CWE-552

Files or Directories Accessible to External Parties

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product makes files or directories accessible to unauthorized actors, even though they should not be.

482 vulnerabilities with CWE-552
CVE-2025-32819 HIGH
SonicWall SMA 100/200/210/400/410/500v < 10.2.1.15-81sv Authenticated Arbitrary File Deletion
CVSS 8.8
CVE-2025-1982 HIGH
Ready's Attachment Upload - Path Traversal
CVE-2025-2222 HIGH
Files or Directories Accessible - Info Disclosure
CVSS 7.8
CVE-2025-27147 HIGH
GLPI Inventory Plugin <1.5.0 - Privilege Escalation
CVSS 8.2
CVE-2025-2652 MEDIUM
SourceCodester Employee and Visitor Gate Pass Logging System 1.0 - ...
CVSS 5.3
CVE-2025-2651 MEDIUM
SourceCodester Online Eyewear Shop 1.0 - Info Disclosure
CVSS 5.3
CVE-2025-22369 HIGH
Mennekes Smart/Premium - Info Disclosure
CVE-2025-25267 MEDIUM
Tecnomatix Plant Simulation <V2302.0021, <V2404.0010 - Info Disclosure
CVSS 6.2
CVE-2025-25266 MEDIUM
Tecnomatix Plant Simulation <V2302.0021-V2404.0010 - Info Disclosure
CVSS 6.8
CVE-2025-2147 MEDIUM
Beijing Zhide Intelligent Internet Technology Modern Farm Digital I...
CVSS 5.3
CVE-2025-2038 HIGH
Blood Bank Management System 1.0 - Info Disclosure
CVSS 7.3
CVE-2025-25759 HIGH
SUCMS 1.0 - Path Traversal and Arbitrary File Deletion via admin_template.php
CVSS 7.5
CVE-2025-25799 MEDIUM
SeaCMS 13.3 - Arbitrary File Read via admin_safe.php file_get_contents
CVSS 6.0
CVE-2025-26525 HIGH
Moodle - Arbitrary File Read via TeX Notation Filter
CVSS 8.6
CVE-2025-23421 MEDIUM
Qardio Heart Health iOS <2.7.4 & Android <2.5.1 - Firmware Exposure
CVSS 6.4
CVE-2025-1042 MEDIUM
GitLab EE <17.6.5-17.8.2 - Info Disclosure
CVSS 4.9
CVE-2025-0509 HIGH
Sparkle < 2.6.4 - Unauthenticated Update Replacement via Signature Bypass
CVSS 7.3
CVE-2025-21609 CRITICAL
SiYuan Note <3.1.18 - File Deletion
CVSS 9.1
CVE-2024-56462 HIGH
IBM QRadar SIEM is vulnerable to using components with known vulnerabilities
CVSS 7.2
CVE-2024-11399 MEDIUM
Synology BeeDrive For Desktop < 1.3.2-13814 - Files or Directories Accessible to External Parties
CVSS 6.8
CVE-2024-56731 CRITICAL
Gogs < 0.13.3 - Remote Code Execution via .git Directory File Deletion
CVSS 10.0
CVE-2024-8031 MEDIUM
Secure Downloads WP <1.2.3 - Info Disclosure
CVSS 6.5
CVE-2024-4981 HIGH
Pagure < 5.14.1 - Unauthenticated Information Disclosure via Symbolic Link Traversal
CVSS 7.6
CVE-2024-13126 MEDIUM
WordPress Plugin <3.3.07 - Path Traversal
CVSS 4.6
CVE-2024-48864 CRITICAL
File Station 5 <5.5.6.4741 - Info Disclosure
CVSS 9.1
Details
Vulnerabilities 482