CWE-552 · 418 kayıt
Files or Directories Accessible to External Parties
Bu sınıftaki CVE’ler
418 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
89Hemen | CVE-2020-17519Silahlaştırılmış | Apache Flink directory traversal attack: reading remote files through the REST APIapache · flink · CWE-552 | Yüksek7,5 | KEV | %97,8 | 5 Oca 2021 |
88Hemen | CVE-2025-11371Silahlaştırılmış | Gladinet CentreStack and TrioFox Local File Inclusion Flawgladinet · centrestack · CWE-552 | Yüksek7,5 | KEV | %92,1 | 9 Eki 2025 |
75Bu hafta | CVE-2016-3715Silahlaştırılmış | The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted imimagemagick · imagemagick · CWE-552 | Orta5,5 | KEV | %75,3 | 5 May 2016 |
75Bu hafta | CVE-2017-16651Silahlaştırılmış | Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's fileroundcube · webmail · CWE-552 | Yüksek7,8 | KEV | %45,7 | 9 Kas 2017 |
63Bu hafta | CVE-2023-50164Kavram kanıtı | Apache Struts: File upload component had a directory traversal vulnerabilityapache · struts · CWE-552 | Kritik9,8 | — | %80,8 | 7 Ara 2023 |
57Planlayın | CVE-2020-15175Kavram kanıtı | Unauthenticated File Deletion in GLPIglpi-project · glpi · CWE-552 | Kritik9,1 | — | %71,6 | 7 Eki 2020 |
57Planlayın | CVE-2017-14942Kavram kanıtı | Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct requesintelbras · wrn 150 firmware · CWE-552 | Kritik9,8 | — | %60,9 | 29 Eyl 2017 |
56Planlayın | CVE-2024-53676İstismar yok | A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.hpe · insight remote support · CWE-552 | Kritik9,8 | — | %56,3 | 26 Kas 2024 |
55Planlayın | CVE-2024-39931İstismar yok | Gogs through 0.13.0 allows deletion of internal files.gogs · gogs · CWE-552 | Kritik9,9 | — | %52,7 | 4 Tem 2024 |
46Planlayın | CVE-2023-2766Kavram kanıtı | Weaver OA jx2_config.ini file accessweaver · e-office · CWE-552 | Yüksek7,5 | — | %54,2 | 17 May 2023 |
42Planlayın | CVE-2024-6209Kavram kanıtı | unauthorized file accessabb · aspect-ent-12 firmware · CWE-552 | Kritik9,4 | — | %17,2 | 5 Tem 2024 |
40Planlayın | CVE-2025-41240İstismar yok | Mounted Kubernetes Secrets under a predictable path located within the web server document rootvmware · bitnamicharts/appsmith · CWE-552 | Kritik10,0 | — | %0,7 | 24 Tem 2025 |
40Planlayın | CVE-2026-71379İstismar yok | Toptech TMS7 and TopHAT Files or Directories Accessible to External Partiestoptech systems · tms7 · CWE-552 | Kritik10,0 | — | — | Bugün |
39İzleyin | CVE-2023-6114Kavram kanıtı | Duplicator < 1.5.7.1; Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Data Exposureawesomemotive · duplicator · CWE-552 | Yüksek7,5 | — | %30,9 | 26 Ara 2023 |
39İzleyin | CVE-2015-5211İstismar yok | Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to vmware · spring framework · CWE-552 | Kritik9,6 | — | %2,6 | 25 May 2017 |
39İzleyin | CVE-2020-12743İstismar yok | An issue was discovered in Gazie 7.32.gazie project · gazie · CWE-552 | Kritik9,8 | — | %1,5 | 11 May 2020 |
39İzleyin | CVE-2024-56731İstismar yok | Gogs deletion of internal files allows remote command executiongogs · gogs · CWE-552 | Kritik9,8 | — | %1,2 | 24 Haz 2025 |
39İzleyin | CVE-2017-10930İstismar yok | The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being azte · zxr10 1800-2s firmware · CWE-552 | Kritik9,8 | — | %1,1 | 19 Eyl 2017 |
39İzleyin | CVE-2023-29931İstismar yok | laravel-s 3.7.35 is vulnerable to Local File Inclusion via /src/Illuminate/Laravel.php.laravels project · laravels · CWE-552 | Kritik9,8 | — | %0,9 | 22 Haz 2023 |
39İzleyin | CVE-2026-2331İstismar yok | An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due tsick ag · sick lector85x · CWE-552 | Kritik9,8 | — | %0,9 | 6 Mar 2026 |
39İzleyin | CVE-2023-48710İstismar yok | iTop limit pages/exec.php script to PHP filescombodo · itop · CWE-552 | Kritik9,8 | — | %0,7 | 15 Nis 2024 |
39İzleyin | CVE-2024-39581İstismar yok | Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulnerability.dell · insightiq · CWE-552 | Kritik9,8 | — | %0,4 | 10 Eyl 2024 |
38İzleyin | CVE-2026-8715İstismar yok | Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPathhashicorp · tooling · CWE-552 | Kritik9,6 | — | %0,5 | 13 Ağu 2026 |
38İzleyin | CVE-2025-11919İstismar yok | Unprotected temporary directories in Wolfram Cloud may result in privilege escalationwolfram research inc. · cloud · CWE-552 | Kritik9,6 | — | %0,4 | 26 Haz 2026 |
37İzleyin | CVE-2025-32819İstismar yok | A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete sonicwall · sma 100 firmware · CWE-552 | Yüksek8,8 | — | %6,4 | 7 May 2025 |
- CVE-2020-1751989Hemen
Apache Flink directory traversal attack: reading remote files through the REST API
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %98apache · flink5 Oca 2021
- CVE-2025-1137188Hemen
Gladinet CentreStack and TrioFox Local File Inclusion Flaw
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %92gladinet · centrestack9 Eki 2025
- CVE-2016-371575Bu hafta
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted im
OrtaCVSS 5,5KEVSilahlaştırılmışEPSS %75imagemagick · imagemagick5 May 2016
- CVE-2017-1665175Bu hafta
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's file
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %46roundcube · webmail9 Kas 2017
- CVE-2023-5016463Bu hafta
Apache Struts: File upload component had a directory traversal vulnerability
KritikCVSS 9,8Kavram kanıtıEPSS %81apache · struts7 Ara 2023
- CVE-2020-1517557Planlayın
Unauthenticated File Deletion in GLPI
KritikCVSS 9,1Kavram kanıtıEPSS %72glpi-project · glpi7 Eki 2020
- CVE-2017-1494257Planlayın
Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct reques
KritikCVSS 9,8Kavram kanıtıEPSS %61intelbras · wrn 150 firmware29 Eyl 2017
- CVE-2024-5367656Planlayın
A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.
KritikCVSS 9,8İstismar yokEPSS %56hpe · insight remote support26 Kas 2024
- CVE-2024-3993155Planlayın
Gogs through 0.13.0 allows deletion of internal files.
KritikCVSS 9,9İstismar yokEPSS %53gogs · gogs4 Tem 2024
- CVE-2023-276646Planlayın
Weaver OA jx2_config.ini file access
YüksekCVSS 7,5Kavram kanıtıEPSS %54weaver · e-office17 May 2023
- CVE-2024-620942Planlayın
unauthorized file access
KritikCVSS 9,4Kavram kanıtıEPSS %17abb · aspect-ent-12 firmware5 Tem 2024
- CVE-2025-4124040Planlayın
Mounted Kubernetes Secrets under a predictable path located within the web server document root
KritikCVSS 10,0İstismar yokEPSS %1vmware · bitnamicharts/appsmith24 Tem 2025
- CVE-2026-7137940Planlayın
Toptech TMS7 and TopHAT Files or Directories Accessible to External Parties
KritikCVSS 10,0İstismar yoktoptech systems · tms7Bugün
- CVE-2023-611439İzleyin
Duplicator < 1.5.7.1; Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Data Exposure
YüksekCVSS 7,5Kavram kanıtıEPSS %31awesomemotive · duplicator26 Ara 2023
- CVE-2015-521139İzleyin
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to
KritikCVSS 9,6İstismar yokEPSS %3vmware · spring framework25 May 2017
- CVE-2020-1274339İzleyin
An issue was discovered in Gazie 7.32.
KritikCVSS 9,8İstismar yokEPSS %2gazie project · gazie11 May 2020
- CVE-2024-5673139İzleyin
Gogs deletion of internal files allows remote command execution
KritikCVSS 9,8İstismar yokEPSS %1gogs · gogs24 Haz 2025
- CVE-2017-1093039İzleyin
The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being a
KritikCVSS 9,8İstismar yokEPSS %1zte · zxr10 1800-2s firmware19 Eyl 2017
- CVE-2023-2993139İzleyin
laravel-s 3.7.35 is vulnerable to Local File Inclusion via /src/Illuminate/Laravel.php.
KritikCVSS 9,8İstismar yokEPSS %1laravels project · laravels22 Haz 2023
- CVE-2026-233139İzleyin
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due t
KritikCVSS 9,8İstismar yokEPSS %1sick ag · sick lector85x6 Mar 2026
- CVE-2023-4871039İzleyin
iTop limit pages/exec.php script to PHP files
KritikCVSS 9,8İstismar yokEPSS %1combodo · itop15 Nis 2024
- CVE-2024-3958139İzleyin
Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulnerability.
KritikCVSS 9,8İstismar yokEPSS %0dell · insightiq10 Eyl 2024
- CVE-2026-871538İzleyin
Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath
KritikCVSS 9,6İstismar yokEPSS %0hashicorp · tooling13 Ağu 2026
- CVE-2025-1191938İzleyin
Unprotected temporary directories in Wolfram Cloud may result in privilege escalation
KritikCVSS 9,6İstismar yokEPSS %0wolfram research inc. · cloud26 Haz 2026
- CVE-2025-3281937İzleyin
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete
YüksekCVSS 8,8İstismar yokEPSS %6sonicwall · sma 100 firmware7 May 2025