CWE-552

Files or Directories Accessible to External Parties

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product makes files or directories accessible to unauthorized actors, even though they should not be.

482 vulnerabilities with CWE-552
CVE-2025-59054 HIGH
dstack < 0.5.4 - Unauthenticated Sensitive Data Exposure via LUKS2 Volume Metadata
CVE-2025-58753 HIGH
Copyparty <1.19.8 - Info Disclosure
CVSS 7.5
CVE-2025-9273 MEDIUM
CData API Server - Authenticated Information Disclosure via MySQL Connection Misconfiguration
CVSS 4.3
CVE-2025-52460 MEDIUM
DOS Co., Ltd. SS1 <= 16.0.0.10 and SS1 Cloud <= 2.1.3 - Unauthenticated Arbitrary File Access
CVSS 5.3
CVE-2025-43758 MEDIUM
Liferay Portal/DXP - Info Disclosure
CVSS 5.3
CVE-2025-51818 MEDIUM
MCCMS 2.7.0 - Arbitrary File Deletion via Backups.php
CVSS 5.4
CVE-2025-43749 MEDIUM
Liferay Portal/DXP - Info Disclosure
CVSS 5.3
CVE-2025-44779 MEDIUM
Ollama < 0.1.34 - Arbitrary File Deletion via /api/pull Endpoint
CVSS 6.6
CVE-2025-23276 HIGH
NVIDIA Installer - Privilege Escalation
CVSS 7.8
CVE-2025-30103 MEDIUM
Dell SmartFabric OS10 <10.6.0.5 - Info Disclosure
CVSS 5.5
CVE-2025-34139 HIGH
Sitecore Experience Manager (XM) 8.0-10.4 - Unauthenticated Arbitrary File Read
CVE-2025-41240 CRITICAL
Bitnami Helm charts - Info Disclosure
CVSS 10.0
CVE-2025-34110 CRITICAL
ColoradoFTP Server < 1.3 Build 8 - Path Traversal
CVE-2025-53536 HIGH
Roo Code <3.22.6 - Command Injection
CVSS 8.1
CVE-2025-49797 HIGH
Multiple Brother, Toshiba Tec, and Ricoh Windows Driver Installers - Privilege Escalation
CVSS 7.8
CVE-2025-0620 MEDIUM
Samba 4.21.0-4.21.5 - Unauthenticated File Share Exposure via Session Reauthentication
CVSS 4.9
CVE-2025-40908 CRITICAL
YAML-LibYAML <0.903.0 - Code Injection
CVSS 9.1
CVE-2025-4634 MEDIUM
Airpointer <2.4.107-2 - Local File Inclusion
CVSS 4.1
CVE-2025-5273 MEDIUM
mcp-markdownify-server - Info Disclosure
CVSS 6.5
CVE-2025-48928 MEDIUM KEV
TeleMessage <2025-05-05 - Info Disclosure
CVSS 4.0
CVE-2025-4134 HIGH
Avast Business Antivirus for Linux <4.5 - Info Disclosure
CVSS 7.3
CVE-2025-45529 HIGH
Siteserver CMS 7.3.1 - Arbitrary File Read via ReadTextAsynchronous Function
CVSS 7.1
CVE-2025-4909 HIGH
SourceCodester Client DBMS 1.0 - Info Disclosure
CVSS 7.3
CVE-2025-4807 MEDIUM
SourceCodester Online Student Clearance System 1.0 - Info Disclosure
CVSS 5.3
CVE-2025-21264 HIGH
Visual Studio Code - Info Disclosure
CVSS 7.1
Details
Vulnerabilities 482