Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0
webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database ba
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileac
Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code fr
CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by access
Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated att
Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in th
An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelis
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileac
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio
phpgurukul News Portal Project V4.1 has an Arbitrary File Deletion Vulnerability in remove_file.php. The parameter file
The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odo
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functional
The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticSearch
The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its file m
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that res
KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 mishandle configuration management. Once any user is logged in and main
ZKTeco ZKAccess Professional 3.5.3 contains an insecure file permissions vulnerability that allows authenticated users t
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project
An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through
Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 ope
Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorizati
Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the
OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().
Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the automatic image-downlo
A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient val
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project
TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and e
Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor reso
FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 3.3.0, the application contains an unauthe
EverSync 0.5 contains an arbitrary file download vulnerability that allows unauthenticated attackers to access sensitive
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whethe
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project
An issue in Pro-Bit before v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdi
A path handling issue was addressed with improved logic. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.
Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in R
GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler
repomix contains a local file inclusion vulnerability in the git clone endpoint that allows unauthenticated attackers to
Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handleb
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker t
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive t
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importStdMd passes the l
Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for des
The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allow
Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can in
A path traversal vulnerability exists in Zen MCP Server before 9.8.2 that allows authenticated attackers to read arbitra
An arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors runnin
Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenticated
A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows
Frequently Asked Questions
What is CWE-552?
CWE-552 (CWE-552) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-552?
There are 78 CVE records associated with CWE-552 in our database. Of these, 17 are critical severity, 25 are high severity, and 31 are medium severity.
How can I protect against CWE-552 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-552 using AI-powered security agents.
Detect CWE-552 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-552 vulnerabilities across your infrastructure.
Get Started