An improper cache key vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to acc
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver
SolarView Compact ver.6.00 was discovered to contain a local file disclosure via /html/Solar_Ftp.php.
Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.
A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmoun
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmoun
Markdownify version 1.4.1 allows an external attacker to remotely obtain arbitrary local files on any client that attemp
Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An a
CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.
An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files a
Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin <= 4.13.1 at WordPress.
The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and gu
Jenkins NUnit Plugin 0.27 and earlier implements an agent-to-controller message that parses files inside a user-specifie
An issue was discovered in taoCMS v3.0.2. There is an arbitrary file read vulnerability that can read any files via admi
In taocms 3.0.1 after logging in to the background, there is an Arbitrary file download vulnerability at the File Manage
The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is u
The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog fold
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot cr
Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.
The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog fold
Auth. (admin+) Arbitrary File Read vulnerability in S2W – Import Shopify to WooCommerce plugin <= 1.1.12 on WordPress.
An implicit Intent hijacking vulnerability in Dialer prior to SMR Jan-2022 Release 1 allows unprivileged applications to
A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Androi
ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web roo
In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1, the names of folders in the Files area c
ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classl
Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get
Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applica
Exposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local attacker to access icc
Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast before version 9.10 or 10.6 allows
A vulnerability in the implementation of an internal file management service for Cisco Nexus 3000 Series Switches and Ci
Files are accessible without restrictions from the /update/results page of redhat-certification 7 package, allowing an a
A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs with high privileges us
Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.
Emby Server is a personal media server with apps on many devices. In Emby Server on Windows there is a set of arbitrary
The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and
A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file
In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing a
It was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /
A vulnerability exists in gowitness < 2.3.6 that allows an unauthenticated attacker to perform an arbitrary file read us
In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.
Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation of a pathname in index.
In gitit before 0.15.0.0, the Export feature can be exploited to leak information from files.
A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information.
The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-c
A local file inclusion vulnerability in ExpertPDF 9.5.0 through 14.1.0 allows attackers to read the file contents from f
Hitachi Content Platform Anywhere (HCP-AW) 4.4.5 and later allows information disclosure. If authenticated user creates
Frequently Asked Questions
What is CWE-552?
CWE-552 (CWE-552) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-552?
There are 583 CVE records associated with CWE-552 in our database. Of these, 48 are critical severity, 196 are high severity, and 223 are medium severity.
How can I protect against CWE-552 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-552 using AI-powered security agents.
Detect CWE-552 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-552 vulnerabilities across your infrastructure.
Get Started