An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. Gallery leaks Private Mode thumbnails
In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder
SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted.
The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x
Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could hav
Byobu Apport hook may disclose sensitive information since it automatically uploads the local user's .screenrc which may
Files or Directories Accessible to External Parties in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3
The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for
HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious i
A vulnerability has been identified in All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respe
PhantomJS through 2.1.1 has an arbitrary file read vulnerability, as demonstrated by an XMLHttpRequest for a file:// URI
In savePhotoFromUriToUri of ContactPhotoUtils.java in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.
In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymo
cPanel before 55.9999.141 allows arbitrary file-read operations because of a multipart form processing error (SEC-99).
Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers have a JUCI ACL misconfiguration that allows the "user" accoun
vBulletin through 5.5.4 mishandles external URLs within the /core/vb/vurl.php file and the /core/vb/vurl directories.
Open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to
A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before ve
In SilverStripe assets 4.0, there is broken access control on files.
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root
An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 could allow a l
An issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfi
pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The
Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension ma
redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker
LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /u
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly
An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a ser
IBM RSA DM (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to access set
A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an unauthenticated, local
The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in or
Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication,
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versio
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary file
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having lo
Tenshi 0.15 creates a tenshi.pid file after dropping privileges to a non-root account, which might allow local users to
Vulnerability in Wordpress plugin BackWPup before v3.4.2 allows possible brute forcing of backup file for download.
Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0 could allow an authenticated attacker to download fil
Microsoft Windows 10 allows an elevation of privilege vulnerability when the Windows Update Delivery Optimization does n
An issue was discovered in certain Apple products. iTunes before 12.7 is affected. The issue involves the "Data Sync" co
A vulnerability in Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could all
An information disclosure vulnerability in Fortinet FortiWeb 5.8.2 and below versions allows logged-in admin user to vie
Frequently Asked Questions
What is CWE-552?
CWE-552 (CWE-552) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-552?
There are 583 CVE records associated with CWE-552 in our database. Of these, 48 are critical severity, 196 are high severity, and 223 are medium severity.
How can I protect against CWE-552 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-552 using AI-powered security agents.
Detect CWE-552 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-552 vulnerabilities across your infrastructure.
Get Started