VYPR

CWE-552

Files or Directories Accessible to External Parties

BaseDraft

Description

The product makes files or directories accessible to unauthorized actors, even though they should not be.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-150 · CAPEC-639

CVEs mapped to this weakness (493)

page 3 of 25
  • CVE-2026-40631HigMay 13, 2026
    risk 0.57cvss 8.7epss 0.00

    An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2026-33698CriApr 10, 2026
    risk 0.57cvss 9.8epss 0.00

    Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ directory and allow an unauthenticated attacker to modify existing files or create new files where allowed by system permissions. This…

  • CVE-2016-20025HigMar 16, 2026
    risk 0.57cvss 8.8epss 0.00

    ZKTeco ZKAccess Professional 3.5.3 contains an insecure file permissions vulnerability that allows authenticated users to escalate privileges by modifying executable files. Attackers can leverage the Modify permission granted to the Authenticated Users group to replace…

  • CVE-2025-68719HigJan 8, 2026
    risk 0.57cvss 8.8epss 0.00

    KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 mishandle configuration management. Once any user is logged in and maintains an active session, an attacker can directly query the backup endpoint and download a full configuration archive. This archive contains sensitive files…

  • CVE-2021-4463HigNov 12, 2025
    risk 0.57cvss epss 0.01

    Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulnerability in the 'downloads' endpoint. The 'fileName' parameter is not properly sanitized, allowing attackers to craft traversal sequences and access sensitive…

  • CVE-2025-34139HigJul 25, 2025
    risk 0.57cvss epss 0.00

    A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud that could allow an unauthenticated attacker to read arbitrary files. This vulnerability affects all Experience Platform topologies (XM, XP, XC)…

  • CVE-2025-34110CriJul 15, 2025
    risk 0.57cvss epss 0.01

    A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated attackers to read or write arbitrary files outside the configured FTP root directory. The flaw is due to insufficient sanitation of user-supplied file paths in…

  • CVE-2024-50627HigDec 9, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Privilege Escalation vulnerability exists in the file upload feature. It allows an attacker on the local area network (with specific permissions) to upload and execute malicious files, potentially leading to…

  • CVE-2024-36442HigAug 22, 2024
    risk 0.57cvss 8.8epss 0.01

    cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an authenticated attacker to gain access to arbitrary files on the device's file system.

  • CVE-2024-4098CriJun 20, 2024
    risk 0.57cvss 9.8epss 0.01

    The Shariff Wrapper plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6.13 via the shariff3uu_fetch_sharecounts function. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the…

  • CVE-2024-5262CriJun 5, 2024
    risk 0.57cvss 9.8epss 0.01

    Files or Directories Accessible to External Parties vulnerability in smb server in ProjectDiscovery Interactsh allows remote attackers to read/write any files in the directory and subdirectories of where the victim runs interactsh-server via anonymous login.

  • CVE-2024-3564HigJun 1, 2024
    risk 0.57cvss 8.8epss 0.01

    The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the plugin's 'content_block' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above,…

  • CVE-2023-39479HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.02

    Softing Secure Integration Server OPC UA Gateway Directory Creation Vulnerability. This vulnerability allows remote attackers to create directories on affected installations of Softing Secure Integration Server. Although authentication is required to exploit this vulnerability,…

  • CVE-2023-39545HigNov 17, 2023
    risk 0.57cvss 8.8epss 0.01

    CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command.

  • CVE-2023-45160HigOct 5, 2023
    risk 0.57cvss 8.8epss 0.01

    In the affected version of the 1E Client, an ordinary user could subvert downloaded instruction resource files, e.g., to substitute a harmful script. by replacing a resource script file created by an instruction at run time with a malicious script. The 1E Client's temporary…

  • CVE-2023-29931CriJun 22, 2023
    risk 0.57cvss 9.8epss 0.01

    laravel-s 3.7.35 is vulnerable to Local File Inclusion via /src/Illuminate/Laravel.php.

  • CVE-2023-0822HigFeb 17, 2023
    risk 0.57cvss 8.8epss 0.01

    The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization, which could allow an unauthorized user to bypass authorization and access privileged functionality.

  • CVE-2022-45052HigJan 4, 2023
    risk 0.57cvss 8.8epss 0.01

    A Local File Inclusion vulnerability has been found in Axiell Iguana CMS. Due to insufficient neutralisation of user input on the url parameter on the Proxy.type.php endpoint, external users are capable of accessing files on the server.

  • CVE-2022-42234HigOct 14, 2022
    risk 0.57cvss 8.8epss 0.01

    There is a file inclusion vulnerability in the template management module in UCMS 1.6

  • CVE-2021-4112HigAug 25, 2022
    risk 0.57cvss 8.8epss 0.00

    A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment.