Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-552

MITRE ↗

CWE-552

17
CRITICAL
25
HIGH
31
MEDIUM
1
LOW
77 CVEs · Page 1/2
9.9
CVE-2025-14771

Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0

9.8
CVE-2020-37082

webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database ba

9.8
CVE-2026-2331

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileac

9.8
CVE-2026-33698

Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code fr

9.8
CVE-2019-25709

CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by access

9.8
CVE-2026-40624

Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated att

9.6
CVE-2026-8715

Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in th

9.4
CVE-2026-2330

An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelis

9.4
CVE-2026-11841

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileac

9.4
CVE-2026-73653

Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider

9.3
CVE-2026-34361

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio

9.1
CVE-2025-69990

phpgurukul News Portal Project V4.1 has an Arbitrary File Deletion Vulnerability in remove_file.php. The parameter file

9.1
CVE-2026-25137

The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odo

9.1
CVE-2026-40484

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functional

9.1
CVE-2026-31215

The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticSearch

9.1
CVE-2026-31216

The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its file m

9.0
CVE-2026-45721

Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that res

8.8
CVE-2025-68719

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 mishandle configuration management. Once any user is logged in and main

8.8
CVE-2016-20025

ZKTeco ZKAccess Professional 3.5.3 contains an insecure file permissions vulnerability that allows authenticated users t

8.7
CVE-2026-35169

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project

8.7
CVE-2026-40631

An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through

8.2
CVE-2025-37168

Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 ope

8.1
CVE-2026-63040

Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorizati

8.1
CVE-2026-63042

Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the

8.1
CVE-2026-75464

OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().

8.1
CVE-2026-53580

Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the automatic image-downlo

7.8
CVE-2025-69875

A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient val

7.7
CVE-2026-35446

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project

7.7
CVE-2026-54457

TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and e

7.7
CVE-2026-75889

Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor reso

7.5
CVE-2026-25231

FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 3.3.0, the application contains an unauthe

7.5
CVE-2018-25164

EverSync 0.5 contains an arbitrary file download vulnerability that allows unauthenticated attackers to access sensitive

7.5
CVE-2026-34785

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whethe

7.5
CVE-2026-34392

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project

7.5
CVE-2025-69428

An issue in Pro-Bit before v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdi

7.5
CVE-2026-39871

A path handling issue was addressed with improved logic. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.

7.5
CVE-2026-45088

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in R

7.5
CVE-2025-66389

GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler

7.5
CVE-2026-59703

repomix contains a local file inclusion vulnerability in the git clone endpoint that allows unauthenticated attackers to

7.5
CVE-2026-63490

Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handleb

7.4
CVE-2026-57990

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker t

7.2
CVE-2024-56462

IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive t

6.8
CVE-2026-32750

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importStdMd passes the l

6.8
CVE-2024-11399

Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for des

6.8
CVE-2026-19093

The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allow

6.8
CVE-2026-82020

Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can in

6.5
CVE-2025-66689

A path traversal vulnerability exists in Zen MCP Server before 9.8.2 that allows authenticated attackers to read arbitra

6.5
CVE-2025-37177

An arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors runnin

6.5
CVE-2025-66955

Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenticated

6.5
CVE-2021-47960

A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows

Frequently Asked Questions

What is CWE-552?

CWE-552 (CWE-552) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-552?

There are 78 CVE records associated with CWE-552 in our database. Of these, 17 are critical severity, 25 are high severity, and 31 are medium severity.

How can I protect against CWE-552 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-552 using AI-powered security agents.

Detect CWE-552 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-552 vulnerabilities across your infrastructure.

Get Started