Skip to main content

CWE archive

CWE-552 CVEs

Programmatic archive

480 CVEs tagged with CWE-55243 Critical, 200 High, 225 Medium, 12 Low, 0 Unrated.

CVE-2021-34765

Published Sep 2, 2021

A vulnerability in the web UI for Cisco Nexus Insights could allow an authenticated, remote attacker to view and download files related to the web application. The attacker requir…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36233

Published Aug 31, 2021

The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary files from the filesystem by specifying…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39316

Published Aug 31, 2021

The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the `dzsap_download` action…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25351

Published Aug 20, 2021

An information disclosure vulnerability in rConfig 3.9.5 has been fixed for version 3.9.6. This vulnerability allowed remote authenticated attackers to read files on the system vi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38711

Published Aug 16, 2021

In gitit before 0.15.0.0, the Export feature can be exploited to leak information from files.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37348

Published Aug 13, 2021

Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation of a pathname in index.php.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-29969

Published Aug 5, 2021

If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS handshake, then Thunde…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32752

Published Jul 9, 2021

Ether Logs is a package that allows one to check one's logs in the Craft 3 utilities section. A vulnerability was found in versions prior to 3.0.4 that allowed authenticated admin…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-33359

Published Jun 9, 2021

A vulnerability exists in gowitness < 2.3.6 that allows an unauthenticated attacker to perform an arbitrary file read using the file:// scheme in the url parameter to get an image…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-31831

Published Jun 3, 2021

Incorrect access to deleted scripts vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to gain access to signed SQL scripts wh…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10867

Published May 26, 2021

Files are accessible without restrictions from the /update/results page of redhat-certification 7 package, allowing an attacker to remove any file accessible by the apached user.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-10863

Published May 26, 2021

It was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer directory, through the /rhcer…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29024

Published May 17, 2021

In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppos…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-1256

Published Apr 29, 2021

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite files on the file system of an affected devic…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21429

Published Apr 27, 2021

OpenAPI Generator allows generation of API client libraries, server stubs, documentation and configuration automatically given an OpenAPI Spec. Using `File.createTempFile` in JDK…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24154

Published Apr 5, 2021

The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitra…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1434

Published Mar 24, 2021

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying file system. This vulnerabil…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21355

Published Mar 23, 2021

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1, due to the lack of ensuring file extensions belong to co…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20253

Published Mar 9, 2021

A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker to elevate the privilege from a low privileged user to the a…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 376-400 of 480 CVEsPage 16 of 20