Vulnerabilities > Files or Directories Accessible to External Parties

DATE CVE VULNERABILITY TITLE RISK
2023-05-18 CVE-2023-20184 Files or Directories Accessible to External Parties vulnerability in Cisco DNA Center
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user.
network
low complexity
cisco CWE-552
4.3
2023-05-17 CVE-2023-2766 Files or Directories Accessible to External Parties vulnerability in Weaver Office Automation 9.5
A vulnerability was found in Weaver OA 9.5 and classified as problematic.
network
low complexity
weaver CWE-552
7.5
2023-05-09 CVE-2023-29107 Files or Directories Accessible to External Parties vulnerability in Siemens 6Gk1411-1Ac00 Firmware and 6Gk1411-5Ac00 Firmware
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1).
network
low complexity
siemens CWE-552
5.3
2023-03-28 CVE-2023-28375 Files or Directories Accessible to External Parties vulnerability in Propumpservice Osprey Pump Controller Firmware 1.01
Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated file disclosure.
network
low complexity
propumpservice CWE-552
7.5
2023-03-28 CVE-2023-23330 Files or Directories Accessible to External Parties vulnerability in Amano Xoffice 7.1.3879
amano Xparc parking solutions 7.1.3879 was discovered to be vulnerable to local file inclusion.
network
low complexity
amano CWE-552
7.5
2023-03-10 CVE-2023-1246 Files or Directories Accessible to External Parties vulnerability in Saysis Starcities 1.1/1.3
Files or Directories Accessible to External Parties vulnerability in Saysis Starcities allows Collect Data from Common Resource Locations.This issue affects Starcities: through 1.3.
network
low complexity
saysis CWE-552
7.5
2023-03-09 CVE-2023-26948 Files or Directories Accessible to External Parties vulnerability in Onekeyadmin 1.3.9
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/file/download.
network
low complexity
onekeyadmin CWE-552
7.5
2023-03-08 CVE-2023-26956 Files or Directories Accessible to External Parties vulnerability in Onekeyadmin 1.3.9
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/curd/code.
network
low complexity
onekeyadmin CWE-552
7.5
2023-02-22 CVE-2023-22974 Files or Directories Accessible to External Parties vulnerability in Open-Emr Openemr
A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controlling a connection to an attacker-controlled MySQL server.
network
low complexity
open-emr CWE-552
7.5
2023-02-17 CVE-2023-0822 Files or Directories Accessible to External Parties vulnerability in Deltaww Diaenergie
The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization, which could allow an unauthorized user to bypass authorization and access privileged functionality.
network
low complexity
deltaww CWE-552
8.8