VYPR

CWE-552

Files or Directories Accessible to External Parties

BaseDraft

Description

The product makes files or directories accessible to unauthorized actors, even though they should not be.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-150 · CAPEC-639

CVEs mapped to this weakness (493)

page 18 of 25
  • CVE-2026-40564MedMay 26, 2026
    risk 0.35cvss 6.5epss 0.00

    Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI is currently not validated so that it points to user-owned files or addresses.  This lets a user with CR…

  • CVE-2026-7817MedMay 11, 2026
    risk 0.35cvss 6.5epss 0.00

    Local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities in pgAdmin 4 LLM API configuration endpoints. User-supplied api_key_file and api_url preferences were passed to the LLM provider clients without validation. An authenticated user could read…

  • CVE-2025-51818MedAug 21, 2025
    risk 0.35cvss 5.4epss 0.00

    MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute arbitrary commands

  • CVE-2025-5273MedMay 29, 2025
    risk 0.35cvss 6.5epss 0.00

    Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Files or Directories Accessible to External Parties via the get-markdown-file tool. An attacker can craft a prompt that, once accessed by the MCP host, will allow it to read arbitrary files from the…

  • CVE-2025-4807MedMay 16, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, was found in SourceCodester Online Student Clearance System 1.0. This affects an unknown part. The manipulation leads to exposure of information through directory listing. It is possible to initiate the attack remotely. The…

  • CVE-2025-2652MedMar 23, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to exposure of information through directory listing. The attack…

  • CVE-2025-2651MedMar 23, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /oews/admin/. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack…

  • CVE-2024-48019MedFeb 4, 2025
    risk 0.35cvss 5.4epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in Apache Doris. Application administrators can read arbitrary files from the server filesystem through path traversal. Users are…

  • CVE-2024-32498MedJul 5, 2024
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may…

  • CVE-2024-1005MedJan 29, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This vulnerability affects unknown code of the file /runtime/log. The manipulation leads to files or directories accessible. The attack can be initiated remotely. The…

  • CVE-2023-6375MedNov 30, 2023
    risk 0.35cvss 5.3epss 0.01

    Tyler Technologies Court Case Management Plus may store backups in a location that can be accessed by a remote, unauthenticated attacker. Backups may contain sensitive information such as database credentials.

  • CVE-2023-20184MedMay 18, 2023
    risk 0.35cvss 5.4epss 0.00

    Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user. For more…

  • CVE-2023-20183MedMay 18, 2023
    risk 0.35cvss 5.4epss 0.00

    Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user. For more…

  • CVE-2023-29107MedMay 9, 2023
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The export endpoint discloses some undocumented files. This could allow an unauthenticated remote attacker to gain…

  • CVE-2022-47950MedJan 18, 2023
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to…

  • CVE-2022-2834MedOct 17, 2022
    risk 0.35cvss 5.3epss 0.01

    The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Email Address depending on the plugin's…

  • CVE-2022-33901MedJul 22, 2022
    risk 0.35cvss 5.3epss 0.03

    Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin <= 4.13.1 at WordPress.

  • CVE-2022-34049MedJul 20, 2022
    risk 0.35cvss 5.3epss 0.03

    An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.

  • CVE-2022-25497MedMar 15, 2022
    risk 0.35cvss 5.3epss 0.04

    CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.

  • CVE-2021-33843MedJan 21, 2022
    risk 0.35cvss 5.3epss 0.01

    Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An attacker may use this functionality to change the exposed configuration values such as network settings.