In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to
Ether Logs is a package that allows one to check one's logs in the Craft 3 utilities section. A vulnerability was found
A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker t
An information disclosure vulnerability in rConfig 3.9.5 has been fixed for version 3.9.6. This vulnerability allowed re
The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacke
A denial-of-service vulnerability in Database Security (DBS) prior to 4.8.4 allows a remote authenticated administrator
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary
If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses pri
NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Arbitrary File Read operations via the FDSQueryService endpoint.
Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /ic
Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource fr
Trend Micro Security 2021 v17.0 (Consumer) contains a vulnerability that allows files inside the protected folder to be
It has been discovered in redhat-certification that any unauthorized user may download any file under /var/www/rhcert, p
The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_f
Incorrect access to deleted scripts vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote aut
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to overwrite arb
A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1
A vulnerability in the web UI for Cisco Nexus Insights could allow an authenticated, remote attacker to view and downloa
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The
OpenAPI Generator allows generation of API client libraries, server stubs, documentation and configuration automatically
Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get
Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credent
An issue was discovered in Gazie 7.32. A successful installation does not remove or block (or in any other way prevent u
An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization
An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific
Zoom Client for Meetings through 4.6.8 on macOS copies runwithroot to a user-writable temporary directory during install
Dell PowerProtect Data Manager (PPDM) versions prior to 19.4 and Dell PowerProtect X400 versions prior to 3.2 contain an
A local file inclusion vulnerability in B&R SiteManager versions <9.2.620236042 allows authenticated users to read sensi
The local file inclusion vulnerability present in B&R SiteManager versions <9.2.620236042 allows authenticated users to
In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the
A vulnerability has been identified in OZW672 (All versions < V10.00), OZW772 (All versions < V10.00). Vulnerable versio
In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were b
By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htacce
An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests t
In GLPI before version 9.5.2, the `pluginimage.send.php` endpoint allows a user to specify an image from a plugin. The
MonoX through 5.1.40.5152 allows administrators to execute arbitrary code by modifying an ASPX template.
A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated,
In Elide before 4.5.14, it is possible for an adversary to "guess and check" the value of a model field they do not have
In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, arbitrary local file read is possible by defining unsafe win
In Open Enclave before version 0.12.0, an information disclosure vulnerability exists when an enclave application using
Dell EMC NetWorker versions prior to 19.3.0.2 contain an incorrect privilege assignment vulnerability. A non-LDAP remote
Dell EMC NetWorker versions prior to 19.3.0.2 contain an improper authorization vulnerability. Certain remote users with
A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file t
An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific
A vulnerability in the CLI implementation of a specific command of Cisco IOS XE Software could allow an authenticated, l
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volum
Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible
An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS
Frequently Asked Questions
What is CWE-552?
CWE-552 (CWE-552) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-552?
There are 583 CVE records associated with CWE-552 in our database. Of these, 48 are critical severity, 196 are high severity, and 223 are medium severity.
How can I protect against CWE-552 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-552 using AI-powered security agents.
Detect CWE-552 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-552 vulnerabilities across your infrastructure.
Get Started