CWE-552
Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
474 vulnerabilities with CWE-552
CVE-2025-23276
HIGH
NVIDIA Installer - Privilege Escalation
CVSS 7.8
CVE-2025-30103
MEDIUM
Dell SmartFabric OS10 <10.6.0.5 - Info Disclosure
CVSS 5.5
CVE-2025-34139
HIGH
Sitecore Experience Manager (XM) 8.0-10.4 - Unauthenticated Arbitrary File Read
CVE-2025-41240
CRITICAL
Bitnami Helm charts - Info Disclosure
CVSS 10.0
CVE-2025-34110
CRITICAL
ColoradoFTP Server < 1.3 Build 8 - Path Traversal
CVE-2025-53536
HIGH
Roo Code <3.22.6 - Command Injection
CVSS 8.1
CVE-2025-49797
HIGH
Multiple Brother, Toshiba Tec, and Ricoh Windows Driver Installers - Privilege Escalation
CVSS 7.8
CVE-2025-0620
MEDIUM
Samba 4.21.0-4.21.5 - Unauthenticated File Share Exposure via Session Reauthentication
CVSS 4.9
CVE-2025-40908
CRITICAL
YAML-LibYAML <0.903.0 - Code Injection
CVSS 9.1
CVE-2025-4634
MEDIUM
Airpointer <2.4.107-2 - Local File Inclusion
CVSS 4.1
CVE-2025-5273
MEDIUM
mcp-markdownify-server - Info Disclosure
CVSS 6.5
CVE-2025-48928
MEDIUM
KEV
TeleMessage <2025-05-05 - Info Disclosure
CVSS 4.0
CVE-2025-4134
HIGH
Avast Business Antivirus for Linux <4.5 - Info Disclosure
CVSS 7.3
CVE-2025-45529
HIGH
Siteserver CMS 7.3.1 - Arbitrary File Read via ReadTextAsynchronous Function
CVSS 7.1
CVE-2025-4909
HIGH
SourceCodester Client DBMS 1.0 - Info Disclosure
CVSS 7.3
CVE-2025-4807
MEDIUM
SourceCodester Online Student Clearance System 1.0 - Info Disclosure
CVSS 5.3
CVE-2025-21264
HIGH
Visual Studio Code - Info Disclosure
CVSS 7.1
CVE-2025-32819
HIGH
SonicWall SMA 100/200/210/400/410/500v < 10.2.1.15-81sv Authenticated Arbitrary File Deletion
CVSS 8.8
CVE-2025-1982
HIGH
Ready's Attachment Upload - Path Traversal
CVE-2025-2222
HIGH
Files or Directories Accessible - Info Disclosure
CVSS 7.8
CVE-2025-27147
HIGH
GLPI Inventory Plugin <1.5.0 - Privilege Escalation
CVSS 8.2
CVE-2025-2652
MEDIUM
SourceCodester Employee and Visitor Gate Pass Logging System 1.0 - ...
CVSS 5.3
CVE-2025-2651
MEDIUM
SourceCodester Online Eyewear Shop 1.0 - Info Disclosure
CVSS 5.3
CVE-2025-22369
HIGH
Mennekes Smart/Premium - Info Disclosure
CVE-2025-25267
MEDIUM
Tecnomatix Plant Simulation <V2302.0021, <V2404.0010 - Info Disclosure
CVSS 6.2
Details
Vulnerabilities
474