Skip to main content

CWE archive

CWE-552 CVEs

Programmatic archive

480 CVEs tagged with CWE-55243 Critical, 200 High, 225 Medium, 12 Low, 0 Unrated.

CVE-2024-40767

Published Jul 24, 2024

In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK fl…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6911

Published Jul 22, 2024

Files on the Windows system are accessible without authentication to external parties due to a local file inclusion in PerkinElmer ProcessPlus.This issue affects ProcessPlus: thro…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-41916

Published Jul 15, 2024

In Apache Linkis =1.4.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will trigge…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39931

Published Jul 4, 2024

Gogs through 0.13.0 allows deletion of internal files.

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-4836

Published Jul 2, 2024

Web services managed by Edito CMS (Content Management System) in versions from 3.5 through 3.25 leak sensitive data as they allow downloading configuration files by an unauthentic…

CVSS 7.5 · High

CVE-2024-0949

Published Jun 27, 2024

Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypa…

CVSS 9.8 · Critical

CVE-2024-5262

Published Jun 5, 2024

Files or Directories Accessible to External Parties vulnerability in smb server in ProjectDiscovery Interactsh allows remote attackers to read/write any files in the directory and…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-5587

Published Jun 2, 2024

A vulnerability was found in Casdoor up to 1.335.0. It has been classified as problematic. Affected is an unknown function of the file /conf/app.conf of the component Configuratio…

CVSS 6.9 · Medium

CVE-2024-3564

Published Jun 1, 2024

The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the plugin's 'content_block' sho…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-35183

Published May 15, 2024

wolfictl is a command line tool for working with Wolfi. A git authentication issue in versions prior to 0.16.10 allows a local user’s GitHub token to be sent to remote servers oth…

CVSS 4.4 · Medium

CVE-2024-34066

Published May 3, 2024

Pterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the node configuration or posting it accidentally somewhere, an…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39480

Published May 3, 2024

Softing Secure Integration Server FileDirectory OPC UA Object Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affect…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39479

Published May 3, 2024

Softing Secure Integration Server OPC UA Gateway Directory Creation Vulnerability. This vulnerability allows remote attackers to create directories on affected installations of So…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-48710

Published Apr 15, 2024

iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they should have restricted access. Hopefully, there is no sensiti…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-2759

Published Apr 4, 2024

Improper access control vulnerability in Apaczka plugin for PrestaShop allows information gathering from saved templates without authentication.This issue affects Apaczka plugin f…

CVSS 7.5 · High

CVE-2024-29225

Published Apr 4, 2024

ELECOM wireless LAN routers allow a network-adjacent unauthenticated attacker to obtain the configuration file containing sensitive information by sending a specially crafted requ…

CVSS 4.3 · Medium
Showing 176-200 of 480 CVEsPage 8 of 20