VulnSea

CWE-552

CVEs classified under CWE-552, newest first.

32 CVEsRSS

CVE-2026-77884High· 7.1PoC
1w ago

Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network

Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage.

MidnightBrain Trust · Gallery - Private Photo VaultEPSS 0.32%via NVD
CVE-2026-54629High· 7.5
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, a…

Twilightjulien040 · anyqueryEPSS 0.97%via NVD
CVE-2026-80494High· 8.6
1w ago

The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to downloa…

The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to downloa…

TwilightEPSS 0.32%via NVD
CVE-2026-68831Medium· 5.5
2w ago

Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.

Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.

Sunlitmicrosoft · windows_10_1607EPSS 0.38%via NVD
CVE-2026-67402None
2w ago

An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host

An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable an…

SunlitEPSS 0.32%via NVD
CVE-2026-75164Medium· 6.5
2w ago

An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to retrieve arbitrary files from the device file…

An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to retrieve arbitrary files from the device file…

SunlitEPSS 0.40%via NVD
CVE-2026-74853Medium· 6.8
2w ago

The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitrary files from the server, including files outside the web root

The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitrary files from the server, including files outside the web root. O…

SunlitEPSS 0.23%via NVD
CVE-2026-85175High· 8.8
2w ago

SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), which only blocks conf/conf.json by exact match and does not restrict the TLS private key (conf/…

SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), which only blocks conf/conf.json by exact match and does not restrict the TLS private key (conf/…

TwilightEPSS 0.19%via NVD
CVE-2026-82020Medium· 6.8
3w ago

Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential store by bypassing sensitive-path guards that excluded t…

Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential store by bypassing sensitive-path guards that excluded t…

SunlitEPSS 0.33%via NVD
CVE-2026-53580High· 8.1
3w ago

Trilium is an open-source hierarchical note-taking application

Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the automatic image-download feature accepts file:// URLs in a note's img tags and reads the referenced local file with no path validation, all…

TwilightEPSS 0.27%via NVD
CVE-2026-75413High· 7.5
3w ago

DocSys V2.02.80 is vulnerable to Any File Download

DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need to go through authentication to utilize the downloadDocEx.do interface and download any file via the parameter targetPath.

TwilightEPSS 0.28%via NVD
CVE-2026-75464High· 8.1
4w ago

OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().

OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().

TwilightEPSS 0.26%via NVD
CVE-2026-54457High· 7.7
1mo ago

TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation

TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied…

Twilighttensorzero · tensorzeroEPSS 0.29%via NVD
CVE-2026-63490High· 7.5
1mo ago

Handlebars.java provides logic-less and semantic Mustache templates with Java

Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader w…

Twilightgithub · com.github.jknack:handlebars-springmvcEPSS 0.47%via NVD
CVE-2026-19903Medium· 5.3
1mo ago

A vulnerability has been found in SourceCodester Online Clothing Store 1.0

A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db/shopping.sql of the component SQL Database Backup. The manipulation leads to files or directories accessible. Remote…

SunlitEPSS 0.31%via NVD
CVE-2026-73653Critical· 9.4
1mo ago

Vitest is a testing framework powered by Vite

Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accep…

MidnightEPSS 0.64%via NVD
CVE-2026-8715Critical· 9.6
1mo ago

Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files…

Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files…

MidnightEPSS 0.34%via NVD
CVE-2026-11841Critical· 9.4
1mo ago

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed throu…

MidnightEPSS 0.49%via NVD
CVE-2026-57990High· 7.4
1mo ago

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.50%via NVD
GHSA-p63j-vcc4-9vmvCritical· 9.4
2mo ago

@vitest/browser: Browser Mode provider commands bypass the file-access permission gate

@vitest/browser: Browser Mode provider commands bypass the file-access permission gate

Midnightvitest · @vitest/browservia GHSA
CVE-2026-13533Medium· 5.3
2mo ago

A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2

A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function Spyc::YAMLLoad of the file /config/config.yaml of the component htaccess Handler. Such manipulation leads to files or…

SunlitEPSS 0.48%via NVD
CVE-2026-45543Medium· 5.3
3mo ago

Nextcloud is an open source content collaboration platform

Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent files for the affected form. The scope is limited to u…

Sunlitnextcloud · formsEPSS 0.27%via NVD
CVE-2026-40631High· 8.7
4mo ago

An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation.  Note: Software versions which have reached End of Technical Suppor…

An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation.  Note: Software versions which have reached End of Technical Suppor…

TwilightEPSS 0.25%via NVD
CVE-2026-34361Critical· 9.3
5mo ago

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that makes outbound HTTP reque…

Midnighthapifhir · hl7_fhir_coreEPSS 0.30%via NVD
CVE-2025-0620Medium· 4.9
1y ago

A flaw was found in Samba

A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.

Sunlitsamba · sambaEPSS 0.75%via NVD
CVE-2025-5273Medium· 6.5
1y ago

Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Files or Directories Accessible to External Parties via the get-markdown-file tool

Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Files or Directories Accessible to External Parties via the get-markdown-file tool. An attacker can craft a prompt that, once accessed by the MCP host, will al…

SunlitEPSS 0.39%via NVD
CVE-2023-36664High· 7.8PoC
3y ago

Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).

Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).

Midnightartifex · ghostscriptEPSS 4.2%via NVD
CVE-2022-36552High· 7.5
4y ago

Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which allows attackers to steal all data such as source code and system files via a crafted GET request.

Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which allows attackers to steal all data such as source code and system files via a crafted GET request.

Twilighttendacn · ac6_firmwareEPSS 0.70%via NVD
CVE-2022-24138High· 7.8
4y ago

IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramData folder, ProgramData folder has "rwx" permissions for unprivileged users

IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramData folder, ProgramData folder has "rwx" permissions for unprivileged users. Low privilege users can use SetOpLock to…

Twilightiobit · advanced_systemcareEPSS 0.58%via NVD
CVE-2021-22769Medium· 4.3
5y ago

A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an attacker is not restricted or incorrectly…

A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an attacker is not restricted or incorrectly…

Sunlitschneider-electric · easergy_t300_firmwareEPSS 0.65%via NVD
CWE-552 vulnerabilities (CVEs) · VulnSea