Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-552

MITRE ↗

CWE-552

48
CRITICAL
196
HIGH
223
MEDIUM
13
LOW
494 CVEs · Page 8/10
5.7
CVE-2022-23738

An improper cache key vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to acc

5.5
CVE-2022-23621

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver

5.5
CVE-2022-29302

SolarView Compact ver.6.00 was discovered to contain a local file disclosure via /html/Solar_Ftp.php.

5.5
CVE-2022-31475

Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.

5.5
CVE-2021-3800

A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by

5.5
CVE-2021-3995

A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmoun

5.5
CVE-2021-3996

A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmoun

5.5
CVE-2022-41710

Markdownify version 1.4.1 allows an external attacker to remotely obtain arbitrary local files on any client that attemp

5.3
CVE-2021-33843

Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An a

5.3
CVE-2022-25497

CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.

5.3
CVE-2022-34049

An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files a

5.3
CVE-2022-33901

Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin <= 4.13.1 at WordPress.

5.3
CVE-2022-2834

The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and gu

5.3
CVE-2022-43414

Jenkins NUnit Plugin 0.27 and earlier implements an agent-to-controller message that parses files inside a user-specifie

4.9
CVE-2022-23316

An issue was discovered in taoCMS v3.0.2. There is an arbitrary file read vulnerability that can read any files via admi

4.9
CVE-2021-44983

In taocms 3.0.1 after logging in to the background, there is an Arbitrary file download vulnerability at the File Manage

4.9
CVE-2021-25004

The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is u

4.9
CVE-2022-2222

The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog fold

4.9
CVE-2022-22490

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot cr

4.9
CVE-2022-35235

Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.

4.9
CVE-2022-2981

The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog fold

4.9
CVE-2022-44634

Auth. (admin+) Arbitrary File Read vulnerability in S2W – Import Shopify to WooCommerce plugin <= 1.1.12 on WordPress.

4.4
CVE-2022-22270

An implicit Intent hijacking vulnerability in Dialer prior to SMR Jan-2022 Release 1 allows unprivileged applications to

4.4
CVE-2022-27837

A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Androi

4.3
CVE-2021-20148

ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web roo

4.3
CVE-2022-24694

In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1, the names of folders in the Files area c

4.3
CVE-2021-3856

ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classl

4.0
CVE-2022-22267

Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get

4.0
CVE-2022-22269

Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applica

2.3
CVE-2022-33686

Exposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local attacker to access icc

9.9
CVE-2021-43821

Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast before version 9.10 or 10.6 allows

9.8
CVE-2021-1361

A vulnerability in the implementation of an internal file management service for Cisco Nexus 3000 Series Switches and Ci

9.1
CVE-2018-10867

Files are accessible without restrictions from the /update/results page of redhat-certification 7 package, allowing an a

8.8
CVE-2021-20182

A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs with high privileges us

8.8
CVE-2021-32688

Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens

8.8
CVE-2021-25741

A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts

8.6
CVE-2021-21355

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.

8.6
CVE-2021-32833

Emby Server is a personal media server with apps on many devices. In Emby Server on Windows there is a set of arbitrary

7.8
CVE-2021-22015

The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and

7.5
CVE-2020-17519 KEV

A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file

7.5
CVE-2021-29024

In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing a

7.5
CVE-2018-10863

It was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /

7.5
CVE-2021-33359

A vulnerability exists in gowitness < 2.3.6 that allows an unauthenticated attacker to perform an arbitrary file read us

7.5
CVE-2021-36763

In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.

7.5
CVE-2021-37348

Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation of a pathname in index.

7.5
CVE-2021-38711

In gitit before 0.15.0.0, the Export feature can be exploited to leak information from files.

7.5
CVE-2020-22124

A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information.

7.5
CVE-2021-39316

The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-c

7.5
CVE-2020-35340

A local file inclusion vulnerability in ExpertPDF 9.5.0 through 14.1.0 allows attackers to read the file contents from f

7.5
CVE-2021-41573

Hitachi Content Platform Anywhere (HCP-AW) 4.4.5 and later allows information disclosure. If authenticated user creates

Frequently Asked Questions

What is CWE-552?

CWE-552 (CWE-552) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-552?

There are 583 CVE records associated with CWE-552 in our database. Of these, 48 are critical severity, 196 are high severity, and 223 are medium severity.

How can I protect against CWE-552 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-552 using AI-powered security agents.

Detect CWE-552 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-552 vulnerabilities across your infrastructure.

Get Started