CWE-552: CWE-552

103
Total CVEs
19
Critical
55
High
7.6
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
5
2025
37
2024
28
2023
16
2022
7

Top Affected Vendors

1 Apache 4
2 Redhat 3
3 Abb 2
4 Dell 2
5 Ibm 2
6 Openstack 2
7 Siemens 2
8 Arubanetworks 2
9 Huawei 1
10 Iteachyou 1

All CWE-552 CVEs (103)

CVE-2023-43856
7.5

Dreamer CMS v4.1.3 contains an arbitrary file read vulnerability in the TemplateController component that allows attackers to read sensitive files fro...

Sep 27, 2023
CVE-2023-4475
7.5

An arbitrary file movement vulnerability in ASUSTOR Data Master (ADM) allows attackers to exploit the file renaming feature to move files to unintende...

Aug 22, 2023
CVE-2023-34645
7.5

CVE-2023-34645 is an arbitrary file read vulnerability in jfinal CMS 5.1.0 that allows attackers to read sensitive files from the server filesystem. T...

Jun 16, 2023
CVE-2023-33568
7.5

This vulnerability in Dolibarr ERP/CRM software allows unauthenticated attackers to dump the entire database and access sensitive company data includi...

Jun 13, 2023
CVE-2023-25260
7.5

Stimulsoft Designer (Web) 2023.1.3 contains a Local File Inclusion vulnerability that allows attackers to read arbitrary files on the server. This aff...

Mar 28, 2023
CVE-2023-23330
7.5

CVE-2023-23330 is a local file inclusion vulnerability in Amano Xparc parking solutions that allows attackers to read arbitrary files on the server. T...

Mar 28, 2023
CVE-2023-1246
7.5

This vulnerability allows attackers to access sensitive files or directories in Saysis Starcities software, potentially exposing configuration data, c...

Mar 10, 2023
CVE-2023-26956
7.5

CVE-2023-26956 is an arbitrary file read vulnerability in onekeyadmin v1.3.9 that allows attackers to read sensitive files on the server via the /admi...

Mar 8, 2023
CVE-2022-48161
7.5

Easy Images v2.0 contains an arbitrary file download vulnerability in the /application/down.php component that allows attackers to download any file f...

Feb 1, 2023
CVE-2022-28462
7.5

CVE-2022-28462 is an arbitrary file reading vulnerability in novel-plus 3.6.0 that allows attackers to read sensitive files from the server filesystem...

May 5, 2022
CVE-2022-0656
7.5

This vulnerability in the uDraw WordPress plugin allows attackers to read arbitrary files on the web server without authentication. By exploiting an u...

Apr 25, 2022
CVE-2022-23377
7.5

CVE-2022-23377 is a local file inclusion vulnerability in Archeevo document management systems that allows attackers to read arbitrary files on the se...

Mar 1, 2022
CVE-2022-25104
7.5

HorizontCMS v1.0.0-beta.2 contains an arbitrary file download vulnerability in the /admin/file-manager/ component that allows authenticated attackers ...

Feb 24, 2022
CVE-2021-38711
7.5

CVE-2021-38711 is an information disclosure vulnerability in gitit's Export feature that allows attackers to read arbitrary files from the server file...

Aug 16, 2021
CVE-2021-37348
7.5

CVE-2021-37348 is a local file inclusion vulnerability in Nagios XI that allows attackers to read arbitrary files on the server through improper pathn...

Aug 13, 2021
CVE-2021-36763
7.5

CVE-2021-36763 is a directory traversal vulnerability in CODESYS V3 web server that allows external attackers to access files or directories they shou...

Aug 3, 2021
CVE-2021-33359
7.5

This vulnerability in gowitness versions before 2.3.6 allows unauthenticated attackers to read arbitrary files on the server by using the file:// sche...

Jun 9, 2021
CVE-2021-29024
7.5

CVE-2021-29024 is a directory traversal vulnerability in InvoicePlane that allows unauthenticated attackers to list directories and download files tha...

May 17, 2021
CVE-2025-4134
7.3

A local user can spoof or tamper with Avast Business Antivirus update files due to insufficient file validation in the do_update_vps function. This vu...

May 28, 2025
CVE-2025-0509
7.3

This vulnerability allows attackers to bypass Sparkle's (Ed)DSA signature verification and replace legitimate software updates with malicious payloads...

Feb 4, 2025
CVE-2024-39581
7.3

CVE-2024-39581 is a directory traversal vulnerability in Dell PowerScale InsightIQ versions 5.0 through 5.1 that allows unauthenticated remote attacke...

Sep 10, 2024
CVE-2021-32752
7.2

CVE-2021-32752 is an arbitrary file read vulnerability in Ether Logs plugin for Craft CMS. Authenticated admin users can read any file on the server, ...

Jul 9, 2021
CVE-2025-45529
7.1

This vulnerability allows unauthenticated attackers to read arbitrary files on SSCMS servers by sending specially crafted GET requests to the /cms/tem...

May 27, 2025
CVE-2024-11629
7.1

This vulnerability in Progress Telerik Document Processing Libraries allows attackers to export the contents of arbitrary files to RTF format, potenti...

Feb 12, 2025
CVE-2025-25266
6.8

This vulnerability in Tecnomatix Plant Simulation allows unauthorized attackers to delete files even when system access should be prohibited. It affec...

Mar 11, 2025
CVE-2024-54099
6.7

This CVE describes a file replacement vulnerability affecting certain Huawei devices. Attackers can replace critical files to compromise system integr...

Dec 12, 2024
CVE-2025-37177
6.5

An arbitrary file deletion vulnerability in the command-line interface of Aruba mobility conductors running AOS-10 or AOS-8 allows authenticated remot...

Jan 13, 2026
CVE-2025-37130
6.5

This vulnerability in EdgeConnect SD-WAN's command-line interface allows authenticated attackers to read arbitrary files from the underlying filesyste...

Sep 16, 2025
CVE-2025-5273
6.5

The mcp-markdownify-server package is vulnerable to arbitrary file read attacks through its get-markdown-file tool. Attackers can craft malicious prom...

May 29, 2025
CVE-2024-53649
6.5

This vulnerability in Siemens SIPROTEC 5 protection devices allows authenticated remote attackers to read arbitrary files from the filesystem via impr...

Jan 14, 2025
CVE-2024-40767
6.5

This vulnerability allows authenticated users to trick OpenStack Nova into reading arbitrary files from the server by uploading specially crafted disk...

Jul 24, 2024
CVE-2023-41916
6.5

Apache Linkis versions up to 1.4.0 have a vulnerability where attackers with authorized accounts can configure malicious MySQL JDBC parameters to trig...

Jul 15, 2024
CVE-2024-32498
6.5

This vulnerability allows authenticated users to access arbitrary files on OpenStack servers by uploading a crafted QCOW2 image with external data ref...

Jul 5, 2024
CVE-2024-5056
6.5

This CVE describes a CWE-552 vulnerability where specific files or directories are accessible to external parties in Schneider Electric devices. If ex...

Jun 12, 2024
CVE-2024-51058
6.2

A Local File Inclusion (LFI) vulnerability in TCPDF 6.7.5 allows attackers to read arbitrary files from the server's file system through malicious <im...

Nov 26, 2024
CVE-2025-25799
6.0

SeaCMS 13.3 contains an arbitrary file read vulnerability in the admin_safe.php file that allows attackers to read sensitive files on the server. This...

Feb 26, 2025
CVE-2024-45627
5.9

This vulnerability in Apache Linkis allows authenticated attackers to read arbitrary files from the server by injecting malicious MySQL JDBC parameter...

Jan 14, 2025
CVE-2025-13225
5.6

CVE-2025-13225 is an arbitrary file deletion vulnerability in TanOS that allows authenticated attackers to delete files they shouldn't have access to....

Nov 19, 2025
CVE-2025-30103
5.5

Dell SmartFabric OS10 Software versions before 10.6.0.5 have a file permission vulnerability that allows low-privileged local users to access files or...

Jul 30, 2025
CVE-2025-12648
5.3

The WP-Members WordPress plugin stores user-uploaded files in predictable directories without proper access controls, allowing unauthenticated attacke...

Jan 7, 2026
CVE-2025-14442
5.3

The Secure Copy Content Protection and Content Locking WordPress plugin stores exported CSV files in a publicly accessible directory with predictable ...

Dec 12, 2025
CVE-2025-12747
5.3

The Tainacan WordPress plugin exposes private uploaded files to unauthenticated users due to inadequate access controls. This vulnerability allows att...

Nov 21, 2025
CVE-2025-12894
5.3

The Import WP plugin for WordPress exposes sensitive data through unprotected directories. Unauthenticated attackers can access exported/imported file...

Nov 21, 2025
CVE-2025-33150
5.3

IBM Cognos Analytics Certified Containers 12.1.0 contains hidden pages that can expose package parameter information to unauthorized users. This infor...

Nov 10, 2025
CVE-2025-31996
5.3

HCL Unica Platform has improper access controls that leave files unprotected, potentially exposing sensitive system or private information. Attackers ...

Oct 13, 2025
CVE-2025-52460
5.3

This vulnerability allows remote unauthenticated attackers to access uploaded files and SS1 configuration files in vulnerable versions. It affects SS1...

Aug 28, 2025
CVE-2025-43749
5.3

This vulnerability allows unauthenticated users (guests) to access files uploaded via forms and stored in Liferay's document library by manipulating U...

Aug 20, 2025
CVE-2024-47106
5.3

IBM Jazz for Service Management versions 1.1.3 through 1.1.3.22 have improper access restrictions that could allow remote attackers to obtain sensitiv...

Jan 18, 2025
CVE-2024-8655
5.3

This vulnerability allows remote attackers to access sensitive files or directories on Mercury MNVR816 devices through improper access controls in the...

Sep 10, 2024
CVE-2024-5045
5.3

This vulnerability in SourceCodester Online Birth Certificate Management System 1.0 allows remote attackers to access sensitive files or directories t...

May 17, 2024

About CWE-552 (CWE-552)

Our database tracks 103 CVEs classified as CWE-552, with 19 rated critical and 55 rated high severity. The average CVSS score for CWE-552 vulnerabilities is 7.6.

External reference: View CWE-552 on MITRE CWE →

Monitor CWE-552 Vulnerabilities

Get alerted when new CWE-552 CVEs affect your infrastructure.

Start Monitoring Free