VYPR

CWE-552

Files or Directories Accessible to External Parties

BaseDraft

Description

The product makes files or directories accessible to unauthorized actors, even though they should not be.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-150 · CAPEC-639

CVEs mapped to this weakness (493)

page 7 of 25
  • CVE-2025-69428HigApr 27, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in Pro-Bit before v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdirectories.

  • CVE-2018-25164HigMar 6, 2026
    risk 0.49cvss 7.5epss 0.00

    EverSync 0.5 contains an arbitrary file download vulnerability that allows unauthenticated attackers to access sensitive files by requesting them directly from the files directory. Attackers can send GET requests to the files directory to download database files like db.sq3…

  • CVE-2026-25231HigFeb 9, 2026
    risk 0.49cvss 7.5epss 0.01

    FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 3.3.0, the application contains an unauthenticated file read vulnerability due to the lack of access control on the /uploads directory. Files uploaded to this directory can be accessed directly by any…

  • CVE-2019-25239HigDec 24, 2025
    risk 0.49cvss 7.5epss 0.00

    V-SOL GPON/EPON OLT Platform 2.03 contains an unauthenticated information disclosure vulnerability that allows attackers to download configuration files via direct object reference. Attackers can retrieve sensitive configuration data by sending HTTP GET requests to the…

  • CVE-2025-11965HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.00

    In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], a StaticHandler configuration for restricting access to hidden files fails to restrict access to hidden directories, allowing unauthorized users to retrieve files within them (e.g. '.git/config').

  • CVE-2024-4981HigMay 12, 2025
    risk 0.49cvss 7.6epss 0.00

    A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make visible content from outside the git repo.

  • CVE-2025-25759HigFeb 27, 2025
    risk 0.49cvss 7.5epss 0.01

    An issue in the component admin_template.php of SUCMS v1.0 allows attackers to execute a directory traversal and arbitrary file deletion via a crafted GET request.

  • CVE-2024-57452HigFeb 3, 2025
    risk 0.49cvss 7.5epss 0.00

    ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows attackers to delete any file and folder.

  • CVE-2024-43660HigJan 9, 2025
    risk 0.49cvss 7.5epss 0.01

    The CGI script .sh can be used to download any file on the filesystem. This issue affects Iocharger firmware for AC model chargers beforeversion 24120701. Likelihood: High, but credentials required. Impact: Critical – The script can be used to download any file on…

  • CVE-2024-52047HigDec 31, 2024
    risk 0.49cvss 7.5epss 0.01

    A widget local file inclusion vulnerability in Trend Micro Apex One could allow a remote attacker to execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to…

  • CVE-2024-10403HigNov 21, 2024
    risk 0.49cvss 7.5epss 0.01

    Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download operation initiated by SANnav or through WebEM in a weblinker core dump that is later captured via…

  • CVE-2024-49359HigOct 24, 2024
    risk 0.49cvss 7.5epss 0.01

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Zima_Server_IP:PORT>/v2_1/file` in ZimaOS is vulnerable to a directory traversal attack, allowing authenticated users…

  • CVE-2024-7107HigSep 26, 2024
    risk 0.49cvss 7.5epss 0.00

    Files or Directories Accessible to External Parties vulnerability in National Keep Cyber Security Services CyberMath allows Collect Data from Common Resource Locations. This issue affects CyberMath: before CYBM.240816253.

  • CVE-2023-49198HigAug 21, 2024
    risk 0.49cvss 7.5epss 0.01

    Mysql security vulnerability in Apache SeaTunnel. Attackers can read files on the MySQL server by modifying the information in the MySQL URL allowLoadLocalInfile=true&allowUrlInLocalInfile=true&allowLoadLocalInfileInPath=/&maxAllowedPacket=655360 This issue affects Apache…

  • CVE-2024-7729HigAug 14, 2024
    risk 0.49cvss 7.5epss 0.01

    The CAYIN Technology CMS lacks proper access control, allowing unauthenticated remote attackers to download arbitrary CGI files.

  • CVE-2024-38429HigJul 30, 2024
    risk 0.49cvss 7.5epss 0.00

    Matrix Tafnit v8 -  CWE-552: Files or Directories Accessible to External Parties

  • CVE-2024-6911HigJul 22, 2024
    risk 0.49cvss 7.5epss 0.05

    Files on the Windows system are accessible without authentication to external parties due to a local file inclusion in PerkinElmer ProcessPlus.This issue affects ProcessPlus: through 1.11.6507.0.

  • CVE-2024-6421HigJul 10, 2024
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP service.

  • CVE-2024-4836HigJul 2, 2024
    risk 0.49cvss 7.5epss 0.03

    Web services managed by Edito CMS (Content Management System) in versions from 3.5 through 3.25 leak sensitive data as they allow downloading configuration files by an unauthenticated user. The issue in versions 3.5 - 3.25 was removed in releases which dates from 10th of January…

  • CVE-2024-2759HigApr 4, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper access control vulnerability in Apaczka plugin for PrestaShop allows information gathering from saved templates without authentication.This issue affects Apaczka plugin for PrestaShop from v1 through v4.