CWE-552
Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
483 vulnerabilities with CWE-552
CVE-2024-49359
HIGH
ZimaOS < 1.2.5 - Authenticated Directory Traversal via File API Endpoint
CVSS 7.5
CVE-2024-49756
MEDIUM
AshPostgres <2.4.10 - Info Disclosure
CVSS 5.3
CVE-2024-44807
MEDIUM
BurgerEditor and BurgerEditor Limited Edition < 2.25.1 - Directory Listing Information Disclosure
CVSS 5.3
CVE-2024-45894
MEDIUM
BlueCMS 1.6 - Arbitrary File Deletion via file_name Parameter
CVSS 4.9
CVE-2024-7107
HIGH
National Keep Cyber Security Services CyberMath <CYBM.240816253 - I...
CVSS 7.5
CVE-2024-6878
CRITICAL
Eliz Software Panel <2.3.24 - Info Disclosure
CVE-2024-8655
MEDIUM
Mercury MNVR816 <2.0.1.0.5 - Info Disclosure
CVSS 5.3
CVE-2024-39581
HIGH
Dell PowerScale InsightIQ <5.2 - Info Disclosure
CVSS 7.3
CVE-2024-36442
HIGH
Swissphone DiCal-RED 4009 - File Access
CVSS 8.8
CVE-2024-41699
MEDIUM
Priority < 24.0 - Unauthenticated Arbitrary File Read
CVSS 4.4
CVE-2024-7729
HIGH
CAYIN Technology CMS - Info Disclosure
CVSS 7.5
CVE-2024-3913
MEDIUM
Phoenixcontact Phoenix Contact CHARX SEC-3000/3050/3100/3150 Firmware <= 1.6.3 - Unauthenticated Configuration Change
CVSS 5.9
CVE-2024-38876
HIGH
Omnivise T3000 - Authenticated Privilege Escalation via User-Modifiable Code Execution
CVSS 7.8
CVE-2024-27182
MEDIUM
Apache Linkis <=1.5.0 - Privilege Escalation
CVSS 4.9
CVE-2024-38429
HIGH
Matrix Tafnit < 8.4.202 - Files or Directories Accessible to External Parties
CVSS 7.5
CVE-2024-40767
MEDIUM
OpenStack Nova <27.4.1,28.2.1,29.1.1 - Info Disclosure
CVSS 6.5
CVE-2024-6911
HIGH
PerkinElmer ProcessPlus <1.11.6507.0 - Info Disclosure
CVSS 7.5
CVE-2024-6421
HIGH
Pepperl+Fuchs OIT Series Firmware <= 2.11.0 - Information Disclosure via FTP
CVSS 7.5
CVE-2024-6209
CRITICAL
ABB ASPECT - Enterprise <3.08.01 - Info Disclosure
CVSS 10.0
CVE-2024-32498
MEDIUM
OpenStack <24.0.0, <28.0.2, <29.0.3 - Info Disclosure
CVSS 6.5
CVE-2024-39931
CRITICAL
Gogs < 0.13.0 - Unauthenticated Arbitrary File Deletion
CVSS 9.9
CVE-2024-4836
HIGH
Edito CMS 3.5-3.25 - Unauthenticated Sensitive Data Exposure via Configuration File Download
CVSS 7.5
CVE-2024-0949
CRITICAL
Talya Informatics Elektraweb <17.0.68 - Auth Bypass
CVSS 9.8
CVE-2024-4098
CRITICAL
Shariff Wrapper <= 4.6.13 - Unauthenticated Local File Inclusion via shariff3uu_fetch_sharecounts
CVSS 9.8
CVE-2024-5056
MEDIUM
Modicon M340 Firmware - Files or Directories Accessible to External Parties
CVSS 6.5
Details
Vulnerabilities
483