CWE-552

Files or Directories Accessible to External Parties

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product makes files or directories accessible to unauthorized actors, even though they should not be.

483 vulnerabilities with CWE-552
CVE-2023-31064 HIGH
Apache InLong <1.7.0 - Info Disclosure
CVSS 7.5
CVE-2023-20184 MEDIUM
Cisco Catalyst Center < 2.2.3.5 - Authenticated Arbitrary Command Execution in Restricted Container
CVSS 5.4
CVE-2023-20183 MEDIUM
Cisco DNA Center - Privilege Escalation
CVSS 5.4
CVE-2023-2766 MEDIUM
Weaver e-office 9.5 - Files or Directories Accessible to External Parties in jx2_config.ini
CVSS 5.3
CVE-2023-29820 MEDIUM
Webroot SecureAnywhere Endpoint Protection CE <23.1 v.9.0.33.39 - I...
CVSS 5.5
CVE-2023-29107 MEDIUM
SIMATIC Cloud Connect 7 - Info Disclosure
CVSS 5.3
CVE-2023-27180 HIGH
GDidees CMS v3.9.1 - Info Disclosure
CVSS 7.5
CVE-2023-1124 HIGH
Shopping Cart & eCommerce Store <5.4.3 - Local File Inclusion
CVSS 7.2
CVE-2023-28375 HIGH
Osprey Pump Controller 1.01 - Info Disclosure
CVSS 7.5
CVE-2023-25260 HIGH
Stimulsoft Designer (Web) 2023.1.3 - Local File Inclusion
CVSS 7.5
CVE-2023-23330 HIGH
amano Xparc parking solutions <7.1.3879 - Local File Inclusion
CVSS 7.5
CVE-2023-1246 HIGH
Saysis Starcities <=1.3 - Info Disclosure
CVSS 7.5
CVE-2023-26948 HIGH
onekeyadmin <1.3.9 - Info Disclosure
CVSS 7.5
CVE-2023-26956 HIGH
onekeyadmin <1.3.9 - Info Disclosure
CVSS 7.5
CVE-2023-22858 MEDIUM
BlogEngine.NET 3.3.8.0 - Info Disclosure
CVSS 5.3
CVE-2023-22974 HIGH
OpenEMR < 7.0.0 - Unauthenticated Path Traversal via setup.php MySQL Connection
CVSS 7.5
CVE-2023-0822 HIGH
DIAEnergie <1.9.03.001 - Auth Bypass
CVSS 8.8
CVE-2022-42834 LOW
macOS 11.0-11.7.2 - Unprotected Mail Attachment Exposure via Temporary Compression Directory
CVSS 3.3
CVE-2022-45450 HIGH
Acronis Agent < 28610 and Cyber Protect 15 < 30984 - Sensitive Information Disclosure and Manipulation
CVSS 7.5
CVE-2022-44343 HIGH
CRMEB 4.4.4 - Arbitrary File Download
CVSS 7.5
CVE-2022-48094 MEDIUM
lmxcms v1.41 - Arbitrary File Read via TemplateAction.class.php
CVSS 4.9
CVE-2022-48161 HIGH
Easy Images 2.0 - Arbitrary File Download via /application/down.php
CVSS 7.5
CVE-2022-47950 MEDIUM
OpenStack Swift <2.28.1-2.30.0 - Info Disclosure
CVSS 6.5
CVE-2022-23508 HIGH
Weave GitOps - Privilege Escalation
CVSS 8.8
CVE-2022-45052 HIGH
Axiell Iguana CMS 4.0.0-4.5.02 - Local File Inclusion via Proxy.type.php URL Parameter
CVSS 8.8
Details
Vulnerabilities 483