Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to version 0.16.0, a virtual mac
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname
This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_uplo
In multiple CODESYS products, file download and upload function allows access to internal files in the working directory
A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows
There is a file inclusion vulnerability in the template management module in UCMS 1.6
An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible
A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how glibc names the runtime lin
A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may l
IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramD
Trend Micro VPN Proxy Pro version 5.2.1026 and below contains a vulnerability involving some overly permissive folders i
A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows attackers to escalate privi
An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_2
This affects the package drogonframework/drogon before 1.7.5. The unsafe handling of file names during upload using Http
HorizontCMS v1.0.0-beta.2 was discovered to contain an arbitrary file download vulnerability via the component /admin/fi
Archeevo below 5.0 is affected by local file inclusion through file=~/web.config to allow an attacker to retrieve local
74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controlle
Movie Seat Reservation v1 was discovered to contain an unauthenticated file disclosure vulnerability via /index.php?page
The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url
novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.
In ginadmin through 05-10-2022, the incoming path value is not filtered, resulting in arbitrary file reading.
74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Downlo
The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapp
The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download func
The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file download feature to download
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. All files in the /opt/onedev/sites/ directory ar
registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure doe
Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different
Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.
The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL
WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access contr
The web portal of Dragino Lora LG01 18ed40 IoT v4.3.4 has the directory listing at the URL https://10.10.20.74/lib/. Thi
The Wholesale Market for WooCommerce WordPress plugin before 1.0.7 does not have authorisation check, as well as does no
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugi
Authenticated (administrator or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Hover Effect
Whale browser before 3.12.129.18 allowed extensions to replace JavaScript files of the HWP viewer website which could ac
Asana Desktop before 1.6.0 allows remote attackers to exfiltrate local files if they can trick the Asana desktop app int
KiteCMS v1.1.1 was discovered to contain an arbitrary file read vulnerability via the background management module.
cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file informa
An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS pri
The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that ca
When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/re
Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery.
The sourceMapURL feature in devtools was missing security checks that would have allowed a webpage to attempt to include
Some Dahua software products have a vulnerability of unrestricted download of file. After obtaining the permissions of o
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.7.3). The affected application uses a
OpenHarmony-v3.1.2 and prior versions had an Arbitrary file read vulnerability via download_server. Local attackers can
Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporar
The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory.
Frequently Asked Questions
What is CWE-552?
CWE-552 (CWE-552) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-552?
There are 583 CVE records associated with CWE-552 in our database. Of these, 48 are critical severity, 196 are high severity, and 223 are medium severity.
How can I protect against CWE-552 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-552 using AI-powered security agents.
Detect CWE-552 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-552 vulnerabilities across your infrastructure.
Get Started