CWE-552
Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
482 vulnerabilities with CWE-552
CVE-2024-12917
HIGH
Health4All <10.01.2025 - Info Disclosure
CVSS 8.3
CVE-2024-11629
HIGH
Telerik Document Processing <2025.1.205 - Path Traversal
CVSS 7.1
CVE-2024-48019
MEDIUM
Apache Doris 2.1.0-2.1.7 - Path Traversal and Arbitrary File Read
CVSS 5.4
CVE-2024-57452
HIGH
ChestnutCMS <=1.5.0 - File Deletion
CVSS 7.5
CVE-2024-47106
MEDIUM
IBM Jazz for Service Management <1.1.3.22 - Info Disclosure
CVSS 5.3
CVE-2024-45627
MEDIUM
Apache Linkis <1.7.0 - Info Disclosure
CVSS 5.9
CVE-2024-53649
MEDIUM
SIPROTEC 5 - Authenticated Arbitrary File Read via Webserver Path Traversal
CVSS 6.5
CVE-2024-47518
MEDIUM
Arista NG Firewall <= 17.1.1 - Information Disclosure via ETM
CVSS 6.4
CVE-2024-43660
HIGH
Iocharger AC <24120701 - File Download
CVSS 7.5
CVE-2024-52047
HIGH
Trend Micro Apex One < 14.0.13139 - Widget Local File Inclusion
CVSS 7.5
CVE-2024-9945
MEDIUM
Fortra's GoAnywhere MFT <7.7.0 - Info Disclosure
CVSS 5.3
CVE-2024-54099
MEDIUM
File Replacement Vuln - Info Disclosure
CVSS 6.7
CVE-2024-50627
HIGH
Digi ConnectPort LTS Firmware < 1.4.12 - Privilege Escalation via File Upload
CVSS 8.8
CVE-2024-51542
HIGH
ABB ASPECT <3.08.02, NEXUS Series <3.08.02, MATRIX Series <3.08.02 ...
CVSS 8.2
CVE-2024-53676
CRITICAL
HPE Insight Remote Support < 7.14.0.629 - Directory Traversal and Remote Code Execution
CVSS 9.8
CVE-2024-51058
MEDIUM
TCPDF < 6.7.6 - Local File Inclusion via Image Tag
CVSS 6.2
CVE-2024-10403
HIGH
Brocade Fabric OS <8.2.3e2, 9.0.0-9.2.0c, 9.2.1-9.2.1a - Info Discl...
CVSS 7.5
CVE-2024-10126
MEDIUM
M-Files Server <24.11 - Local File Inclusion
CVSS 4.3
CVE-2024-31141
MEDIUM
Apache Kafka Clients - Improper Privilege Management
CVSS 6.5
CVE-2024-52292
HIGH
Craft CMS 3.5.13-4.12.7 and 5.0.0-alpha.1-5.4.8 - Authenticated Path Traversal via dataUrl Function
CVSS 7.7
CVE-2024-8535
HIGH
NetScaler ADC - Privilege Escalation
CVSS 8.1
CVE-2024-48838
LOW
Dell SmartFabric OS10 Software - Info Disclosure
CVSS 3.3
CVE-2024-10526
HIGH
Rapid7 Velociraptor MSI Installer <0.73.3 - Privilege Escalation
CVE-2024-48647
HIGH
Sage FRP 1000 v7.0.0 - Arbitrary File Read via URL Parameter Manipulation
CVSS 7.2
CVE-2024-49359
HIGH
ZimaOS < 1.2.5 - Authenticated Directory Traversal via File API Endpoint
CVSS 7.5
Details
Vulnerabilities
482