In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], a StaticHandler configuration for restricting access to h
due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an a
V-SOL GPON/EPON OLT Platform 2.03 contains an unauthenticated information disclosure vulnerability that allows attackers
A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with anoth
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. This issue a
A vulnerability classified as critical was found in SourceCodester Client Database Management System 1.0. This vulnerabi
Lack of file validation in do_update_vps in Avast Business Antivirus for Linux 4.5 on Linux allows local user to spoof o
Elevation of Privileges in the cleaning feature of Gen Digital CCleaner version 6.33.11465 on Windows allows a local use
In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, th
Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a se
An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbit
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant S
An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.80), SIPROTEC 5 6MD85 (CP300) (All ve
The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloade
Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Files or Directories Accessible to Externa
A vulnerability in the command-line interface of EdgeConnect SD-WAN could allow an authenticated attacker to read arbitr
An arbitrary file download vulnerability in the web interface of Juniper Networks Junos Space allows a network-based aut
Microhard Systems IPn4G 1.1.0 contains a configuration file disclosure vulnerability that allows authenticated attackers
Specially constructed queries targeting ETM could discover active remote access sessions
An attacker could obtain firmware files and reverse engineer their intended use leading to loss of confidentiality and
Exposure of Sensitive Information to an Unauthorized Actor, Missing Encryption of Sensitive Data, Files or Directories A
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant S
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_sa
In Apache Linkis <1.7.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql J
Tanium addressed an arbitrary file deletion vulnerability in TanOS.
Dell SmartFabric OS10 Software, versions prior to 10.6.0.5 contains a Files or Directories Accessible to External Partie
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to Exter
MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute ar
IBM Jazz for Service Management 1.1.3 through 1.1.3.22 could allow a remote attacker to obtain sensitive information fro
A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management Sys
A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is a
A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as pro
A vulnerability, which was classified as problematic, was found in SourceCodester Online Student Clearance System 1.0. T
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q
Files or directories accessible to external parties issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a
HCL Unica Platform is affected by unprotected files due to improper access controls. These files may contain sensitive
FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and the garbage collection i
IBM Cognos Analytics Certified Containers 12.1.0 could disclose package parameter information due to the presence of hid
A vulnerability was determined in SourceCodester Farm Management System 1.0. Affected by this vulnerability is an unknow
The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Informa
The Tainacan plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.0 via
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to sensitive information expos
An insecure direct object reference vulnerability in GitLab EE affecting all versions from 15.7 prior to 17.6.5, 17.7 pr
A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an e
Umbraco is an ASP.NET CMS. Due to unsafe handling and deletion of temporary files in versions 10.0.0 through 13.12.0, du
The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htac
CData API Server MySQL Misconfiguration Information Disclosure Vulnerability. This vulnerability allows remote attackers
The web portal on airpointer 2.4.107-2 was vulnerable local file inclusion. A malicious user with administrative privile
Frequently Asked Questions
What is CWE-552?
CWE-552 (CWE-552) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-552?
There are 583 CVE records associated with CWE-552 in our database. Of these, 48 are critical severity, 196 are high severity, and 223 are medium severity.
How can I protect against CWE-552 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-552 using AI-powered security agents.
Detect CWE-552 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-552 vulnerabilities across your infrastructure.
Get Started