CWE-552
Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
474 vulnerabilities with CWE-552
CVE-2022-2222
MEDIUM
WordPress Download Monitor <4.5.91 - Info Disclosure
CVSS 4.9
CVE-2022-33686
LOW
GsmAlarmManager <SMR Jul-2022 Release 1 - Info Disclosure
CVSS 2.3
CVE-2022-34464
MEDIUM
SICAM GridEdge (Classic) < V2.7.3 - Code Injection
CVSS 6.3
CVE-2022-24138
HIGH
IOBit Advanced System Care 15 - Code Injection
CVSS 7.8
CVE-2022-32143
HIGH
CODESYS PLCWinNT & Runtime Toolkit 2.0-2.4.7.57 - Unauthenticated Arbitrary File Access
CVSS 8.8
CVE-2022-29720
HIGH
74cmsse v3.5.1 - Arbitrary File Read via Download.php
CVSS 7.5
CVE-2022-30428
HIGH
Ginadmin <05-10-2022 - Info Disclosure
CVSS 7.5
CVE-2022-29447
MEDIUM
Wow-Company's Hover Effects <2.1 - LFI
CVSS 6.8
CVE-2022-29446
MEDIUM
Wow-Company's Counter Box <1.1.1 - LFI
CVSS 6.8
CVE-2022-29302
MEDIUM
SolarView Compact 6.00 - Info Disclosure
CVSS 5.5
CVE-2022-28462
HIGH
novel-plus 3.6.0 - Arbitrary File Read
CVSS 7.5
CVE-2022-0656
HIGH
The Web To Print Shop : uDraw WordPress plugin <3.3.3 - Info Disclo...
CVSS 7.5
CVE-2022-28445
MEDIUM
kitecms 1.1.1 - Arbitrary File Read via Background Management Module
CVSS 6.5
CVE-2022-27837
MEDIUM
Android R-13 - Privilege Escalation
CVSS 4.4
CVE-2022-26877
MEDIUM
Asana Desktop <1.6.0 - Info Disclosure
CVSS 6.5
CVE-2022-28002
HIGH
Movie Seat Reservation v1 - Info Disclosure
CVSS 7.5
CVE-2022-26271
HIGH
74cms v3.4.1 - Arbitrary File Read via Download Controller URL Parameter
CVSS 7.5
CVE-2022-24075
MEDIUM
Whale Browser <3.12.129.18 - Info Disclosure
CVSS 6.5
CVE-2022-25497
MEDIUM
CuppaCMS 1.0 - Arbitrary File Read via Copy Function
CVSS 5.3
CVE-2022-23377
HIGH
Archeevo <5.0 - Local File Inclusion
CVSS 7.5
CVE-2022-25104
HIGH
HorizontCMS v1.0.0-beta.2 - Info Disclosure
CVSS 7.5
CVE-2022-25297
HIGH
drogonframework/drogon <1.7.5 - Path Traversal
CVSS 7.5
CVE-2022-25299
CRITICAL
cesanta/mongoose <7.6 - Path Traversal
CVSS 9.8
CVE-2022-23621
MEDIUM
XWiki < 12.10.9, 13.4.3, >=13.6-rc-1 <13.7-rc-1 - Arbitrary File Read via XWiki#invokeServletAndReturnAsString
CVSS 5.5
CVE-2022-24694
MEDIUM
Mahara <20.10.4-21.04.3-21.10.1 - Info Disclosure
CVSS 4.3
Details
Vulnerabilities
474