CWE-552

Files or Directories Accessible to External Parties

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product makes files or directories accessible to unauthorized actors, even though they should not be.

474 vulnerabilities with CWE-552
CVE-2025-25266 MEDIUM
Tecnomatix Plant Simulation <V2302.0021-V2404.0010 - Info Disclosure
CVSS 6.8
CVE-2025-2147 MEDIUM
Beijing Zhide Intelligent Internet Technology Modern Farm Digital I...
CVSS 5.3
CVE-2025-2038 HIGH
Blood Bank Management System 1.0 - Info Disclosure
CVSS 7.3
CVE-2025-25759 HIGH
SUCMS 1.0 - Path Traversal and Arbitrary File Deletion via admin_template.php
CVSS 7.5
CVE-2025-25799 MEDIUM
SeaCMS 13.3 - Arbitrary File Read via admin_safe.php file_get_contents
CVSS 6.0
CVE-2025-26525 HIGH
Moodle - Arbitrary File Read via TeX Notation Filter
CVSS 8.6
CVE-2025-23421 MEDIUM
Qardio Heart Health iOS <2.7.4 & Android <2.5.1 - Firmware Exposure
CVSS 6.4
CVE-2025-1042 MEDIUM
GitLab EE <17.6.5-17.8.2 - Info Disclosure
CVSS 4.9
CVE-2025-0509 HIGH
Sparkle < 2.6.4 - Unauthenticated Update Replacement via Signature Bypass
CVSS 7.3
CVE-2025-21609 CRITICAL
SiYuan Note <3.1.18 - File Deletion
CVSS 9.1
CVE-2024-56462 HIGH
IBM QRadar SIEM is vulnerable to using components with known vulnerabilities
CVSS 7.2
CVE-2024-11399 MEDIUM
Synology BeeDrive For Desktop < 1.3.2-13814 - Files or Directories Accessible to External Parties
CVSS 6.8
CVE-2024-56731 CRITICAL
Gogs < 0.13.3 - Remote Code Execution via .git Directory File Deletion
CVSS 10.0
CVE-2024-8031 MEDIUM
Secure Downloads WP <1.2.3 - Info Disclosure
CVSS 6.5
CVE-2024-4981 HIGH
Pagure < 5.14.1 - Unauthenticated Information Disclosure via Symbolic Link Traversal
CVSS 7.6
CVE-2024-13126 MEDIUM
WordPress Plugin <3.3.07 - Path Traversal
CVSS 4.6
CVE-2024-48864 CRITICAL
File Station 5 <5.5.6.4741 - Info Disclosure
CVSS 9.1
CVE-2024-12917 HIGH
Health4All <10.01.2025 - Info Disclosure
CVSS 8.3
CVE-2024-11629 HIGH
Telerik Document Processing <2025.1.205 - Path Traversal
CVSS 7.1
CVE-2024-48019 MEDIUM
Apache Doris 2.1.0-2.1.7 - Path Traversal and Arbitrary File Read
CVSS 5.4
CVE-2024-57452 HIGH
ChestnutCMS <=1.5.0 - File Deletion
CVSS 7.5
CVE-2024-47106 MEDIUM
IBM Jazz for Service Management <1.1.3.22 - Info Disclosure
CVSS 5.3
CVE-2024-45627 MEDIUM
Apache Linkis <1.7.0 - Info Disclosure
CVSS 5.9
CVE-2024-53649 MEDIUM
SIPROTEC 5 - Authenticated Arbitrary File Read via Webserver Path Traversal
CVSS 6.5
CVE-2024-47518 MEDIUM
Arista NG Firewall <= 17.1.1 - Information Disclosure via ETM
CVSS 6.4
Details
Vulnerabilities 474