Threats Tagged 'cwe-552'
View all threats tagged with 'cwe-552'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-552'
Click on any threat for detailed analysis and mitigation recommendations
0 IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface. Join the discussion | CVE Database V5 | 09/24/2026, 14:18:35 UTC Added: 09/24/2026, 14:49:19 UTC |
0 IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images. Join the discussion | CVE Database V5 | 09/22/2026, 21:21:03 UTC Added: 09/22/2026, 21:33:26 UTC |
0 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment opens a caller-selected server-local file without checking that the resolved path remains in the workspace. A caller can upload environment files, credentials, or other readable host data to a Confluence page and retrieve it through Atlassian. The advisory traces the vulnerable input and processing flow through confluence_upload_attachment, file_path, and open(file_path, "rb"), which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0. Join the discussion | CVE Database V5 | 09/22/2026, 18:45:48 UTC Added: 09/22/2026, 19:03:36 UTC |
0 Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, authorization, or directory restrictions. A remote attacker can use SQLite CREATE VIRTUAL TABLE statements to provide a local path to these modules, which use hashicorp/go-getter under the Anyquery server process and return the selected file contents as queryable table rows. The disclosure is limited only by the filesystem permissions of the server process and can expose system configuration, credentials, and private keys. This issue is fixed in version 0.4.5. Join the discussion | CVE Database V5 | 09/14/2026, 19:55:23 UTC Added: 09/14/2026, 20:02:28 UTC |
0 Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage. Join the discussion | CVE Database V5 | 09/14/2026, 18:02:16 UTC Added: 09/14/2026, 18:32:11 UTC |
0 The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive credentials. Join the discussion | CVE Database V5 | 09/12/2026, 06:00:08 UTC Added: 09/12/2026, 06:17:04 UTC |
0 Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally. Join the discussion | CVE Database V5 | 09/08/2026, 17:14:39 UTC Added: 09/08/2026, 17:24:33 UTC |
The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitrary files from the server, including files outside the web root. Only sites using the restricted display-callback mode are affected, which is the automatic default on installations whose first Pods version predates 3.1. Join the discussion | CVE Database V5 | 09/04/2026, 06:00:03 UTC Added: 09/04/2026, 06:37:45 UTC |
0 An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects installations where CSF Messenger v3 and its HTTPS mode are enabled. WebPros addressed the vulnerability in version 16.31. Join the discussion | CVE Database V5 | 09/03/2026, 23:57:15 UTC Added: 09/04/2026, 00:07:40 UTC |
Trilium versions prior to 0.104.0 have a vulnerability in the automatic image-download feature that allows authenticated users to read arbitrary local files via file:// URLs in note img tags. This occurs because the feature accepts file URLs without path validation, enabling disclosure of files readable by the Trilium process. Additionally, referencing unbounded sources like /dev/zero can cause memory exhaustion and crash the server. The issue affects the web UI, ETAPI, web clipper, and note imports and requires only an authenticated session or ETAPI token. The vulnerability is fixed in version 0.104.0. Join the discussion | CVE Database V5 | 08/27/2026, 19:46:12 UTC Added: 08/27/2026, 20:24:20 UTC |
Showing 1 to 10 of 87 results