CWE-552

Files or Directories Accessible to External Parties

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product makes files or directories accessible to unauthorized actors, even though they should not be.

474 vulnerabilities with CWE-552
CVE-2021-43821 CRITICAL
Opencast <9.10-10.6 - Path Traversal
CVSS 9.9
CVE-2021-25521 MEDIUM
Samsung Internet <16.0.2 - Info Disclosure
CVSS 4.0
CVE-2021-31850 MEDIUM
McAfee Database Security < 4.8.4 - Authenticated Denial of Service and Arbitrary File Write via Archiving Configuration
CVSS 6.1
CVE-2021-43772 MEDIUM
Trend Micro Security <2021-17.0 - Info Disclosure
CVSS 5.5
CVE-2021-42744 MEDIUM
Philips MRI 1.5T and 3T 5.3-5.8.1 - Unauthorized Resource Access
CVSS 5.5
CVE-2021-31600 MEDIUM
Hitachi Vantara Pentaho <9.1 - Info Disclosure
CVSS 4.3
CVE-2021-35203 MEDIUM
NETSCOUT Systems nGeniusONE <6.3.0 - Info Disclosure
CVSS 5.7
CVE-2021-41573 HIGH
Hitachi Content Platform Anywhere >=4.4.5 - Authenticated Information Disclosure via Expired File Share Links
CVSS 7.5
CVE-2021-22015 HIGH
VMware Cloud Foundation 3.0-5.0 and vCenter Server - Local Privilege Escalation via Improper File Permissions
CVSS 7.8
CVE-2021-25741 HIGH
Kubernetes < 1.19.14 - Unauthenticated Files or Directories Accessible via Subpath Volume Mounts
CVSS 8.8
CVE-2021-32833 HIGH
Emby Server <4.6.4.0 - Info Disclosure
CVSS 8.6
CVE-2021-34765 MEDIUM
Cisco Nexus Insights - Info Disclosure
CVSS 4.3
CVE-2021-36233 MEDIUM
MIK.starlight 7.9.5.24363 - Info Disclosure
CVSS 6.5
CVE-2021-39316 HIGH
Zoomsounds <= 6.45 - Unauthenticated Arbitrary File Read via dzsap_download Action
CVSS 7.5
CVE-2021-38711 HIGH
gitit < 0.15.0.0 - Information Disclosure via Export Feature
CVSS 7.5
CVE-2021-37348 HIGH
Nagios XI < 5.8.5 - Local File Inclusion via index.php
CVSS 7.5
CVE-2021-29969 MEDIUM
Thunderbird <78.12 - Info Disclosure
CVSS 5.9
CVE-2021-36763 HIGH
CODESYS V3 <3.5.17.10 - Info Disclosure
CVSS 7.5
CVE-2021-32688 HIGH
Nextcloud Server <19.0.13, <20.0.11, <21.0.3 - Privilege Escalation
CVSS 8.8
CVE-2021-32752 HIGH
Craft 3 <3.0.4 - Privilege Escalation
CVSS 7.2
CVE-2021-22769 MEDIUM
Easergy T300 <V2.7.1 - Info Disclosure
CVSS 4.3
CVE-2021-33359 HIGH
gowitness < 2.3.6 - Unauthenticated Arbitrary File Read via URL Parameter
CVSS 7.5
CVE-2021-31831 MEDIUM
McAfee DBSec <4.8.2 - Info Disclosure
CVSS 4.9
CVE-2021-29024 HIGH
InvoicePlane 1.5.11 - Unauthenticated Directory Traversal and Arbitrary File Download
CVSS 7.5
CVE-2021-1512 MEDIUM
Cisco SD-WAN Software - Command Injection
CVSS 6.0
Details
Vulnerabilities 474