Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-552

MITRE ↗

CWE-552

48
CRITICAL
196
HIGH
223
MEDIUM
13
LOW
494 CVEs · Page 2/10
6.5
CVE-2026-7817

Local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities in pgAdmin 4 LLM API configuration end

6.5
CVE-2026-8704

Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified.

6.5
CVE-2026-40564

Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Ku

6.5
CVE-2026-15342

Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one wo

6.3
CVE-2026-33380

A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's fi

6.2
CVE-2026-29066

Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.

5.7
CVE-2026-40425

The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive file

5.5
CVE-2026-32185

Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofi

5.5
CVE-2026-35440

Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose

5.3
CVE-2025-12648

The WP-Members Membership Plugin for WordPress is vulnerable to unauthorized file access in versions up to, and includin

5.3
CVE-2026-4532

A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0. Affected by this vuln

5.3
CVE-2026-4900

A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the fil

5.3
CVE-2026-5335

The Magic Export & Import WordPress plugin before 1.2.0 stores exported CSV files at a publicly accessible location, mak

5.3
CVE-2026-45543

Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collab

5.3
CVE-2026-13533

A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function

5.3
CVE-2026-19903

A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db

5.3
CVE-2026-19987

A security vulnerability has been detected in SourceCodester Best Employee Management System 1.0. This affects an unknow

5.3
CVE-2026-76799

A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the f

5.3
CVE-2026-78051

A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the f

4.9
CVE-2021-4474

Ruckus Access Point products contain an arbitrary file read vulnerability in the command-line interface that allows auth

4.9
CVE-2026-6418

An issue was discovered in the Shared Account Synchronization component of PaperCut MF (version 25.0.4). The application

4.9
CVE-2026-42063

A vulnerability exists in iControl SOAP where an authenticated attacker with the Resource Administrator or Administrator

4.3
CVE-2026-33071

FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, the WebDAV upload endpoint accep

3.7
CVE-2026-14849

The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it

CVE-2026-24732

Files or Directories Accessible to External Parties, Incorrect Permission Assignment for Critical Resource vulnerability

CVE-2026-4760

From Panorama Web HMI, an attacker can gain read access to certain Web HMI server files, if he knows their paths and if

CVE-2025-7389

A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-le

10.0
CVE-2024-56731

Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .

10.0
CVE-2025-41240

Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located wit

9.1
CVE-2025-21609

SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary f

9.1
CVE-2024-48864

A files or directories accessible to external parties vulnerability has been reported to affect File Station 5. If explo

9.1
CVE-2025-40908

YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified

9.1
CVE-2025-68109

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality doe

8.8
CVE-2025-32819

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversa

8.6
CVE-2025-26525

Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is ava

8.3
CVE-2024-12917

Files or Directories Accessible to External Parties vulnerability in Agito Computer Health4All allows Exploiting Incorre

8.2
CVE-2025-27147

The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNM

8.1
CVE-2025-53536

Roo Code is an AI-powered autonomous coding agent. Prior to 3.22.6, if the victim had "Write" auto-approved, an attacker

8.1
CVE-2023-41566

OA EKP v16 was discovered to contain an arbitrary download vulnerability via the component /ui/sys_ui_extend/sysUiExtend

8.1
CVE-2025-11959

Files or Directories Accessible to External Parties, Exposure of Private Personal Information to an Unauthorized Actor v

7.8
CVE-2025-2222

CWE-552: Files or Directories Accessible to External Parties vulnerability over https exists that could leak information

7.8
CVE-2025-49797

Multiple Brother driver installers for Windows contain a privilege escalation vulnerability. If exploited, an arbitrary

7.8
CVE-2025-23276

NVIDIA Installer for Windows contains a vulnerability where an attacker may be able to escalate privileges. A successful

7.6
CVE-2024-4981

A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links

7.5
CVE-2024-43660

The CGI script <redacted>.sh can be used to download any file on the filesystem. This issue affects Iocharger firmware

7.5
CVE-2024-57452

ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows

7.5
CVE-2025-25759

An issue in the component admin_template.php of SUCMS v1.0 allows attackers to execute a directory traversal and arbitra

7.5
CVE-2025-58753

Copyparty is a portable file server. In versions prior to 1.19.8, there was a missing permission-check in the shares fea

7.5
CVE-2025-61734

Files or Directories Accessible to External Parties vulnerability in Apache Kylin. You are fine as long as the Kylin's

7.5
CVE-2025-11371 KEV

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local Fil

Frequently Asked Questions

What is CWE-552?

CWE-552 (CWE-552) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-552?

There are 583 CVE records associated with CWE-552 in our database. Of these, 48 are critical severity, 196 are high severity, and 223 are medium severity.

How can I protect against CWE-552 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-552 using AI-powered security agents.

Detect CWE-552 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-552 vulnerabilities across your infrastructure.

Get Started