.5
CVE-2026-45721 CRITICAL
Algernon: handler.lua discovery walks parent directories above the server root
CVSS 9.0
CVE-2026-40564 MEDIUM
Apache Flink Kubernetes Operator: Server-Side Request Forgery and local file access in Kubernetes Operator
CVSS 6.5
CVE-2026-8704 MEDIUM
Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified
CVSS 6.5
CVE-2026-33380 MEDIUM
Grafana OSS Arbitrary File Read via SQL Expressions
CVSS 6.3
CVE-2026-42063 MEDIUM
F5 BIG-IP 16.1.0-21.1.0 - Authenticated Sensitive File Download via iControl SOAP
CVSS 4.9
CVE-2026-40631 HIGH
F5 BIG-IP 21.1.0-21.0.0.2 Authenticated Privilege Escalation via iControl SOAP
CVSS 8.7
CVE-2026-35440 MEDIUM
Microsoft Word Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-32185 MEDIUM
Microsoft Teams Spoofing Vulnerability
CVSS 5.5
CVE-2026-31216 CRITICAL
nexent v1.7.5.2 - Unauthenticated File Deletion
CVSS 9.1
CVE-2026-31215 CRITICAL
nexent v1.7.5.2 - Arbitrary File Deletion
CVSS 9.1
CVE-2026-39871 HIGH
macOS - Information Disclosure
CVSS 7.5
CVE-2026-7817 MEDIUM
pgAdmin 4: Local file inclusion and server-side request forgery in LLM API configuration endpoints
CVSS 6.5
CVE-2026-6418 MEDIUM
PaperCut NG/MF: Path Traversal in Shared Account Synchronization
CVSS 4.9
CVE-2026-5335 MEDIUM
Magic Export & Import < 1.2.0 - Unauthenticated PII Disclosure
CVSS 5.3
CVE-2026-40484 CRITICAL
ChurchCRM: Authenticated Remote Code Execution via Unrestricted PHP File Write in Database Restore Function
CVSS 9.1
CVE-2026-33698 CRITICAL
Chamilo LMS affected by unauthenticated RCE in main/install folder
CVSS 9.8
CVE-2026-35446 HIGH
LORIS FilesDownloadHandler - Path Traversal
CVSS 7.7
CVE-2026-35169 HIGH
LORIS has potential cross-site scripting in help_editor module
CVSS 8.7
CVE-2026-34392 HIGH
LORIS Static File Router - Path Traversal
CVSS 7.5
CVE-2026-34361 CRITICAL
HAPI FHIR: Unauthenticated SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token Theft
CVSS 9.3
CVE-2026-4900 MEDIUM
code-projects Online Food Ordering System localhost.sql privilege escalation
CVSS 5.3
CVE-2026-4760 HIGH
Potential unauthorized access to files on the Web HMI server host
Details
Vulnerabilities 474