The product makes files or directories accessible to unauthorized actors, even though they should not be.
Volume of CVEs assigned to CWE-552 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
480 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-11371HIGH In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system | Oct 9, 2025 | 7.5 | 98 | YES | YES |
CVE-2020-17519HIGH A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST | Jan 5, 2021 | 7.5 | 98 | YES | YES |
CVE-2016-3715MEDIUM The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image. | May 5, 2016 | 5.5 | 93 | YES | YES |
CVE-2017-16651HIGH Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, a | Nov 9, 2017 | 7.8 | 87 | YES | YES |
CVE-2021-39316HIGH The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the `dzsap_download` action | Aug 31, 2021 | 7.5 | 78 | NO | YES |
CVE-2023-50164CRITICAL An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote | Dec 7, 2023 | 9.8 | 74 | NO | NO |
CVE-2017-14942CRITICAL Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg | Sep 30, 2017 | 9.8 | 74 | NO | YES |
CVE-2023-2766HIGH A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/urlpage/mobileurl/configfile/jx2_ | May 17, 2023 | 7.5 | 65 | NO | YES |
CVE-2020-15175CRITICAL In GLPI before version 9.5.2, the `pluginimage.send.php` endpoint allows a user to specify an image from a plugin. The parameters can be maliciously crafted to instead delete the | Oct 7, 2020 | 9.1 | 63 | NO | NO |
CVE-2024-53676CRITICAL A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution. | Nov 27, 2024 | 9.8 | 61 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.