CWE-552: Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
265 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-34110 — ColoradoFTP Server <= 1.3 Build 8 Path Traversal Information Disclosure
- CVE-2025-68109 — ChurchCRM vulnerable to RCE with database restore functionality
- CVE-2026-2331 — CVE-2026-2331
- CVE-2024-53676 — A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution
- CVE-2026-2330 — CVE-2026-2330
- CVE-2026-34361 — HAPI FHIR: Unauthenticated SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token Theft
- CVE-2024-5262 — ProjectDiscovery Interactsh - Files or Directories Accessible to External Parties
- CVE-2026-25137 — NixOs Odoo database and filestore publicly accessible with default odoo configuration
- CVE-2024-51542 — Configuration Download
- CVE-2025-21609 — SiYuan has an arbitrary file deletion vulnerability
- CVE-2025-14896 — due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an a
- CVE-2018-25164 — EverSync 0.5 Arbitrary File Download via files Directory
- CVE-2025-26525 — Arbitrary file read risk through pdfTeX
- CVE-2025-15065 — Data Exposure in Kings Information & Network KESS Enterprise
- CVE-2024-10526 — Rapid7 Velociraptor Local Privilege Escalation In Windows Velociraptor Service
- CVE-2024-56731 — Gogs deletion of internal files allows remote command execution
- CVE-2025-59054 — dstack has insecure LUKS2 persistent storage partitions that may be opened and used
- CVE-2025-49797 — Multiple Brother driver installers for Windows contain a privilege escalation vulnerability. If exploited, an arbitrary
- CVE-2024-38876 — A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Cont
- CVE-2024-34066 — Arbitrary File Write/Read in Pterodactyl wings
Recently published
- CVE-2026-67402 — An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger
- CVE-2026-85175 — SiYuan before v3.8.2 TLS Private Key Disclosure via getFile
- CVE-2026-82020 — Hermes Agent 0.16.0 < 0.17.0 Credential Store Overwrite via File-Write Tool
- CVE-2026-53580 — Trilium arbitrary file read and denial of service via file:// URLs in the automatic image-download feature
- CVE-2026-78051 — alexta69 MeTube Cookie File cookies.txt file access
- CVE-2026-54457 — TensorZero: Arbitrary file read and SSRF in TensorZero Gateway's internal object storage endpoint
- CVE-2026-63042 — Apache InLong: Missing authorization on DataNode management endpoints
- CVE-2026-63040 — Apache InLong: Missing authorization in StreamSource forceDelete
- CVE-2026-63490 — Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass
- CVE-2026-76799 — code-projects Login Registration System SQL Database Backup login_registration_system.sql file access
- CVE-2026-19987 — SourceCodester Best Employee Management System Profile exposure of information through directory listing
- CVE-2026-19903 — SourceCodester Online Clothing Store SQL Database Backup shopping.sql file access
- CVE-2026-8715 — Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath
- CVE-2026-73653 — Vitest: Browser Mode provider commands bypass the file-access permission gate
- CVE-2026-11841 — CVE-2026-11841
- CVE-2026-59703 — repomix - Local File Inclusion via file:// URL Scheme in Git Clone Endpoint
- CVE-2026-13533 — agentejo Cockpit CMS htaccess config.yaml YAMLLoad file access
- CVE-2026-40624 — AVer PTC cameras Files or Directories Accessible to External Parties
- CVE-2025-14771 — File Disclosure in ABB T-MAC Plus web application and in ABB T-MAC plus Server - Default IIS Web Site
- CVE-2026-45543 — Nextcloud: Deleting a Forms collaborator share leaves uploaded response files accessible through a lingering Files share
More specific weaknesses
- CWE-219 — Storage of File with Sensitive Data Under Web Root
- CWE-220 — Storage of File With Sensitive Data Under FTP Root
- CWE-527 — Exposure of Version-Control Repository to an Unauthorized Control Sphere
- CWE-528 — Exposure of Core Dump File to an Unauthorized Control Sphere
- CWE-529 — Exposure of Access Control List Files to an Unauthorized Control Sphere
- CWE-530 — Exposure of Backup File to an Unauthorized Control Sphere
- CWE-539 — Use of Persistent Cookies Containing Sensitive Information
- CWE-553 — Command Shell in Externally Accessible Directory