A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controll
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/curd/code.
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/file/downloa
Files or Directories Accessible to External Parties vulnerability in Saysis Starcities allows Collect Data from Common R
amano Xparc parking solutions 7.1.3879 was discovered to be vulnerable to local file inclusion.
Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.
Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated file disclosure. Using a GET parameter, attacker
GDidees CMS v3.9.1 was discovered to contain a source code disclosure vulnerability by the backup feature which is acces
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Ac
Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's
jfinal CMS 5.1.0 has an arbitrary file read vulnerability.
Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due
An Arbitrary File Movement vulnerability was found in ASUSTOR Data Master (ADM) allows an attacker to exploit the file r
Dreamer CMS v4.1.3 was discovered to contain an arbitrary file read vulnerability via the component /admin/TemplateContr
carRental 1.0 is vulnerable to Incorrect Access Control (Arbitrary File Read on the Back-end System).
Unauthenticated arbitrary file read in the IDAttend’s IDWeb application 3.1.013 allows the retrieval of any file present
The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listin
The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticate
An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers t
The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack
File accessibility vulnerability in Delinea Secret Server, in its v10.9.000002 and v11.4.000002 versions. Exploitation o
A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Telit Cinterion BGS5, Telit Cinte
Files or Directories Accessible to External Parties vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page mod
The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content
An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML fil
An attacker could bypass the latest Delta Electronics InfraSuite Device Master (versions prior to 1.0.7) patch, which c
In multiple Codesys products in multiple versions, after successful authentication as a user, specially crafted network
A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastr
The Front End PM WordPress plugin before 11.4.3 does not block listing the contents of the directories where it stores a
The File Manager WordPress plugin before 6.3 does not restrict the file managers root directory, allowing an administrat
Improper input validation vulnerability in ChooserActivity prior to SMR Nov-2023 Release 1 allows local attackers to rea
A CWE-552 "Files or Directories Accessible to External Parties” in the web interface of the Tyan S5552 BMC version 3.00
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to a
Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to
Inappropriate file type control in Zscaler Proxy versions 3.6.1.25 and prior allows local attackers to bypass file downl
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read i
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read i
An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connec
A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of
A Directory Browsing vulnerability in MCL-Net version 4.3.5.8788 webserver running on default port 5080, allows attacker
Files or Directories Accessible to External Parties in RDT400 in SICK APU allows an unprivileged remote attacker to dow
The WP Job Openings WordPress plugin before 3.4.3 does not block listing the contents of the directories where it stores
Tyler Technologies Court Case Management Plus may store backups in a location that can be accessed by a remote, unauthen
lmxcms v1.41 was discovered to contain an arbitrary file read vulnerability via TemplateAction.class.php.
Dell vApp Manager, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote malicious user with
A vulnerability was found in Xinhu RockOA 2.3.2. It has been classified as problematic. This affects the function start
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Monterey 12.6.3, macOS Ven
A vulnerability was found in Dreamer CMS up to 4.1.3. It has been classified as problematic. Affected is an unknown func
Frequently Asked Questions
What is CWE-552?
CWE-552 (CWE-552) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-552?
There are 583 CVE records associated with CWE-552 in our database. Of these, 48 are critical severity, 196 are high severity, and 223 are medium severity.
How can I protect against CWE-552 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-552 using AI-powered security agents.
Detect CWE-552 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-552 vulnerabilities across your infrastructure.
Get Started