Local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities in pgAdmin 4 LLM API configuration end
Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified.
Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Ku
Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one wo
A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's fi
Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.
The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive file
Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofi
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose
The WP-Members Membership Plugin for WordPress is vulnerable to unauthorized file access in versions up to, and includin
A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0. Affected by this vuln
A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the fil
The Magic Export & Import WordPress plugin before 1.2.0 stores exported CSV files at a publicly accessible location, mak
Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collab
A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function
A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db
A security vulnerability has been detected in SourceCodester Best Employee Management System 1.0. This affects an unknow
A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the f
A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the f
Ruckus Access Point products contain an arbitrary file read vulnerability in the command-line interface that allows auth
An issue was discovered in the Shared Account Synchronization component of PaperCut MF (version 25.0.4). The application
A vulnerability exists in iControl SOAP where an authenticated attacker with the Resource Administrator or Administrator
FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, the WebDAV upload endpoint accep
The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it
Files or Directories Accessible to External Parties, Incorrect Permission Assignment for Critical Resource vulnerability
From Panorama Web HMI, an attacker can gain read access to certain Web HMI server files, if he knows their paths and if
A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-le
Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .
Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located wit
SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary f
A files or directories accessible to external parties vulnerability has been reported to affect File Station 5. If explo
YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified
ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality doe
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversa
Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is ava
Files or Directories Accessible to External Parties vulnerability in Agito Computer Health4All allows Exploiting Incorre
The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNM
Roo Code is an AI-powered autonomous coding agent. Prior to 3.22.6, if the victim had "Write" auto-approved, an attacker
OA EKP v16 was discovered to contain an arbitrary download vulnerability via the component /ui/sys_ui_extend/sysUiExtend
Files or Directories Accessible to External Parties, Exposure of Private Personal Information to an Unauthorized Actor v
CWE-552: Files or Directories Accessible to External Parties vulnerability over https exists that could leak information
Multiple Brother driver installers for Windows contain a privilege escalation vulnerability. If exploited, an arbitrary
NVIDIA Installer for Windows contains a vulnerability where an attacker may be able to escalate privileges. A successful
A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links
The CGI script <redacted>.sh can be used to download any file on the filesystem. This issue affects Iocharger firmware
ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows
An issue in the component admin_template.php of SUCMS v1.0 allows attackers to execute a directory traversal and arbitra
Copyparty is a portable file server. In versions prior to 1.19.8, there was a missing permission-check in the shares fea
Files or Directories Accessible to External Parties vulnerability in Apache Kylin. You are fine as long as the Kylin's
In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local Fil
Frequently Asked Questions
What is CWE-552?
CWE-552 (CWE-552) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-552?
There are 583 CVE records associated with CWE-552 in our database. Of these, 48 are critical severity, 196 are high severity, and 223 are medium severity.
How can I protect against CWE-552 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-552 using AI-powered security agents.
Detect CWE-552 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-552 vulnerabilities across your infrastructure.
Get Started