Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-552

MITRE ↗

CWE-552

48
CRITICAL
196
HIGH
223
MEDIUM
13
LOW
494 CVEs · Page 4/10
4.0
CVE-2025-48928 KEV

The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent

3.7
CVE-2025-14697

A security flaw has been discovered in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3

3.7
CVE-2025-15153

A weakness has been identified in PbootCMS up to 3.2.12. Impacted is an unknown function of the file /data/pbootcms.db o

CVE-2023-29080

Potential privilege escalation vulnerability in Revenera InstallShield versions 2022 R2 and 2021 R2 due to adding Instal

CVE-2025-22369

The ReadFile endpoint of the firmware for Mennekes Smart / Premium Chargingpoints can be abused to read arbitrary files

CVE-2025-1982

Local File Inclusion vulnerability in Ready's attachment upload panel allows low privileged user to provide link to a lo

CVE-2025-34110

A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated att

CVE-2025-34139

A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Mana

CVE-2009-10005

ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 expose the mimencode binary via

CVE-2025-59054

dstack is a software development kit (SDK) to simplify the deployment of arbitrary containerized apps into trusted execu

CVE-2021-4463

Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulne

CVE-2025-64185

Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writ

10.0
CVE-2024-6209

Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series

9.9
CVE-2024-39931

Gogs through 0.13.0 allows deletion of internal files.

9.8
CVE-2024-2055

The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the

9.8
CVE-2024-2056

Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy servi

9.8
CVE-2023-48710

iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they sho

9.8
CVE-2024-5262

Files or Directories Accessible to External Parties vulnerability in smb server in ProjectDiscovery Interactsh allows re

9.8
CVE-2024-4098

The Shariff Wrapper plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6.13

9.8
CVE-2024-0949

Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability

9.8
CVE-2024-53676

A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution

9.0
CVE-2024-21403

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

8.8
CVE-2023-39479

Softing Secure Integration Server OPC UA Gateway Directory Creation Vulnerability. This vulnerability allows remote atta

8.8
CVE-2024-3564

The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to

8.8
CVE-2024-36442

cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an authenticated attacker to gain access to arbitrar

8.8
CVE-2024-50627

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Privilege Escalation vulnerability exists in the file u

8.5
CVE-2024-27894

The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the functio

8.4
CVE-2024-34066

Pterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the

8.2
CVE-2024-51542

Configuration Download vulnerabilities allow access to dependency configuration information.  Affected products: ABB A

8.1
CVE-2024-8535

Authenticated user can access unintended user capabilities in NetScaler ADC and NetScaler Gateway if the appliance must

7.8
CVE-2023-47202

A local file inclusion vulnerability on the Trend Micro Apex One management server could allow a local attacker to escal

7.8
CVE-2024-3037

An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print

7.8
CVE-2024-38876

A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Cont

7.7
CVE-2024-52292

Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions o

7.5
CVE-2023-6266

The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file

7.5
CVE-2023-4550

Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on W

7.5
CVE-2024-24161

MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not fil

7.5
CVE-2024-2052

CWE-552: Files or Directories Accessible to External Parties vulnerability exists that could allow unauthenticated file

7.5
CVE-2024-2759

Improper access control vulnerability in Apaczka plugin for PrestaShop allows information gathering from saved templates

7.5
CVE-2024-4836

Web services managed by Edito CMS (Content Management System) in versions from 3.5 through 3.25 leak sensitive data as t

7.5
CVE-2024-6421

An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP servic

7.5
CVE-2024-6911

Files on the Windows system are accessible without authentication to external parties due to a local file inclusion in P

7.5
CVE-2024-38429

Matrix Tafnit v8 -  CWE-552: Files or Directories Accessible to External Parties

7.5
CVE-2024-7729

The CAYIN Technology CMS lacks proper access control, allowing unauthenticated remote attackers to download arbitrary CG

7.5
CVE-2023-49198

Mysql security vulnerability in Apache SeaTunnel. Attackers can read files on the MySQL server by modifying the informa

7.5
CVE-2024-7107

Files or Directories Accessible to External Parties vulnerability in National Keep Cyber Security Services CyberMath all

7.5
CVE-2024-49359

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all

7.5
CVE-2024-10403

Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFT

7.5
CVE-2024-52047

A widget local file inclusion vulnerability in Trend Micro Apex One could allow a remote attacker to execute arbitrary c

7.3
CVE-2024-39581

Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulne

Frequently Asked Questions

What is CWE-552?

CWE-552 (CWE-552) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-552?

There are 583 CVE records associated with CWE-552 in our database. Of these, 48 are critical severity, 196 are high severity, and 223 are medium severity.

How can I protect against CWE-552 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-552 using AI-powered security agents.

Detect CWE-552 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-552 vulnerabilities across your infrastructure.

Get Started