VYPR

CWE-552

Files or Directories Accessible to External Parties

BaseDraft

Description

The product makes files or directories accessible to unauthorized actors, even though they should not be.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-150 · CAPEC-639

CVEs mapped to this weakness (493)

page 1 of 25
  • CVE-2025-11371HigKEVOct 9, 2025
    risk 0.71cvss 7.5epss 0.92

    In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild.  This issue impacts…

  • CVE-2024-6209CriJul 5, 2024
    risk 0.69cvss 10.0epss 0.17

    Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to access files unauthorized

  • CVE-2017-14942CriSep 30, 2017
    risk 0.69cvss 9.8epss 0.61

    Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg containing an admin:language=pt cookie.

  • CVE-2024-53676CriNov 27, 2024
    risk 0.68cvss 9.8epss 0.52

    A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.

  • CVE-2024-39931CriJul 4, 2024
    risk 0.68cvss 9.9epss 0.53

    Gogs through 0.13.0 allows deletion of internal files.

  • CVE-2025-41240CriJul 24, 2025
    risk 0.65cvss 10.0epss 0.01

    Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document root. In affected versions, this can lead to unauthenticated access to sensitive credentials via HTTP/S. A remote attacker could…

  • CVE-2024-2056CriMar 5, 2024
    risk 0.65cvss 9.8epss 0.17

    Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service is running, running as the root user, is bound to the loopback interface, and is listening on TCP port 7050. Security…

  • CVE-2020-17519HigKEVJan 5, 2021
    risk 0.65cvss 7.5epss 0.98

    A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager…

  • CVE-2026-40624CriJun 19, 2026
    risk 0.64cvss 9.8epss 0.01

    Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated attacker to achieve arbitrary code execution via a specially crafted web request.

  • CVE-2025-14771CriJun 3, 2026
    risk 0.64cvss 9.9epss 0.00

    Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

  • CVE-2019-25709CriApr 12, 2026
    risk 0.64cvss 9.8epss 0.01

    CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deserialized database and use them to delete…

  • CVE-2026-2331CriMar 6, 2026
    risk 0.64cvss 9.8epss 0.01

    An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature,…

  • CVE-2020-37082CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.01

    webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database backup files without authentication. Attackers can directly access generated backup files in the companies/weberp/ directory by requesting the…

  • CVE-2024-0949CriJun 27, 2024
    risk 0.64cvss 9.8epss 0.01

    Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass. This issue affects Elektraweb: before v17.0.68.

  • CVE-2024-2055CriMar 5, 2024
    risk 0.64cvss 9.8epss 0.01

    The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by default, and runs as the root user.

  • CVE-2023-5199CriOct 30, 2023
    risk 0.64cvss 9.9epss 0.01

    The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and including, 0.3 via the 'php-to-page' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to include local file and…

  • CVE-2021-32008CriMar 4, 2022
    risk 0.64cvss 9.9epss 0.01

    This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories.

  • CVE-2021-1361CriFeb 24, 2021
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the implementation of an internal file management service for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode that are running Cisco NX-OS Software could allow an unauthenticated, remote attacker to create,…

  • CVE-2020-10516CriJun 3, 2020
    risk 0.64cvss 9.8epss 0.02

    An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization member to escalate permissions and gain access to unauthorized repositories within an organization. This vulnerability affected all versions of GitHub…

  • CVE-2020-12743CriMay 11, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Gazie 7.32. A successful installation does not remove or block (or in any other way prevent use of) its own file /setup/install/setup.php, meaning that anyone can request it without authentication. This file allows arbitrary PHP file inclusion via a…