Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-552'

View all threats tagged with 'cwe-552'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-552

Threats Tagged 'cwe-552'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-14849: CWE-552 Files or Directories Accessible to External Parties in Paid Membership SubscriptionsCVE-2026-14849
0

A vulnerability in the Paid Membership Subscriptions WordPress plugin before version 3.0.7 allows unauthenticated users to download exported member and payment data files. These files, containing personally identifiable information (PII), are written to a predictable location in the uploads directory without proper access protection. This exposure can occur while the export artifact is present on the server.

Join the discussion
CVE-2026-11841: CWE-552 Files or directories accessible to external parties in SICK AG InspectorP61xCVE-2026-11841
0

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment.

Join the discussion
CVE-2026-57990: CWE-552: Files or Directories Accessible to External Parties in Microsoft Microsoft Edge (Chromium-based)CVE-2026-57990
0

CVE-2026-57990 is a high-severity vulnerability in Microsoft Edge (Chromium-based) where files or directories are accessible to external parties, potentially allowing unauthorized information disclosure over a network. The vulnerability has a CVSS score of 7.4 and has been officially fixed by Microsoft.

Join the discussion
CVE-2026-57990: CWE-552: Files or Directories Accessible to External Parties in Microsoft Microsoft Edge (Chromium-based)CVE-2026-57990
0

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: cwe-552
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses