CWE-552
Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
483 vulnerabilities with CWE-552
CVE-2022-26271
HIGH
74cms v3.4.1 - Arbitrary File Read via Download Controller URL Parameter
CVSS 7.5
CVE-2022-24075
MEDIUM
Whale Browser <3.12.129.18 - Info Disclosure
CVSS 6.5
CVE-2022-25497
MEDIUM
CuppaCMS 1.0 - Arbitrary File Read via Copy Function
CVSS 5.3
CVE-2022-23377
HIGH
Archeevo <5.0 - Local File Inclusion
CVSS 7.5
CVE-2022-25104
HIGH
HorizontCMS v1.0.0-beta.2 - Info Disclosure
CVSS 7.5
CVE-2022-25297
HIGH
drogonframework/drogon <1.7.5 - Path Traversal
CVSS 7.5
CVE-2022-25299
CRITICAL
cesanta/mongoose <7.6 - Path Traversal
CVSS 9.8
CVE-2022-23621
MEDIUM
XWiki < 12.10.9, 13.4.3, >=13.6-rc-1 <13.7-rc-1 - Arbitrary File Read via XWiki#invokeServletAndReturnAsString
CVSS 5.5
CVE-2022-24694
MEDIUM
Mahara <20.10.4-21.04.3-21.10.1 - Info Disclosure
CVSS 4.3
CVE-2022-23316
MEDIUM
taoCMS 3.0.2 - Unauthenticated Arbitrary File Read via Admin Download Path Parameter
CVSS 4.9
CVE-2022-21236
HIGH
Reolink RLC-410W Firmware 3.0.0.136_20121102 - Information Disclosure via Web Server Misconfiguration
CVSS 7.5
CVE-2022-0244
HIGH
GitLab CE/EE <14.5 - Info Disclosure
CVSS 8.6
CVE-2022-22270
MEDIUM
Dialer <SMR Jan-2022 Release 1 - Info Disclosure
CVSS 4.4
CVE-2022-22269
MEDIUM
Keeping sensitive data - Info Disclosure
CVSS 4.0
CVE-2022-22268
MEDIUM
Samsung Knox Guard <SMR Jan-2022 Release 1 - Privilege Escalation
CVSS 6.1
CVE-2022-22267
MEDIUM
ActivityMetricsLogger <SMR Jan-2022 Release 1 - Info Disclosure
CVSS 4.0
CVE-2021-47960
MEDIUM
Synology SSL VPN Client < 1.4.5-0684 - Information Disclosure via Local HTTP Server
CVSS 6.5
CVE-2021-4474
MEDIUM
Ruckus AP CLI Arbitrary File Read Allows Authenticated Remote File Access
CVSS 4.9
CVE-2021-4463
HIGH
Longjing Technology BEMS API <=1.21 - Info Disclosure
CVE-2021-3856
MEDIUM
Keycloak < 15.1.0 - Unauthenticated Arbitrary File Read via Theme Resource Path Traversal
CVSS 4.3
CVE-2021-4112
HIGH
Ansible-Tower - Privilege Escalation
CVSS 8.8
CVE-2021-3996
MEDIUM
util-linux 2.34-2.37.2 - Unauthenticated Filesystem Unmount via libmount Logic Error
CVSS 5.5
CVE-2021-3995
MEDIUM
util-linux 2.34-2.37.2 - Unprivileged FUSE Filesystem Unmount via UID Prefix Match
CVSS 5.5
CVE-2021-3800
MEDIUM
glib < 2.63.6 - Information Disclosure via Charset Alias
CVSS 5.5
CVE-2021-40150
HIGH
E1 Zoom camera <3.0.0.716 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities
483