Vulnerabilities > Files or Directories Accessible to External Parties

DATE CVE VULNERABILITY TITLE RISK
2022-11-29 CVE-2022-44356 Files or Directories Accessible to External Parties vulnerability in Wavlink Wl-Wn531G3 Firmware M31G3.V5030.200325/M31G3.V5030.201204
WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data and log files.
network
low complexity
wavlink CWE-552
7.5
2022-11-21 CVE-2022-3691 Files or Directories Accessible to External Parties vulnerability in Fluenx Deepl PRO API Translation
The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor.
network
low complexity
fluenx CWE-552
7.5
2022-11-18 CVE-2022-44583 Files or Directories Accessible to External Parties vulnerability in Watchtowerhq Watchtower
Unauth.
network
low complexity
watchtowerhq CWE-552
7.5
2022-11-10 CVE-2022-45129 Files or Directories Accessible to External Parties vulnerability in Payara
Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422.
network
low complexity
payara CWE-552
7.5
2022-11-03 CVE-2022-41710 Files or Directories Accessible to External Parties vulnerability in Markdownify Project Markdownify 1.4.1
Markdownify version 1.4.1 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious markdown file through Markdownify.
local
low complexity
markdownify-project CWE-552
5.5
2022-11-03 CVE-2022-43449 Files or Directories Accessible to External Parties vulnerability in Openharmony 3.1/3.1.1/3.1.2
OpenHarmony-v3.1.2 and prior versions had an Arbitrary file read vulnerability via download_server.
local
low complexity
openharmony CWE-552
5.5
2022-11-01 CVE-2022-23738 Files or Directories Accessible to External Parties vulnerability in Github Enterprise Server
An improper cache key vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to access private repository files through a public repository.
network
low complexity
github CWE-552
5.7
2022-10-28 CVE-2022-37424 Files or Directories Accessible to External Parties vulnerability in Opennebula
Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery.
network
low complexity
opennebula CWE-552
6.5
2022-10-17 CVE-2022-2834 Files or Directories Accessible to External Parties vulnerability in Helpful Project Helpful
The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Email Address depending on the plugin's settings
network
low complexity
helpful-project CWE-552
5.3
2022-10-14 CVE-2022-42234 Files or Directories Accessible to External Parties vulnerability in Ucms Project Ucms 1.6
There is a file inclusion vulnerability in the template management module in UCMS 1.6
network
low complexity
ucms-project CWE-552
8.8