CWE-552
Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
482 vulnerabilities with CWE-552
CVE-2026-11841
CRITICAL
Sick AG InspectorP61x - Files or Directories Accessible to External Parties
CVSS 9.4
CVE-2026-57990
HIGH
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVSS 7.4
CVE-2026-15342
MEDIUM
Plane < 1.3.0 - Authenticated Cross-Tenant Data Exposure and Deletion via Asset-Management API
CVSS 6.5
CVE-2026-59703
HIGH
repomix - Local File Inclusion via file:// URL Scheme in Git Clone Endpoint
CVSS 7.5
CVE-2026-13533
MEDIUM
agentejo Cockpit CMS htaccess config.yaml YAMLLoad file access
CVSS 5.3
CVE-2026-40624
CRITICAL
AVer PTC cameras Files or Directories Accessible to External Parties
CVSS 9.8
CVE-2026-45543
MEDIUM
Nextcloud Forms 4.3.0-5.2.6 - Unauthorized Read Access to Uploaded Respondent Files
CVSS 5.3
CVE-2026-40425
MEDIUM
MacGregor Voyage Data Recorder (VDR) G4e Files or Directories Accessible to External Parties
CVSS 5.7
CVE-2026-45088
HIGH
Dalfox: Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file` in Dalfox Server Mode
CVSS 7.5
CVE-2026-45721
CRITICAL
Algernon: handler.lua discovery walks parent directories above the server root
CVSS 9.0
CVE-2026-40564
MEDIUM
Apache Flink Kubernetes Operator: Server-Side Request Forgery and local file access in Kubernetes Operator
CVSS 6.5
CVE-2026-8704
MEDIUM
Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified
CVSS 6.5
CVE-2026-33380
MEDIUM
Grafana OSS Arbitrary File Read via SQL Expressions
CVSS 6.3
CVE-2026-42063
MEDIUM
F5 BIG-IP 16.1.0-21.1.0 - Authenticated Sensitive File Download via iControl SOAP
CVSS 4.9
CVE-2026-40631
HIGH
F5 BIG-IP 21.1.0-21.0.0.2 Authenticated Privilege Escalation via iControl SOAP
CVSS 8.7
CVE-2026-35440
MEDIUM
Microsoft Word Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-32185
MEDIUM
Microsoft Teams Spoofing Vulnerability
CVSS 5.5
CVE-2026-31216
CRITICAL
nexent v1.7.5.2 - Unauthenticated File Deletion
CVSS 9.1
CVE-2026-31215
CRITICAL
nexent v1.7.5.2 - Arbitrary File Deletion
CVSS 9.1
CVE-2026-39871
HIGH
macOS - Information Disclosure
CVSS 7.5
CVE-2026-7817
MEDIUM
pgAdmin 4: Local file inclusion and server-side request forgery in LLM API configuration endpoints
CVSS 6.5
CVE-2026-6418
MEDIUM
PaperCut NG/MF: Path Traversal in Shared Account Synchronization
CVSS 4.9
CVE-2026-5335
MEDIUM
Magic Export & Import < 1.2.0 - Unauthenticated PII Disclosure
CVSS 5.3
CVE-2026-40484
CRITICAL
ChurchCRM: Authenticated Remote Code Execution via Unrestricted PHP File Write in Database Restore Function
CVSS 9.1
CVE-2026-33698
CRITICAL
Chamilo LMS affected by unauthenticated RCE in main/install folder
CVSS 9.8
Details
Vulnerabilities
482