Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-552'

View all threats tagged with 'cwe-552'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-552

Threats Tagged 'cwe-552'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-40624: CWE-552 in AVer PTC500SCVE-2026-40624
0

Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated attacker to achieve arbitrary code execution via a specially crafted web request.

Join the discussion
CVE-2024-7107: CWE-552 Files or Directories Accessible to External Parties in National Keep Cyber Security Services CyberMathCVE-2024-7107
0

Files or Directories Accessible to External Parties vulnerability in National Keep Cyber Security Services CyberMath allows Collect Data from Common Resource Locations. This issue affects CyberMath: before CYBM.240816253.

Join the discussion
CVE-2024-6878: CWE-552 Files or Directories Accessible to External Parties in Eliz Software PanelCVE-2024-6878
0

Files or Directories Accessible to External Parties vulnerability in Eliz Software Panel allows Collect Data from Common Resource Locations. This issue affects Panel: before v2.3.24.

Join the discussion
CVE-2025-14771: CWE-552 Files or directories accessible to external parties in ABB T-MAC PlusCVE-2025-14771
0

Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

Join the discussion
CVE-2026-45543: CWE-552: Files or Directories Accessible to External Parties in nextcloud security-advisoriesCVE-2026-45543
0

Nextcloud versions from 4.3.0 up to but not including 5.2.7 contain a vulnerability where a removed collaborator retains unauthorized read access to uploaded respondent files for forms they previously had access to. This issue is limited to files associated with those specific forms. The vulnerability has been addressed and patched in version 5.2.7.

Join the discussion
CVE-2024-12917: CWE-552 Files or Directories Accessible to External Parties in Agito Computer Health4AllCVE-2024-12917
0

Files or Directories Accessible to External Parties vulnerability in Agito Computer Health4All allows Exploiting Incorrectly Configured Access Control Security Levels, Authentication Abuse. This issue affects Health4All: before 10.01.2025.

Join the discussion
CVE-2026-40425: CWE-552 in Danelec MacGregor Voyage Data Recorder (VDR) G4eCVE-2026-40425
0

CVE-2026-40425 is a medium severity vulnerability in the Danelec MacGregor Voyage Data Recorder (VDR) G4e. The administrator account on the device's web interface can directly edit sensitive authentication-related files, which may allow changing the root password. This vulnerability could lead to unauthorized access or control escalation if exploited. No official patch or remediation guidance is currently available from the vendor. The device is not a cloud service, so remediation depends on vendor updates or manual mitigation. There are no known exploits in the wild at this time.

Join the discussion
CVE-2026-45088: CWE-73: External Control of File Name or Path in hahwul dalfoxCVE-2026-45088
0

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the custom-payload-file field in model.Options is JSON-tagged and deserialized directly from the attacker's request body, then propagated unchanged through dalfox.Initialize into the scan engine. The engine passes the value to voltFile.ReadLinesOrLiteral, which reads lines from any file path accessible to the dalfox process and embeds each line as an XSS payload in outbound HTTP requests directed at the attacker-controlled target URL. Because the server has no API key by default, an unauthenticated network attacker can exfiltrate the contents of arbitrary files on the dalfox host by reading them line-by-line through scan traffic. This vulnerability is fixed in 2.13.0.

Join the discussion
CVE-2026-45721: CWE-20: Improper Input Validation in xyproto algernonCVE-2026-45721
0

Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that resolves to a directory without an index file, DirPage walks upward through parent directories — past the configured server root — looking for a file named handler.lua to execute as the request handler. The loop terminates only after 100 ancestor steps or when filepath.Dir returns ., so on any absolute server-root path the search reaches the filesystem root (/ on Unix, drive letter on Windows). The first handler.lua it finds is loaded into the Lua interpreter with the full Algernon API exposed — including run3(), httpclient, os.execute, io.popen, PQ, MSSQL, raw filesystem access, and the userstate database. Any process that can write handler.lua anywhere in a parent directory of the server root obtains pre-authenticated remote code execution on the next HTTP request. This is reachable without authentication — the lookup happens before the permission check returns a hit (the perm system only gates URL prefixes, not the handler-resolution step), and any URL pointing at a directory without an index triggers the walk. On a fresh stock Algernon install the request GET / is enough. This vulnerability is fixed in 1.17.7.

Join the discussion
CVE-2026-40564: CWE-552 Files or Directories Accessible to External Parties in Apache Software Foundation Apache Flink Kubernetes OperatorCVE-2026-40564
0

Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI is currently not validated so that it points to user-owned files or addresses.  This lets a user with CR create permissions read files from the operator pod's filesystem and pull content from any backing store reachable through Flink's pluggable filesystem layer and access them through the submitted Flink job. Furthermore for fetching from http/https addresses there is currently no allowlist on the URI scheme, no host check, no IP-range restriction, and no protection against pointing the URI at internal or link-local addresses.This issue affects Apache Flink Kubernetes Operator: from 1.3.0 before 1.15.0. Users are recommended to upgrade to version 1.15.0, which fixes the issue.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Tag: cwe-552
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses