CWE-552
Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
474 vulnerabilities with CWE-552
CVE-2023-5907
MEDIUM
WordPress File Manager <6.3 - Privilege Escalation
CVSS 6.5
CVE-2023-50164
CRITICAL
Apache Struts 2.0.0-2.5.32 - Path Traversal and Remote Code Execution via File Upload
CVSS 9.8
CVE-2023-6375
MEDIUM
Tyler Technologies Court Case Management Plus - Info Disclosure
CVSS 5.3
CVE-2023-39545
HIGH
CLUSTERPRO X <5.1 - Command Injection
CVSS 8.8
CVE-2023-47612
MEDIUM
Telit Cinterion BGS5 EHS5/6/8 PDS5/6/8 ELS61/81 PLS62 - Unauthenticated Arbitrary File Read/Write via Physical Access
CVSS 6.8
CVE-2023-42534
MEDIUM
ChooserActivity <SMR Nov-2023 Release 1 - Info Disclosure
CVSS 6.3
CVE-2023-4930
MEDIUM
Front End PM WP <11.4.3 - Info Disclosure
CVSS 6.5
CVE-2023-31017
HIGH
NVIDIA GPU Display Driver for Windows - Code Injection
CVSS 7.8
CVE-2023-5099
HIGH
WordPress <=2.7 - Local File Inclusion
CVSS 8.8
CVE-2023-5199
CRITICAL
PHP to Page < 0.3 - Authenticated Local File Inclusion to Remote Code Execution via Shortcode
CVSS 9.9
CVE-2023-26580
HIGH
IDAttend's IDWeb <3.1.013 - Info Disclosure
CVSS 7.5
CVE-2023-33517
HIGH
carRental 1.0 - Arbitrary File Read via Incorrect Access Control
CVSS 7.5
CVE-2023-4933
MEDIUM
WP Job Openings <3.4.3 - Info Disclosure
CVSS 5.3
CVE-2023-3155
HIGH
WordPress Gallery Plugin <3.39 - Info Disclosure
CVSS 7.2
CVE-2023-5101
MEDIUM
SICK APU0200 Firmware < 4.0.0.6 - Unauthenticated Arbitrary File Read via HTTP Requests
CVSS 5.3
CVE-2023-23366
HIGH
Music Station 5.3.0-5.3.21 - Authenticated Path Traversal
CVSS 7.7
CVE-2023-23365
HIGH
QNAP Music Station 5.3.0-5.3.21 - Authenticated Path Traversal
CVSS 7.7
CVE-2023-45160
HIGH
1e 1E Client - Resource File Subversion
CVSS 8.8
CVE-2023-20235
MEDIUM
Cisco IOS XE < 17.3.1 - Authenticated Privilege Escalation via Docker Privileged Mode
CVSS 6.5
CVE-2023-5297
LOW
Xinhu RockOA 2.3.2 - Info Disclosure
CVSS 3.7
CVE-2023-43856
HIGH
Dreamer CMS v4.1.3 - Info Disclosure
CVSS 7.5
CVE-2023-3712
MEDIUM
Honeywell PM43 Firmware < P10.19.050004 - Privilege Escalation via Unprotected Files or Directories
CVSS 6.6
CVE-2023-4588
MEDIUM
Delinea Secret Server <11.4.000002 - Info Disclosure
CVSS 6.8
CVE-2023-4743
LOW
Dreamer CMS <4.1.3 - Info Disclosure
CVSS 3.1
CVE-2023-41717
MEDIUM
Zscaler Proxy <3.6.1.25 - Auth Bypass
CVSS 5.5
Details
Vulnerabilities
474