CWE-552

Files or Directories Accessible to External Parties

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product makes files or directories accessible to unauthorized actors, even though they should not be.

474 vulnerabilities with CWE-552
CVE-2020-3476 MEDIUM
Cisco IOS XE - Privilege Escalation
CVSS 6.0
CVE-2020-24312 HIGH
WP File Manager <6.4 - Info Disclosure
CVSS 7.5
CVE-2020-11976 HIGH
Apache Wicket <9.0.0-M5 - Info Disclosure
CVSS 7.5
CVE-2020-4075 MEDIUM
Electron <7.2.4-9.0.0-beta21 - Local File Read
CVSS 6.8
CVE-2020-5356 HIGH
Dell PowerProtect <19.4-3.2 - Auth Bypass
CVSS 7.7
CVE-2020-3267 HIGH
Cisco Unified CCX - Privilege Escalation
CVSS 7.1
CVE-2020-10516 CRITICAL
GitHub Enterprise Server <2.21 - Privilege Escalation
CVSS 9.8
CVE-2020-12743 CRITICAL
Gazie 7.9-7.32 - Unauthenticated Arbitrary File Inclusion via setup.php hidden_req Parameter
CVSS 9.8
CVE-2020-12470 HIGH
MonoX < 5.1.40.5152 - Authenticated Remote Code Execution via ASPX Template Modification
CVSS 7.2
CVE-2020-11469 HIGH
Zoom Client for Meetings <4.6.8 - Privilege Escalation
CVSS 7.8
CVE-2020-5289 MEDIUM
Elide < 4.5.14 - Unauthorized Data Access via Filter Expression Side Channel
CVSS 6.8
CVE-2020-5250 HIGH
PrestaShop <1.7.6.4 - Info Disclosure
CVSS 7.6
CVE-2020-10105 MEDIUM
Zammad 3.0-3.2 - Source Code Disclosure via OPTIONS Request
CVSS 5.3
CVE-2020-1726 MEDIUM
Podman <1.6.0 - Privilege Escalation
CVSS 5.9
CVE-2020-3927 HIGH
ServiSign < 1.0.19.0617 - Arbitrary File Access via Crafted API Parameter
CVSS 8.3
CVE-2020-3926 MEDIUM
ServiSign security plugin - Path Traversal
CVSS 6.1
CVE-2019-25709 CRITICAL
CF Image Hosting Script 1.6.5 Unauthorized Database Access
CVSS 9.8
CVE-2019-25239 HIGH
V-SOL GPON/EPON OLT Platform 2.03 - Info Disclosure
CVSS 7.5
CVE-2019-3897 MEDIUM
Red Hat Certification <6-7 - Info Disclosure
CVSS 5.3
CVE-2019-7306 MEDIUM
byobu - Information Disclosure via Apport Hook
CVSS 4.3
CVE-2019-7305 MEDIUM
eXtplorer < 2.1.0 - Information Exposure via World-Accessible System Directories
CVSS 5.8
CVE-2019-20593 MEDIUM
Samsung Mobile <O - Info Disclosure
CVSS 5.3
CVE-2019-20529 HIGH
Frappe 11-12 - Unauthenticated Sensitive Data Exposure via Prepared Report File Storage
CVSS 7.5
CVE-2019-13941 HIGH
OZW Web Server < V10.00 - Info Disclosure
CVSS 7.5
CVE-2019-19843 CRITICAL
Ruckus Wireless Unleashed <200.7.10.102.64 - Info Disclosure
CVSS 9.8
Details
Vulnerabilities 474