Перейти к содержимому
Noroxi

CWE-552 · 418 записей

Files or Directories Accessible to External Parties

CVE этого класса

418 записей

  • CVE-2020-17519
    89Срочно

    Apache Flink directory traversal attack: reading remote files through the REST API

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 98 %

    apache · flink5 янв. 2021 г.

  • CVE-2025-11371
    88Срочно

    Gladinet CentreStack and TrioFox Local File Inclusion Flaw

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 92 %

    gladinet · centrestack9 окт. 2025 г.

  • CVE-2016-3715
    75На этой неделе

    The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted im

    СредняяCVSS 5,5KEVГотовый эксплойтEPSS 75 %

    imagemagick · imagemagick5 мая 2016 г.

  • CVE-2017-16651
    75На этой неделе

    Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's file

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 46 %

    roundcube · webmail9 нояб. 2017 г.

  • CVE-2023-50164
    63На этой неделе

    Apache Struts: File upload component had a directory traversal vulnerability

    КритическаяCVSS 9,8Proof of conceptEPSS 81 %

    apache · struts7 дек. 2023 г.

  • CVE-2020-15175
    57В плане

    Unauthenticated File Deletion in GLPI

    КритическаяCVSS 9,1Proof of conceptEPSS 72 %

    glpi-project · glpi7 окт. 2020 г.

  • CVE-2017-14942
    57В плане

    Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct reques

    КритическаяCVSS 9,8Proof of conceptEPSS 61 %

    intelbras · wrn 150 firmware29 сент. 2017 г.

  • CVE-2024-53676
    56В плане

    A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.

    КритическаяCVSS 9,8Эксплойта нетEPSS 56 %

    hpe · insight remote support26 нояб. 2024 г.

  • CVE-2024-39931
    55В плане

    Gogs through 0.13.0 allows deletion of internal files.

    КритическаяCVSS 9,9Эксплойта нетEPSS 53 %

    gogs · gogs4 июл. 2024 г.

  • CVE-2023-2766
    46В плане

    Weaver OA jx2_config.ini file access

    ВысокаяCVSS 7,5Proof of conceptEPSS 54 %

    weaver · e-office17 мая 2023 г.

  • CVE-2024-6209
    42В плане

    unauthorized file access

    КритическаяCVSS 9,4Proof of conceptEPSS 17 %

    abb · aspect-ent-12 firmware5 июл. 2024 г.

  • CVE-2025-41240
    40В плане

    Mounted Kubernetes Secrets under a predictable path located within the web server document root

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    vmware · bitnamicharts/appsmith24 июл. 2025 г.

  • CVE-2026-71379
    40В плане

    Toptech TMS7 and TopHAT Files or Directories Accessible to External Parties

    КритическаяCVSS 10,0Эксплойта нет

    toptech systems · tms7Сегодня

  • CVE-2023-6114
    39Наблюдать

    Duplicator < 1.5.7.1; Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Data Exposure

    ВысокаяCVSS 7,5Proof of conceptEPSS 31 %

    awesomemotive · duplicator26 дек. 2023 г.

  • CVE-2015-5211
    39Наблюдать

    Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to

    КритическаяCVSS 9,6Эксплойта нетEPSS 3 %

    vmware · spring framework25 мая 2017 г.

  • CVE-2020-12743
    39Наблюдать

    An issue was discovered in Gazie 7.32.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    gazie project · gazie11 мая 2020 г.

  • CVE-2024-56731
    39Наблюдать

    Gogs deletion of internal files allows remote command execution

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    gogs · gogs24 июн. 2025 г.

  • CVE-2017-10930
    39Наблюдать

    The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being a

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    zte · zxr10 1800-2s firmware19 сент. 2017 г.

  • CVE-2023-29931
    39Наблюдать

    laravel-s 3.7.35 is vulnerable to Local File Inclusion via /src/Illuminate/Laravel.php.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    laravels project · laravels22 июн. 2023 г.

  • CVE-2026-2331
    39Наблюдать

    An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due t

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    sick ag · sick lector85x6 мар. 2026 г.

  • CVE-2023-48710
    39Наблюдать

    iTop limit pages/exec.php script to PHP files

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    combodo · itop15 апр. 2024 г.

  • CVE-2024-39581
    39Наблюдать

    Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulnerability.

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    dell · insightiq10 сент. 2024 г.

  • CVE-2026-8715
    38Наблюдать

    Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath

    КритическаяCVSS 9,6Эксплойта нетEPSS 0 %

    hashicorp · tooling13 авг. 2026 г.

  • CVE-2025-11919
    38Наблюдать

    Unprotected temporary directories in Wolfram Cloud may result in privilege escalation

    КритическаяCVSS 9,6Эксплойта нетEPSS 0 %

    wolfram research inc. · cloud26 июн. 2026 г.

  • CVE-2025-32819
    37Наблюдать

    A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete

    ВысокаяCVSS 8,8Эксплойта нетEPSS 6 %

    sonicwall · sma 100 firmware7 мая 2025 г.

Все классы уязвимостей