CWE-552

Files or Directories Accessible to External Parties

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product makes files or directories accessible to unauthorized actors, even though they should not be.

483 vulnerabilities with CWE-552
CVE-2020-1908 MEDIUM
WhatsApp <2.20.100 - Privilege Escalation
CVSS 4.6
CVE-2020-26183 MEDIUM
Dell EMC NetWorker <19.3.0.2 - Privilege Escalation
CVSS 6.8
CVE-2020-26182 MEDIUM
Dell EMC NetWorker <19.3.0.2 - Privilege Escalation
CVSS 6.8
CVE-2020-11642 HIGH
B&R SiteManager <9.2.620236042 - DoS
CVSS 7.7
CVE-2020-11641 HIGH
B&R SiteManager <9.2.620236042 - Info Disclosure
CVSS 7.7
CVE-2020-15224 MEDIUM
Open Enclave <0.12.0 - Info Disclosure
CVSS 6.8
CVE-2020-15175 HIGH
GLPI < 9.5.2 - Unauthenticated Arbitrary File Deletion and Information Disclosure via pluginimage.send.php
CVSS 7.4
CVE-2020-25636 MEDIUM
Ansible - Unauthenticated Arbitrary File Write via AWS SSM Connection Plugin
CVSS 6.6
CVE-2020-13953 MEDIUM
Apache Tapestry <5.5.0 - Info Disclosure
CVSS 5.3
CVE-2020-3476 MEDIUM
Cisco IOS XE - Privilege Escalation
CVSS 6.0
CVE-2020-24312 HIGH
WP File Manager <6.4 - Info Disclosure
CVSS 7.5
CVE-2020-11976 HIGH
Apache Wicket <9.0.0-M5 - Info Disclosure
CVSS 7.5
CVE-2020-4075 MEDIUM
Electron <7.2.4-9.0.0-beta21 - Local File Read
CVSS 6.8
CVE-2020-5356 HIGH
Dell PowerProtect <19.4-3.2 - Auth Bypass
CVSS 7.7
CVE-2020-3267 HIGH
Cisco Unified CCX - Privilege Escalation
CVSS 7.1
CVE-2020-10516 CRITICAL
GitHub Enterprise Server <2.21 - Privilege Escalation
CVSS 9.8
CVE-2020-12743 CRITICAL
Gazie 7.9-7.32 - Unauthenticated Arbitrary File Inclusion via setup.php hidden_req Parameter
CVSS 9.8
CVE-2020-12470 HIGH
MonoX < 5.1.40.5152 - Authenticated Remote Code Execution via ASPX Template Modification
CVSS 7.2
CVE-2020-11469 HIGH
Zoom Client for Meetings <4.6.8 - Privilege Escalation
CVSS 7.8
CVE-2020-5289 MEDIUM
Elide < 4.5.14 - Unauthorized Data Access via Filter Expression Side Channel
CVSS 6.8
CVE-2020-5250 HIGH
PrestaShop <1.7.6.4 - Info Disclosure
CVSS 7.6
CVE-2020-10105 MEDIUM
Zammad 3.0-3.2 - Source Code Disclosure via OPTIONS Request
CVSS 5.3
CVE-2020-1726 MEDIUM
Podman <1.6.0 - Privilege Escalation
CVSS 5.9
CVE-2020-3927 HIGH
ServiSign < 1.0.19.0617 - Arbitrary File Access via Crafted API Parameter
CVSS 8.3
CVE-2020-3926 MEDIUM
ServiSign security plugin - Path Traversal
CVSS 6.1
Details
Vulnerabilities 483