CWE-552

Files or Directories Accessible to External Parties

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product makes files or directories accessible to unauthorized actors, even though they should not be.

482 vulnerabilities with CWE-552
CVE-2025-66689 MEDIUM
Zen MCP Server <9.8.2 - Path Traversal
CVSS 6.5
CVE-2025-68719 HIGH
KAYSUS KS-WR3600 <1.0.5.9.1 - Info Disclosure
CVSS 8.8
CVE-2025-12648 MEDIUM
WP-Members Membership Plugin <3.5.4.4 - Info Disclosure
CVSS 5.3
CVE-2025-15065 MEDIUM
Kings Information & Network Co. KESS Enterprise <*.25.9.19.exe - Pr...
CVSS 6.3
CVE-2025-15153 LOW
pbootcms < 3.2.12 - Direct Request Access to SQLite Database File
CVSS 3.7
CVE-2025-14896 HIGH
kroki - Server-Side Request Forgery via Vega Diagram Specification
CVSS 7.5
CVE-2025-68109 CRITICAL
ChurchCRM < 6.5.3 - Remote Code Execution via Database Restore File Upload
CVSS 9.1
CVE-2025-14697 LOW
Shenzhen Sixun Software Sixun Shanghui Group Business Management Sy...
CVSS 3.7
CVE-2025-14442 MEDIUM
Secure Copy <= 4.9.2 - Unauthenticated Sensitive Information Exposure via CSV Export
CVSS 5.3
CVE-2025-66625 MEDIUM
Umbraco CMS 10.0.0-13.12.0 - Authenticated Arbitrary File Existence Enumeration via Dictionary Upload
CVSS 4.9
CVE-2025-12747 MEDIUM
Tainacan < 1.0.0 - Unauthenticated Information Exposure via Private File Access
CVSS 5.3
CVE-2025-12894 MEDIUM
Import WP - Sensitive Information Exposure
CVSS 5.3
CVE-2025-64185 MEDIUM
Open OnDemand <4.0.8-3.1.16 - Info Disclosure
CVE-2025-13225 MEDIUM
Tanium TanOS 1.8.4.0000 through 1.8.4.0229 - Arbitrary File Deletion
CVSS 5.6
CVE-2025-13200 MEDIUM
SourceCodester Farm Management System 1.0 - Info Disclosure
CVSS 5.3
CVE-2025-11959 HIGH
Premierturk Information Technologies Inc. Excavation Management Inf...
CVSS 8.1
CVE-2025-33150 MEDIUM
IBM Cognos Analytics Certified Containers 12.1.0 - Info Disclosure
CVSS 5.3
CVE-2025-58152 MEDIUM
FutureNet MA/IP-K - Info Disclosure
CVSS 5.3
CVE-2025-11965 HIGH
Eclipse Vert.x <4.5.21 & <5.0.4 - Info Disclosure
CVSS 7.5
CVE-2025-31996 MEDIUM
HCL Unica Platform - Info Disclosure
CVSS 5.3
CVE-2025-11371 HIGH KEV
Gladinet CentreStack/Triofox Path Traversal
CVSS 7.5
CVE-2025-59976 MEDIUM
Juniper Networks Junos Space <24.1R3 - File Download
CVSS 6.5
CVE-2025-61734 HIGH
Apache Kylin <5.0.2 - Info Disclosure
CVSS 7.5
CVE-2025-37130 MEDIUM
EdgeConnect SD-WAN - Info Disclosure
CVSS 6.5
CVE-2025-3025 HIGH
Gen Digital CCleaner <6.36.11508 - Privilege Escalation
CVSS 7.3
Details
Vulnerabilities 482