Vulnerabilities > Files or Directories Accessible to External Parties

DATE CVE VULNERABILITY TITLE RISK
2024-11-13 CVE-2024-52292 Files or Directories Accessible to External Parties vulnerability in Craftcms Craft CMS
Craft is a content management system (CMS).
network
low complexity
craftcms CWE-552
6.5
2024-11-12 CVE-2024-48838 Files or Directories Accessible to External Parties vulnerability in Dell Smartfabric Os10
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a Files or Directories Accessible to External Parties vulnerability.
local
low complexity
dell CWE-552
3.3
2024-09-26 CVE-2024-7107 Files or Directories Accessible to External Parties vulnerability in Nationalkeep Cybermath 1.4
Files or Directories Accessible to External Parties vulnerability in National Keep Cyber Security Services CyberMath allows Collect Data from Common Resource Locations.This issue affects CyberMath: before CYBM.240816253.
network
low complexity
nationalkeep CWE-552
7.5
2024-09-10 CVE-2024-39581 Files or Directories Accessible to External Parties vulnerability in Dell Insightiq 5.0.1/5.1.0
Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulnerability.
network
low complexity
dell CWE-552
critical
9.8
2024-08-21 CVE-2023-49198 Files or Directories Accessible to External Parties vulnerability in Apache Seatunnel 1.0.0
Mysql security vulnerability in Apache SeaTunnel. Attackers can read files on the MySQL server by modifying the information in the MySQL URL allowLoadLocalInfile=true&allowUrlInLocalInfile=true&allowLoadLocalInfileInPath=/&maxAllowedPacket=655360 This issue affects Apache SeaTunnel: 1.0.0. Users are recommended to upgrade to version [1.0.1], which fixes the issue.
network
low complexity
apache CWE-552
7.5
2024-08-20 CVE-2024-41699 Files or Directories Accessible to External Parties vulnerability in Priority-Software Priority 19.1.0.68/22.0
Priority – CWE-552: Files or Directories Accessible to External Parties
network
low complexity
priority-software CWE-552
7.5
2024-08-14 CVE-2024-7729 The CAYIN Technology CMS lacks proper access control, allowing unauthenticated remote attackers to download arbitrary CGI files.
network
low complexity
CWE-552
7.5
2024-08-13 CVE-2024-3913 Files or Directories Accessible to External Parties vulnerability in Phoenixcontact products
An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup.
high complexity
phoenixcontact CWE-552
5.3
2024-08-02 CVE-2024-27182 Files or Directories Accessible to External Parties vulnerability in Apache Linkis 1.3.2/1.4.0/1.5.0
In Apache Linkis <= 1.5.0, Arbitrary file deletion in Basic management services on A user with an administrator account could delete any file accessible by the Linkis system user . Users are recommended to upgrade to version 1.6.0, which fixes this issue.
network
low complexity
apache CWE-552
4.9
2024-07-30 CVE-2024-38429 Files or Directories Accessible to External Parties vulnerability in Matrix-Globalservices Tafnit
Matrix Tafnit v8 -  CWE-552: Files or Directories Accessible to External Parties
network
low complexity
matrix-globalservices CWE-552
7.5