CWE-552
Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
483 vulnerabilities with CWE-552
CVE-2022-4236
MEDIUM
Welcart e-Commerce <2.8.5 - Info Disclosure
CVSS 6.5
CVE-2022-45426
MEDIUM
Dahua DSS Express and DSS Professional - Unauthenticated Arbitrary File Download via Crafted Packet
CVSS 6.5
CVE-2022-28283
MEDIUM
Firefox < 99.0 - Unauthenticated Arbitrary File Read via DevTools sourceMapURL
CVSS 6.5
CVE-2022-4106
HIGH
WooCommerce <1.0.7 - Unauthenticated RCE
CVSS 7.5
CVE-2022-45227
HIGH
Dragino Lora LG01 18ed40 IoT <4.3.4 - Path Traversal
CVSS 7.5
CVE-2022-44356
HIGH
WAVLINK Quantum D4G - Info Disclosure
CVSS 7.5
CVE-2022-3691
HIGH
WordPress Plugin <1.7.5 - Info Disclosure
CVSS 7.5
CVE-2022-44634
MEDIUM
S2W - Import Shopify to WooCommerce <1.1.12 - Info Disclosure
CVSS 4.9
CVE-2022-44583
HIGH
WatchTowerHQ <3.6.15 - Info Disclosure
CVSS 7.5
CVE-2022-45129
HIGH
Payara <2022-11-04 - Info Disclosure
CVSS 7.5
CVE-2022-43449
MEDIUM
OpenHarmony <v3.1.2 - Info Disclosure
CVSS 6.2
CVE-2022-41710
MEDIUM
Markdownify 1.4.1 - Info Disclosure
CVSS 5.5
CVE-2022-23738
MEDIUM
GitHub Enterprise Server < 3.2.20 - Unauthorized Private Repository File Access via Cache Key Manipulation
CVSS 5.7
CVE-2022-37424
MEDIUM
OpenNebula <Linux - Info Disclosure
CVSS 6.5
CVE-2022-43414
MEDIUM
Jenkins NUnit Plugin <0.27 - Info Disclosure
CVSS 5.3
CVE-2022-2834
MEDIUM
Helpful WP <4.5.26 - Info Disclosure
CVSS 5.3
CVE-2022-42234
HIGH
UCMS 1.6 - File Inclusion in Template Management Module
CVSS 8.8
CVE-2022-2981
MEDIUM
WordPress Download Monitor <4.5.98 - Privilege Escalation
CVSS 4.9
CVE-2022-40126
HIGH
Clash for Windows <0.19.9 - Privilege Escalation
CVSS 7.8
CVE-2022-3287
MEDIUM
fwupd < 1.8.5 - Unauthenticated Sensitive Information Exposure via Redfish Plugin Configuration
CVSS 6.5
CVE-2022-41343
HIGH
dompdf < 2.0.1 - Remote File Inclusion via @font-face Rule
CVSS 7.5
CVE-2022-39208
HIGH
OneDev < 7.3.0 - Unauthenticated Arbitrary File Read via Project Directory Exposure
CVSS 7.5
CVE-2022-36552
HIGH
Tenda AC6 Firmware < 02.03.01.114 - Unauthenticated Arbitrary File Read via DownloadFlash Endpoint
CVSS 7.5
CVE-2022-1117
HIGH
fapolicyd 1.1.2 - Runtime Linker Detection Bypass Allows Execution
CVSS 8.4
CVE-2022-35235
MEDIUM
XplodedThemes WPide <2.6 - Info Disclosure
CVSS 4.9
Details
Vulnerabilities
483