The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent
A security flaw has been discovered in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3
A weakness has been identified in PbootCMS up to 3.2.12. Impacted is an unknown function of the file /data/pbootcms.db o
Potential privilege escalation vulnerability in Revenera InstallShield versions 2022 R2 and 2021 R2 due to adding Instal
The ReadFile endpoint of the firmware for Mennekes Smart / Premium Chargingpoints can be abused to read arbitrary files
Local File Inclusion vulnerability in Ready's attachment upload panel allows low privileged user to provide link to a lo
A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated att
A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Mana
ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 expose the mimencode binary via
dstack is a software development kit (SDK) to simplify the deployment of arbitrary containerized apps into trusted execu
Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulne
Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writ
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series
Gogs through 0.13.0 allows deletion of internal files.
The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the
Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy servi
iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they sho
Files or Directories Accessible to External Parties vulnerability in smb server in ProjectDiscovery Interactsh allows re
The Shariff Wrapper plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6.13
Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability
A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
Softing Secure Integration Server OPC UA Gateway Directory Creation Vulnerability. This vulnerability allows remote atta
The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to
cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an authenticated attacker to gain access to arbitrar
An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Privilege Escalation vulnerability exists in the file u
The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the functio
Pterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the
Configuration Download vulnerabilities allow access to dependency configuration information. Affected products: ABB A
Authenticated user can access unintended user capabilities in NetScaler ADC and NetScaler Gateway if the appliance must
A local file inclusion vulnerability on the Trend Micro Apex One management server could allow a local attacker to escal
An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print
A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Cont
Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions o
The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file
Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on W
MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not fil
CWE-552: Files or Directories Accessible to External Parties vulnerability exists that could allow unauthenticated file
Improper access control vulnerability in Apaczka plugin for PrestaShop allows information gathering from saved templates
Web services managed by Edito CMS (Content Management System) in versions from 3.5 through 3.25 leak sensitive data as t
An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP servic
Files on the Windows system are accessible without authentication to external parties due to a local file inclusion in P
Matrix Tafnit v8 - CWE-552: Files or Directories Accessible to External Parties
The CAYIN Technology CMS lacks proper access control, allowing unauthenticated remote attackers to download arbitrary CG
Mysql security vulnerability in Apache SeaTunnel. Attackers can read files on the MySQL server by modifying the informa
Files or Directories Accessible to External Parties vulnerability in National Keep Cyber Security Services CyberMath all
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all
Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFT
A widget local file inclusion vulnerability in Trend Micro Apex One could allow a remote attacker to execute arbitrary c
Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulne
Frequently Asked Questions
What is CWE-552?
CWE-552 (CWE-552) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-552?
There are 583 CVE records associated with CWE-552 in our database. Of these, 48 are critical severity, 196 are high severity, and 223 are medium severity.
How can I protect against CWE-552 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-552 using AI-powered security agents.
Detect CWE-552 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-552 vulnerabilities across your infrastructure.
Get Started