CWE-552 · 418 записей
Files or Directories Accessible to External Parties
CVE этого класса
418 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
89Срочно | CVE-2020-17519Готовый эксплойт | Apache Flink directory traversal attack: reading remote files through the REST APIapache · flink · CWE-552 | Высокая7,5 | KEV | 97,8 % | 5 янв. 2021 г. |
88Срочно | CVE-2025-11371Готовый эксплойт | Gladinet CentreStack and TrioFox Local File Inclusion Flawgladinet · centrestack · CWE-552 | Высокая7,5 | KEV | 92,1 % | 9 окт. 2025 г. |
75На этой неделе | CVE-2016-3715Готовый эксплойт | The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted imimagemagick · imagemagick · CWE-552 | Средняя5,5 | KEV | 75,3 % | 5 мая 2016 г. |
75На этой неделе | CVE-2017-16651Готовый эксплойт | Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's fileroundcube · webmail · CWE-552 | Высокая7,8 | KEV | 45,7 % | 9 нояб. 2017 г. |
63На этой неделе | CVE-2023-50164Proof of concept | Apache Struts: File upload component had a directory traversal vulnerabilityapache · struts · CWE-552 | Критическая9,8 | — | 80,8 % | 7 дек. 2023 г. |
57В плане | CVE-2020-15175Proof of concept | Unauthenticated File Deletion in GLPIglpi-project · glpi · CWE-552 | Критическая9,1 | — | 71,6 % | 7 окт. 2020 г. |
57В плане | CVE-2017-14942Proof of concept | Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct requesintelbras · wrn 150 firmware · CWE-552 | Критическая9,8 | — | 60,9 % | 29 сент. 2017 г. |
56В плане | CVE-2024-53676Эксплойта нет | A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.hpe · insight remote support · CWE-552 | Критическая9,8 | — | 56,3 % | 26 нояб. 2024 г. |
55В плане | CVE-2024-39931Эксплойта нет | Gogs through 0.13.0 allows deletion of internal files.gogs · gogs · CWE-552 | Критическая9,9 | — | 52,7 % | 4 июл. 2024 г. |
46В плане | CVE-2023-2766Proof of concept | Weaver OA jx2_config.ini file accessweaver · e-office · CWE-552 | Высокая7,5 | — | 54,2 % | 17 мая 2023 г. |
42В плане | CVE-2024-6209Proof of concept | unauthorized file accessabb · aspect-ent-12 firmware · CWE-552 | Критическая9,4 | — | 17,2 % | 5 июл. 2024 г. |
40В плане | CVE-2025-41240Эксплойта нет | Mounted Kubernetes Secrets under a predictable path located within the web server document rootvmware · bitnamicharts/appsmith · CWE-552 | Критическая10,0 | — | 0,7 % | 24 июл. 2025 г. |
40В плане | CVE-2026-71379Эксплойта нет | Toptech TMS7 and TopHAT Files or Directories Accessible to External Partiestoptech systems · tms7 · CWE-552 | Критическая10,0 | — | — | Сегодня |
39Наблюдать | CVE-2023-6114Proof of concept | Duplicator < 1.5.7.1; Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Data Exposureawesomemotive · duplicator · CWE-552 | Высокая7,5 | — | 30,9 % | 26 дек. 2023 г. |
39Наблюдать | CVE-2015-5211Эксплойта нет | Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to vmware · spring framework · CWE-552 | Критическая9,6 | — | 2,6 % | 25 мая 2017 г. |
39Наблюдать | CVE-2020-12743Эксплойта нет | An issue was discovered in Gazie 7.32.gazie project · gazie · CWE-552 | Критическая9,8 | — | 1,5 % | 11 мая 2020 г. |
39Наблюдать | CVE-2024-56731Эксплойта нет | Gogs deletion of internal files allows remote command executiongogs · gogs · CWE-552 | Критическая9,8 | — | 1,2 % | 24 июн. 2025 г. |
39Наблюдать | CVE-2017-10930Эксплойта нет | The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being azte · zxr10 1800-2s firmware · CWE-552 | Критическая9,8 | — | 1,1 % | 19 сент. 2017 г. |
39Наблюдать | CVE-2023-29931Эксплойта нет | laravel-s 3.7.35 is vulnerable to Local File Inclusion via /src/Illuminate/Laravel.php.laravels project · laravels · CWE-552 | Критическая9,8 | — | 0,9 % | 22 июн. 2023 г. |
39Наблюдать | CVE-2026-2331Эксплойта нет | An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due tsick ag · sick lector85x · CWE-552 | Критическая9,8 | — | 0,9 % | 6 мар. 2026 г. |
39Наблюдать | CVE-2023-48710Эксплойта нет | iTop limit pages/exec.php script to PHP filescombodo · itop · CWE-552 | Критическая9,8 | — | 0,7 % | 15 апр. 2024 г. |
39Наблюдать | CVE-2024-39581Эксплойта нет | Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulnerability.dell · insightiq · CWE-552 | Критическая9,8 | — | 0,4 % | 10 сент. 2024 г. |
38Наблюдать | CVE-2026-8715Эксплойта нет | Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPathhashicorp · tooling · CWE-552 | Критическая9,6 | — | 0,5 % | 13 авг. 2026 г. |
38Наблюдать | CVE-2025-11919Эксплойта нет | Unprotected temporary directories in Wolfram Cloud may result in privilege escalationwolfram research inc. · cloud · CWE-552 | Критическая9,6 | — | 0,4 % | 26 июн. 2026 г. |
37Наблюдать | CVE-2025-32819Эксплойта нет | A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete sonicwall · sma 100 firmware · CWE-552 | Высокая8,8 | — | 6,4 % | 7 мая 2025 г. |
- CVE-2020-1751989Срочно
Apache Flink directory traversal attack: reading remote files through the REST API
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 98 %apache · flink5 янв. 2021 г.
- CVE-2025-1137188Срочно
Gladinet CentreStack and TrioFox Local File Inclusion Flaw
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 92 %gladinet · centrestack9 окт. 2025 г.
- CVE-2016-371575На этой неделе
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted im
СредняяCVSS 5,5KEVГотовый эксплойтEPSS 75 %imagemagick · imagemagick5 мая 2016 г.
- CVE-2017-1665175На этой неделе
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's file
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 46 %roundcube · webmail9 нояб. 2017 г.
- CVE-2023-5016463На этой неделе
Apache Struts: File upload component had a directory traversal vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 81 %apache · struts7 дек. 2023 г.
- CVE-2020-1517557В плане
Unauthenticated File Deletion in GLPI
КритическаяCVSS 9,1Proof of conceptEPSS 72 %glpi-project · glpi7 окт. 2020 г.
- CVE-2017-1494257В плане
Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct reques
КритическаяCVSS 9,8Proof of conceptEPSS 61 %intelbras · wrn 150 firmware29 сент. 2017 г.
- CVE-2024-5367656В плане
A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.
КритическаяCVSS 9,8Эксплойта нетEPSS 56 %hpe · insight remote support26 нояб. 2024 г.
- CVE-2024-3993155В плане
Gogs through 0.13.0 allows deletion of internal files.
КритическаяCVSS 9,9Эксплойта нетEPSS 53 %gogs · gogs4 июл. 2024 г.
- CVE-2023-276646В плане
Weaver OA jx2_config.ini file access
ВысокаяCVSS 7,5Proof of conceptEPSS 54 %weaver · e-office17 мая 2023 г.
- CVE-2024-620942В плане
unauthorized file access
КритическаяCVSS 9,4Proof of conceptEPSS 17 %abb · aspect-ent-12 firmware5 июл. 2024 г.
- CVE-2025-4124040В плане
Mounted Kubernetes Secrets under a predictable path located within the web server document root
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %vmware · bitnamicharts/appsmith24 июл. 2025 г.
- CVE-2026-7137940В плане
Toptech TMS7 and TopHAT Files or Directories Accessible to External Parties
КритическаяCVSS 10,0Эксплойта нетtoptech systems · tms7Сегодня
- CVE-2023-611439Наблюдать
Duplicator < 1.5.7.1; Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Data Exposure
ВысокаяCVSS 7,5Proof of conceptEPSS 31 %awesomemotive · duplicator26 дек. 2023 г.
- CVE-2015-521139Наблюдать
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to
КритическаяCVSS 9,6Эксплойта нетEPSS 3 %vmware · spring framework25 мая 2017 г.
- CVE-2020-1274339Наблюдать
An issue was discovered in Gazie 7.32.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %gazie project · gazie11 мая 2020 г.
- CVE-2024-5673139Наблюдать
Gogs deletion of internal files allows remote command execution
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gogs · gogs24 июн. 2025 г.
- CVE-2017-1093039Наблюдать
The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being a
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zte · zxr10 1800-2s firmware19 сент. 2017 г.
- CVE-2023-2993139Наблюдать
laravel-s 3.7.35 is vulnerable to Local File Inclusion via /src/Illuminate/Laravel.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %laravels project · laravels22 июн. 2023 г.
- CVE-2026-233139Наблюдать
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due t
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sick ag · sick lector85x6 мар. 2026 г.
- CVE-2023-4871039Наблюдать
iTop limit pages/exec.php script to PHP files
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %combodo · itop15 апр. 2024 г.
- CVE-2024-3958139Наблюдать
Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %dell · insightiq10 сент. 2024 г.
- CVE-2026-871538Наблюдать
Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath
КритическаяCVSS 9,6Эксплойта нетEPSS 0 %hashicorp · tooling13 авг. 2026 г.
- CVE-2025-1191938Наблюдать
Unprotected temporary directories in Wolfram Cloud may result in privilege escalation
КритическаяCVSS 9,6Эксплойта нетEPSS 0 %wolfram research inc. · cloud26 июн. 2026 г.
- CVE-2025-3281937Наблюдать
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete
ВысокаяCVSS 8,8Эксплойта нетEPSS 6 %sonicwall · sma 100 firmware7 мая 2025 г.