CWE-552
Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
474 vulnerabilities with CWE-552
CVE-2026-4532
MEDIUM
code-projects Simple Food Ordering System Database Backup food.sql file access
CVSS 5.3
CVE-2026-33071
MEDIUM
FileRise: WebDAV upload path bypasses filename validation enforced by regular uploads
CVSS 4.3
CVE-2026-32750
MEDIUM
SiYuan importStdMd: unvalidated localPath imports arbitrary host directories as persistent notes
CVSS 6.8
CVE-2026-29066
MEDIUM
ssw/tinacms/cli < 2.1.8 - Unauthenticated Arbitrary File Read via Vite Dev Server Misconfiguration
CVSS 6.2
CVE-2026-2331
CRITICAL
AppEngine Fileaccess - Info Disclosure
CVSS 9.8
CVE-2026-2330
CRITICAL
CROWN REST Interface - Path Traversal
CVSS 9.4
CVE-2026-24732
MEDIUM
BlueSpice 5.1-5.1.3/5.2-5.2.0 - Auth Bypass
CVE-2026-25231
HIGH
filerise < 3.3.0 - Unauthenticated File Read via /uploads Directory
CVSS 7.5
CVE-2026-25137
CRITICAL
NixOs Odoo <25.11-26.05 - Info Disclosure
CVSS 9.1
CVE-2025-14771
CRITICAL
File Disclosure in ABB T-MAC Plus web application and in ABB T-MAC plus Server - Default IIS Web Site
CVSS 9.9
CVE-2025-69428
HIGH
Pro-Bit < 1.77.4 - Unauthenticated Sensitive Directory Access
CVSS 7.5
CVE-2025-7389
HIGH
Unauthorized Arbitrary File Read via RMI in AdminServer Interface
CVE-2025-66955
MEDIUM
Asseco SEE Live 2.0 - Path Traversal
CVSS 6.5
CVE-2025-69875
HIGH
Quick Heal Total Security 23.0.0 - Privilege Escalation via Quarantine Restore Path Manipulation
CVSS 7.8
CVE-2025-37177
MEDIUM
ArubaOS 6.5.4.0-8.10.0.21 - Authenticated Arbitrary File Deletion via Command-Line Interface
CVSS 6.5
CVE-2025-37168
HIGH
Mobility Conductors <AOS-8 - Privilege Escalation
CVSS 8.2
CVE-2025-69990
CRITICAL
phpgurukul News Portal Project V4.1 - Info Disclosure
CVSS 9.1
CVE-2025-66689
MEDIUM
Zen MCP Server <9.8.2 - Path Traversal
CVSS 6.5
CVE-2025-68719
HIGH
KAYSUS KS-WR3600 <1.0.5.9.1 - Info Disclosure
CVSS 8.8
CVE-2025-12648
MEDIUM
WP-Members Membership Plugin <3.5.4.4 - Info Disclosure
CVSS 5.3
CVE-2025-15065
MEDIUM
Kings Information & Network Co. KESS Enterprise <*.25.9.19.exe - Pr...
CVSS 6.3
CVE-2025-15153
LOW
pbootcms < 3.2.12 - Direct Request Access to SQLite Database File
CVSS 3.7
CVE-2025-14896
HIGH
kroki - Server-Side Request Forgery via Vega Diagram Specification
CVSS 7.5
CVE-2025-68109
CRITICAL
ChurchCRM < 6.5.3 - Remote Code Execution via Database Restore File Upload
CVSS 9.1
CVE-2025-14697
LOW
Shenzhen Sixun Software Sixun Shanghui Group Business Management Sy...
CVSS 3.7
Details
Vulnerabilities
474