CWE-552

Files or Directories Accessible to External Parties

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product makes files or directories accessible to unauthorized actors, even though they should not be.

483 vulnerabilities with CWE-552
CVE-2024-23282 MEDIUM
iPadOS < 16.7.8 and 17.5 - Unauthorized FaceTime Call Initiation via Malicious Email
CVSS 5.5
CVE-2024-5262 CRITICAL
ProjectDiscovery Interactsh - Path Traversal
CVSS 9.8
CVE-2024-5587 MEDIUM
Casdoor < 1.335.0 - Unauthenticated Sensitive File Exposure via Configuration File Handler
CVSS 5.3
CVE-2024-3564 HIGH
Content Blocks (Custom Post Widget) <3.3.0 - Code Injection
CVSS 8.8
CVE-2024-5045 MEDIUM
SourceCodester Online Birth Certificate Management System 1.0 - Inf...
CVSS 5.3
CVE-2024-35183 MEDIUM
wolfictl < 0.16.10 - GitHub Token Exposure to Untrusted Remote Servers
CVSS 4.4
CVE-2024-3037 HIGH
PaperCut NG/MF < 23.0.9 - Arbitrary File Deletion via Web Print
CVSS 7.8
CVE-2024-34066 HIGH
Pterodactyl Wings < 1.11.12 - Arbitrary File Read and Write via Leaked Token
CVSS 8.4
CVE-2024-2759 HIGH
Apaczka v1-v4 - Unauthenticated Information Disclosure via Saved Templates
CVSS 7.5
CVE-2024-29225 MEDIUM
WRC-X3200GST3-B <1.25 & WRC-G01-W <1.24 - Info Disclosure
CVSS 4.3
CVE-2024-2052 HIGH
Files or Directories Accessible - Info Disclosure
CVSS 7.5
CVE-2024-27894 HIGH
Pulsar Functions Worker - Code Injection
CVSS 8.5
CVE-2024-2364 LOW
Musicshelf 1.0/1.1 - Info Disclosure
CVSS 1.8
CVE-2024-2056 CRITICAL
Artica Proxy - Unauthenticated Arbitrary File Read via Exposed Tailon Service
CVSS 9.8
CVE-2024-2055 CRITICAL
Artica Proxy - Privilege Escalation
CVSS 9.8
CVE-2024-21403 CRITICAL
Microsoft Azure Kubernetes Service - Privilege Escalation
CVSS 9.0
CVE-2024-22240 MEDIUM
Aria Operations for Networks - Info Disclosure
CVSS 4.9
CVE-2024-24161 HIGH
MRCMS 3.0 - Arbitrary File Read via /admin/file/edit.do Path Parameter
CVSS 7.5
CVE-2024-1005 MEDIUM
Shanxi Diankeyun Technology NODERP <6.0.2 - Info Disclosure
CVSS 5.3
CVE-2023-41566 HIGH
OA EKP v16 - Arbitrary File Download via sysUiExtend.do
CVSS 8.1
CVE-2023-29080 HIGH
Revenera InstallShield 2022 R2-2021 R2 - Privilege Escalation
CVE-2023-20039 MEDIUM
Cisco Industrial Network Director < 1.11.3 - Authenticated Sensitive Data Exposure via Insufficient File Permissions
CVSS 5.5
CVE-2023-49198 HIGH
Apache SeaTunnel <1.0.1 - Info Disclosure
CVSS 7.5
CVE-2023-41916 MEDIUM
Apache Linkis <1.4.0 - Info Disclosure
CVSS 6.5
CVE-2023-39480 MEDIUM
Softing Secure Integration Server - RCE
CVSS 6.5
Details
Vulnerabilities 483