İçeriğe atla
Noroxi

CWE-552 · 418 kayıt

Files or Directories Accessible to External Parties

Bu sınıftaki CVE’ler

418 kayıt

  • Apache Flink directory traversal attack: reading remote files through the REST API

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %98

    apache · flink5 Oca 2021

  • Gladinet CentreStack and TrioFox Local File Inclusion Flaw

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %92

    gladinet · centrestack9 Eki 2025

  • CVE-2016-3715
    75Bu hafta

    The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted im

    OrtaCVSS 5,5KEVSilahlaştırılmışEPSS %75

    imagemagick · imagemagick5 May 2016

  • CVE-2017-16651
    75Bu hafta

    Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's file

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %46

    roundcube · webmail9 Kas 2017

  • CVE-2023-50164
    63Bu hafta

    Apache Struts: File upload component had a directory traversal vulnerability

    KritikCVSS 9,8Kavram kanıtıEPSS %81

    apache · struts7 Ara 2023

  • CVE-2020-15175
    57Planlayın

    Unauthenticated File Deletion in GLPI

    KritikCVSS 9,1Kavram kanıtıEPSS %72

    glpi-project · glpi7 Eki 2020

  • CVE-2017-14942
    57Planlayın

    Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct reques

    KritikCVSS 9,8Kavram kanıtıEPSS %61

    intelbras · wrn 150 firmware29 Eyl 2017

  • CVE-2024-53676
    56Planlayın

    A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.

    KritikCVSS 9,8İstismar yokEPSS %56

    hpe · insight remote support26 Kas 2024

  • CVE-2024-39931
    55Planlayın

    Gogs through 0.13.0 allows deletion of internal files.

    KritikCVSS 9,9İstismar yokEPSS %53

    gogs · gogs4 Tem 2024

  • CVE-2023-2766
    46Planlayın

    Weaver OA jx2_config.ini file access

    YüksekCVSS 7,5Kavram kanıtıEPSS %54

    weaver · e-office17 May 2023

  • CVE-2024-6209
    42Planlayın

    unauthorized file access

    KritikCVSS 9,4Kavram kanıtıEPSS %17

    abb · aspect-ent-12 firmware5 Tem 2024

  • CVE-2025-41240
    40Planlayın

    Mounted Kubernetes Secrets under a predictable path located within the web server document root

    KritikCVSS 10,0İstismar yokEPSS %1

    vmware · bitnamicharts/appsmith24 Tem 2025

  • CVE-2026-71379
    40Planlayın

    Toptech TMS7 and TopHAT Files or Directories Accessible to External Parties

    KritikCVSS 10,0İstismar yok

    toptech systems · tms7Bugün

  • CVE-2023-6114
    39İzleyin

    Duplicator < 1.5.7.1; Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Data Exposure

    YüksekCVSS 7,5Kavram kanıtıEPSS %31

    awesomemotive · duplicator26 Ara 2023

  • CVE-2015-5211
    39İzleyin

    Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to

    KritikCVSS 9,6İstismar yokEPSS %3

    vmware · spring framework25 May 2017

  • CVE-2020-12743
    39İzleyin

    An issue was discovered in Gazie 7.32.

    KritikCVSS 9,8İstismar yokEPSS %2

    gazie project · gazie11 May 2020

  • CVE-2024-56731
    39İzleyin

    Gogs deletion of internal files allows remote command execution

    KritikCVSS 9,8İstismar yokEPSS %1

    gogs · gogs24 Haz 2025

  • CVE-2017-10930
    39İzleyin

    The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being a

    KritikCVSS 9,8İstismar yokEPSS %1

    zte · zxr10 1800-2s firmware19 Eyl 2017

  • CVE-2023-29931
    39İzleyin

    laravel-s 3.7.35 is vulnerable to Local File Inclusion via /src/Illuminate/Laravel.php.

    KritikCVSS 9,8İstismar yokEPSS %1

    laravels project · laravels22 Haz 2023

  • CVE-2026-2331
    39İzleyin

    An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due t

    KritikCVSS 9,8İstismar yokEPSS %1

    sick ag · sick lector85x6 Mar 2026

  • CVE-2023-48710
    39İzleyin

    iTop limit pages/exec.php script to PHP files

    KritikCVSS 9,8İstismar yokEPSS %1

    combodo · itop15 Nis 2024

  • CVE-2024-39581
    39İzleyin

    Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulnerability.

    KritikCVSS 9,8İstismar yokEPSS %0

    dell · insightiq10 Eyl 2024

  • CVE-2026-8715
    38İzleyin

    Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath

    KritikCVSS 9,6İstismar yokEPSS %0

    hashicorp · tooling13 Ağu 2026

  • CVE-2025-11919
    38İzleyin

    Unprotected temporary directories in Wolfram Cloud may result in privilege escalation

    KritikCVSS 9,6İstismar yokEPSS %0

    wolfram research inc. · cloud26 Haz 2026

  • CVE-2025-32819
    37İzleyin

    A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete

    YüksekCVSS 8,8İstismar yokEPSS %6

    sonicwall · sma 100 firmware7 May 2025

Tüm zafiyet sınıfları