A file disclosure vulnerability exists in Sage 1000 v7.0.0. This vulnerability allows remote attackers to retrieve arbit
A CWE-552 “Files or Directories Accessible to External Parties” vulnerability in the embedded Chromium browser allows a
File replacement vulnerability on some devices Impact: Successful exploitation of this vulnerability will affect integri
Softing Secure Integration Server FileDirectory OPC UA Object Arbitrary File Creation Vulnerability. This vulnerability
CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the d
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file
In Apache Linkis =1.4.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actuall
Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients
Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read a
An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 1
A vulnerability in Cisco IND could allow an authenticated, local attacker to read application data. This vulnerabilit
Unauthorized file access vulnerability in the wallpaper service module. Successful exploitation of this vulnerability ma
A vulnerability has been found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This vulner
A vulnerability was found in SourceCodester Online Birth Certificate Management System 1.0. It has been declared as prob
A vulnerability was found in Casdoor up to 1.335.0. It has been classified as problematic. Affected is an unknown functi
A vulnerability was found in Mercury MNVR816 up to 2.0.1.0.5. It has been classified as problematic. This affects an unk
A directory listing issue in the baserCMS plugin in D-ZERO CO., LTD. BurgerEditor and BurgerEditor Limited Edition befor
AshPostgres is the PostgreSQL data layer for Ash Framework. Starting in version 2.0.0 and prior to version 2.4.10, in ce
An information-disclosure vulnerability exists in Fortra's GoAnywhere MFT application prior to version 7.7.0 that allows
Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may explo
In Apache Linkis <= 1.5.0, Arbitrary file deletion in Basic management services on A user with an administrator accou
BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin/database.php?act=del request.
wolfictl is a command line tool for working with Wolfi. A git authentication issue in versions prior to 0.16.10 allows a
Priority – CWE-552: Files or Directories Accessible to External Parties
ELECOM wireless LAN routers allow a network-adjacent unauthenticated attacker to obtain the configuration file containin
Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a Files or Directories Acc
A vulnerability classified as problematic has been found in Musicshelf 1.0/1.1 on Android. Affected is an unknown functi
Files or Directories Accessible to External Parties vulnerability in Eliz Software Panel allows Collect Data from Common
Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation
The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and
laravel-s 3.7.35 is vulnerable to Local File Inclusion via /src/Illuminate/Laravel.php.
An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to up
Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue
A Local File Inclusion vulnerability has been found in Axiell Iguana CMS. Due to insufficient neutralisation of user inp
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing K
The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization, which could allow an u
In the affected version of the 1E Client, an ordinary user could subvert downloaded instruction resource files, e.g., to
The HTML filter and csv-file search plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and in
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXP
JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of u
Sysaid - CWE-552: Files or Directories Accessible to External Parties - Authenticated users may exfiltrate files fro
Artifex Ghostscript before 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pi
NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may be able to write arbitrary data to
A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow au
A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow au
Easy Images v2.0 was discovered to contain an arbitrary file download vulnerability via the component /application/down.
CRMEB 4.4.4 is vulnerable to Any File download.
Frequently Asked Questions
What is CWE-552?
CWE-552 (CWE-552) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-552?
There are 583 CVE records associated with CWE-552 in our database. Of these, 48 are critical severity, 196 are high severity, and 223 are medium severity.
How can I protect against CWE-552 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-552 using AI-powered security agents.
Detect CWE-552 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-552 vulnerabilities across your infrastructure.
Get Started