VYPR

CWE-552

Files or Directories Accessible to External Parties

BaseDraft

Description

The product makes files or directories accessible to unauthorized actors, even though they should not be.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-150 · CAPEC-639

CVEs mapped to this weakness (493)

page 11 of 25
  • CVE-2024-56462HigMay 27, 2026
    risk 0.47cvss 7.2epss 0.00

    IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive that could be restored and used to gain access to the underlying operating system.

  • CVE-2025-58356HigOct 27, 2025
    risk 0.47cvss epss 0.00

    Constellation is the first Confidential Kubernetes. The Constellation CVM image uses LUKS2-encrypted volumes for persistent storage. When opening an encrypted storage device, the CVM uses the libcryptsetup function crypt_activate_by_passhrase. If the VM is successful in opening…

  • CVE-2025-3025HigSep 15, 2025
    risk 0.47cvss 7.3epss 0.00

    Elevation of Privileges in the cleaning feature of Gen Digital CCleaner version 6.33.11465 on Windows allows a local user to gain SYSTEM privileges via exploiting insecure file delete operations. Reported in CCleaner v. 6.33.11465. This issue affects CCleaner: before <…

  • CVE-2025-4134HigMay 28, 2025
    risk 0.47cvss 7.3epss 0.00

    Lack of file validation in do_update_vps in Avast Business Antivirus for Linux 4.5 on Linux allows local user to spoof or tamper with the update file via an unverified file write.

  • CVE-2025-4909HigMay 19, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability classified as critical was found in SourceCodester Client Database Management System 1.0. This vulnerability affects unknown code. The manipulation leads to exposure of information through directory listing. The attack can be initiated remotely. The exploit has…

  • CVE-2025-2038HigMar 6, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /upload/. The manipulation leads to exposure of information through directory listing. The attack may be initiated…

  • CVE-2024-48647HigOct 30, 2024
    risk 0.47cvss 7.2epss 0.01

    A file disclosure vulnerability exists in Sage 1000 v7.0.0. This vulnerability allows remote attackers to retrieve arbitrary files from the server's file system by manipulating the URL parameter in HTTP requests. The attacker can exploit this flaw to access sensitive…

  • CVE-2024-39581HigSep 10, 2024
    risk 0.47cvss 7.3epss 0.00

    Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to read, modify, and delete arbitrary files.

  • CVE-2023-3155HigOct 16, 2023
    risk 0.47cvss 7.2epss 0.01

    The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.

  • CVE-2023-38948HigAug 3, 2023
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers to execute arbitrary code via downloading a crafted plugin.

  • CVE-2023-1124HigApr 3, 2023
    risk 0.47cvss 7.2epss 0.01

    The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticated users with admin privileges to perform LFI attacks.

  • CVE-2020-12470HigApr 29, 2020
    risk 0.47cvss 7.2epss 0.02

    MonoX through 5.1.40.5152 allows administrators to execute arbitrary code by modifying an ASPX template.

  • CVE-2018-9587HigFeb 11, 2019
    risk 0.47cvss 7.3epss 0.00

    In savePhotoFromUriToUri of ContactPhotoUtils.java in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is possible unauthorized access to files within the contact app due to a confused deputy scenario. This could lead to local escalation…

  • CVE-2025-45529HigMay 27, 2025
    risk 0.46cvss 7.1epss 0.00

    An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor.

  • CVE-2025-21264HigMay 13, 2025
    risk 0.46cvss 7.1epss 0.01

    Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2025-1982HigApr 16, 2025
    risk 0.46cvss epss 0.01

    Local File Inclusion vulnerability in Ready's attachment upload panel allows low privileged user to provide link to a local file using the file:// protocol thus allowing the attacker to read content of the file. This vulnerability can be use to read content of system files.

  • CVE-2025-27147HigMar 25, 2025
    risk 0.46cvss 8.2epss 0.00

    The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNMP), software deployment, VMWare ESX host remote inventory, and data collection (files, Windows registry, WMI). Versions prior to 1.5.0 have an improper access…

  • CVE-2025-22369HigMar 11, 2025
    risk 0.46cvss epss 0.00

    The ReadFile endpoint of the firmware for Mennekes Smart / Premium Chargingpoints can be abused to read arbitrary files from the underlying OS.

  • CVE-2024-11629HigFeb 12, 2025
    risk 0.46cvss 7.1epss 0.00

    In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, the contents of a file at an arbitrary path can be exported to RTF.

  • CVE-2023-33568HigJun 13, 2023
    risk 0.46cvss 7.5epss 0.15

    An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.