Vulnerabilities (CVE)

Filtered by CWE-552
Total 449 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-25759 1 Sucms Project 1 Sucms 2025-04-09 N/A 7.5 HIGH
An issue in the component admin_template.php of SUCMS v1.0 allows attackers to execute a directory traversal and arbitrary file deletion via a crafted GET request.
CVE-2024-13126 1 W3eden 1 Download Manager 2025-04-09 N/A 4.6 MEDIUM
The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.
CVE-2022-47950 2 Debian, Openstack 2 Debian Linux, Swift 2025-04-04 N/A 6.5 MEDIUM
An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and earlier, no longer actively developed).
CVE-2023-4743 1 Iteachyou 1 Dreamer Cms 2025-04-04 2.1 LOW 3.1 LOW
A vulnerability was found in Dreamer CMS up to 4.1.3. It has been classified as problematic. Affected is an unknown function of the file /upload/ueditorConfig?action=config. The manipulation leads to files or directories accessible. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-238632. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2023-43856 1 Iteachyou 1 Dreamer Cms 2025-04-04 N/A 7.5 HIGH
Dreamer CMS v4.1.3 was discovered to contain an arbitrary file read vulnerability via the component /admin/TemplateController.java.
CVE-2015-4715 1 Owncloud 2 Owncloud, Owncloud Server 2025-03-31 4.0 MEDIUM 4.9 MEDIUM
The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values.
CVE-2025-25799 1 Seacms 1 Seacms 2025-03-28 N/A 6.0 MEDIUM
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php.
CVE-2024-27182 1 Apache 1 Linkis 2025-03-27 N/A 4.9 MEDIUM
In Apache Linkis <= 1.5.0, Arbitrary file deletion in Basic management services on A user with an administrator account could delete any file accessible by the Linkis system user . Users are recommended to upgrade to version 1.6.0, which fixes this issue.
CVE-2022-48161 1 Easy Images Project 1 Easy Images 2025-03-27 N/A 7.5 HIGH
Easy Images v2.0 was discovered to contain an arbitrary file download vulnerability via the component /application/down.php. This vulnerability is exploited via a crafted GET request.
CVE-2022-48094 1 Lmxcms 1 Lmxcms 2025-03-27 N/A 4.9 MEDIUM
lmxcms v1.41 was discovered to contain an arbitrary file read vulnerability via TemplateAction.class.php.
CVE-2025-2652 1 Oretnom23 1 Employee And Visitor Gate Pass Logging System 2025-03-26 5.0 MEDIUM 5.3 MEDIUM
A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to exposure of information through directory listing. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to change the configuration settings. Multiple sub-directories are affected.
CVE-2022-44343 1 Crmeb 1 Crmeb 2025-03-26 N/A 7.5 HIGH
CRMEB 4.4.4 is vulnerable to Any File download.
CVE-2020-24312 1 Filemanagerpro 1 File Manager 2025-03-24 5.0 MEDIUM 7.5 HIGH
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.
CVE-2025-2147 1 Caishixiong 1 Modern Farm Digital Integrated Management System 2025-03-24 5.0 MEDIUM 5.3 MEDIUM
A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to files or directories accessible. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2023-41916 1 Apache 1 Linkis 2025-03-14 N/A 6.5 MEDIUM
In Apache Linkis =1.4.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will trigger arbitrary file reading. Therefore, the parameters in the Mysql JDBC URL should be blacklisted. This attack requires the attacker to obtain an authorized account from Linkis before it can be carried out. Versions of Apache Linkis = 1.4.0 will be affected.  We recommend users upgrade the version of Linkis to version 1.5.0.
CVE-2023-26956 1 Onekeyadmin 1 Onekeyadmin 2025-03-05 N/A 7.5 HIGH
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/curd/code.
CVE-2024-53676 1 Hpe 1 Insight Remote Support 2025-03-05 N/A 9.8 CRITICAL
A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.
CVE-2023-26948 1 Onekeyadmin 1 Onekeyadmin 2025-02-28 N/A 7.5 HIGH
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/file/download.
CVE-2023-4930 1 Shamimsplugins 1 Front End Pm 2025-02-26 N/A 6.5 MEDIUM
The Front End PM WordPress plugin before 11.4.3 does not block listing the contents of the directories where it stores attachments to private messages, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled.
CVE-2024-34066 1 Pterodactyl 1 Wings 2025-02-21 N/A 8.4 HIGH
Pterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the node configuration or posting it accidentally somewhere, an attacker can use it to gain arbitrary file write and read access on the node the token is associated to. This issue has been addressed in version 1.11.12 and users are advised to upgrade. Users unable to upgrade may enable the `ignore_panel_config_updates` option as a workaround.