VYPR

CWE-552

Files or Directories Accessible to External Parties

BaseDraft

Description

The product makes files or directories accessible to unauthorized actors, even though they should not be.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-150 · CAPEC-639

CVEs mapped to this weakness (493)

page 16 of 25
  • CVE-2020-3926MedFeb 3, 2020
    risk 0.40cvss 6.1epss 0.01

    An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter.

  • CVE-2025-25799MedFeb 26, 2025
    risk 0.39cvss 6.0epss 0.00

    SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php.

  • CVE-2023-2766MedMay 17, 2023
    risk 0.39cvss 5.3epss 0.54

    A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini. The manipulation leads to files or directories accessible. The attack may be initiated…

  • CVE-2021-40149MedJul 17, 2022
    risk 0.39cvss 5.9epss 0.07

    The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the /self.key URI.

  • CVE-2021-1512MedMay 6, 2021
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying file system of an affected system. This vulnerability is due to insufficient validation of the user-supplied input parameters of a…

  • CVE-2021-1256MedApr 29, 2021
    risk 0.39cvss 6.0epss 0.01

    A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite files on the file system of an affected device by using directory traversal techniques. A successful exploit could cause system instability if…

  • CVE-2020-3476MedSep 24, 2020
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the CLI implementation of a specific command of Cisco IOS XE Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying host file system. The vulnerability is due to insufficient validation of the parameters of a…

  • CVE-2026-54457higJul 15, 2026
    risk 0.38cvss epss

    ### Impact The `/internal/object_storage` endpoint accepts a caller-supplied JSON `storage_path` parameter that dynamically overrides the TensorZero `[object_storage]` configuration. By abusing the `filesystem` storage type, a caller can read arbitrary files from the gateway…

  • CVE-2025-48928MedKEVMay 28, 2025
    risk 0.38cvss 4.0epss 0.01

    The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025.

  • CVE-2024-45627MedJan 14, 2025
    risk 0.38cvss 5.9epss 0.00

    In Apache Linkis <1.7.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will allow the attacker to read arbitrary files from the Linkis server. Therefore, the parameters in the…

  • CVE-2024-3913MedAug 13, 2024
    risk 0.38cvss 5.9epss 0.01

    An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup.

  • CVE-2023-2538MedJul 5, 2023
    risk 0.38cvss 5.8epss 0.00

    A CWE-552 "Files or Directories Accessible to External Parties” in the web interface of the Tyan S5552 BMC version 3.00 allows an unauthenticated remote attacker to retrieve the private key of the TLS certificate in use by the BMC via forced browsing. This can then be abused…

  • CVE-2023-34834MedJun 29, 2023
    risk 0.38cvss 5.3epss 0.04

    A Directory Browsing vulnerability in MCL-Net version 4.3.5.8788 webserver running on default port 5080, allows attackers to gain sensitive information about the configured databases via the "/file" endpoint.

  • CVE-2021-29969MedAug 5, 2021
    risk 0.38cvss 5.9epss 0.01

    If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS handshake, then Thunderbird didn't ignore the injected data. This could have resulted in Thunderbird showing incorrect…

  • CVE-2019-7305MedApr 10, 2020
    risk 0.38cvss 5.8epss 0.02

    Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible over HTTP. Introduced in the Makefile patch file debian/patches/debian-changes-2.1.0b6+dfsg-1 or debian/patches/adds-a-makefile.patch, this can lead to data…

  • CVE-2017-2622MedJul 27, 2018
    risk 0.38cvss 5.9epss 0.00

    An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.

  • CVE-2026-40425MedMay 29, 2026
    risk 0.37cvss 5.7epss 0.00

    The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password.

  • CVE-2026-32750MedMar 19, 2026
    risk 0.37cvss 6.8epss 0.00

    SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importStdMd passes the localPath parameter directly to model.ImportFromLocalPath with zero path validation. The function recursively reads every file under the given path and…

  • CVE-2022-23738MedNov 1, 2022
    risk 0.37cvss 5.7epss 0.01

    An improper cache key vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to access private repository files through a public repository. To exploit this, an actor would need to already be authorized on the GitHub Enterprise Server…

  • CVE-2021-35203MedSep 30, 2021
    risk 0.37cvss 5.7epss 0.01

    NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Arbitrary File Read operations via the FDSQueryService endpoint.