Skip to main content

CWE archive

CWE-552 CVEs

Programmatic archive

487 CVEs tagged with CWE-55246 Critical, 201 High, 227 Medium, 13 Low, 0 Unrated.

CVE-2024-34066

Published May 3, 2024

Pterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the node configuration or posting it accidentally somewhere, an…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39480

Published May 3, 2024

Softing Secure Integration Server FileDirectory OPC UA Object Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affect…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39479

Published May 3, 2024

Softing Secure Integration Server OPC UA Gateway Directory Creation Vulnerability. This vulnerability allows remote attackers to create directories on affected installations of So…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-48710

Published Apr 15, 2024

iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they should have restricted access. Hopefully, there is no sensiti…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-2759

Published Apr 4, 2024

Improper access control vulnerability in Apaczka plugin for PrestaShop allows information gathering from saved templates without authentication.This issue affects Apaczka plugin f…

CVSS 7.5 · High

CVE-2024-29225

Published Apr 4, 2024

ELECOM wireless LAN routers allow a network-adjacent unauthenticated attacker to obtain the configuration file containing sensitive information by sending a specially crafted requ…

CVSS 4.3 · Medium

CVE-2024-2052

Published Mar 18, 2024

CWE-552: Files or Directories Accessible to External Parties vulnerability exists that could allow unauthenticated files and logs exfiltration and download of files when an attack…

CVSS 7.5 · High

CVE-2024-27894

Published Mar 12, 2024

The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referenced by a URL. The supported UR…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2364

Published Mar 10, 2024

A vulnerability classified as problematic has been found in Musicshelf 1.0/1.1 on Android. Affected is an unknown function of the file androidmanifest.xml of the component Backup…

CVSS 1.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-2056

Published Mar 5, 2024

Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service is running, running…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-2055

Published Mar 5, 2024

The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-45594

Published Mar 5, 2024

A CWE-552 “Files or Directories Accessible to External Parties” vulnerability in the embedded Chromium browser allows a physical attacker to arbitrarily download/upload files to/f…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22240

Published Feb 6, 2024

Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading to unauthorized access to sen…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24161

Published Feb 2, 2024

MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1005

Published Jan 29, 2024

A vulnerability has been found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This vulnerability affects unknown code of the file /runtime/log. The…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47202

Published Jan 23, 2024

A local file inclusion vulnerability on the Trend Micro Apex One management server could allow a local attacker to escalate privileges on affected installations. Please note: a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-52112

Published Jan 16, 2024

Unauthorized file access vulnerability in the wallpaper service module. Successful exploitation of this vulnerability may cause features to perform abnormally.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6266

Published Jan 11, 2024

The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP case of the handle_downloadin…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-6114

Published Dec 26, 2023

The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-5907

Published Dec 11, 2023

The File Manager WordPress plugin before 6.3 does not restrict the file managers root directory, allowing an administrator to set a root outside of the WordPress root directory, g…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-50164

Published Dec 7, 2023

An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remot…

CVSS 9.8 · Critical
evidence mentions
12
Buzz score
33.6
Vendor/product tagsBeta · best-effort
Showing 201-225 of 487 CVEsPage 9 of 20