Vulnerabilities (CVE)

Filtered by CWE-552
Total 456 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-36306 1 Airspan 2 Airvelocity 1500, Airvelocity 1500 Firmware 2026-06-17 N/A 6.5 MEDIUM
An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web server binary, and the web server configuration file. These vulnerabilities were found in AirVelocity 1500 running software version 9.3.0.01249, were still present in 15.18.00.2511, and may affect other AirVelocity and AirSpeed models.
CVE-2022-35235 1 Xplodedthemes 1 Wpide - File Manager \& Code Editor 2026-06-17 N/A 4.9 MEDIUM
Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.
CVE-2022-34464 1 Siemens 4 Sicam Gridedge Essential Arm, Sicam Gridedge Essential Gds Arm, Sicam Gridedge Essential Gds Intel and 1 more 2026-06-17 2.1 LOW 6.3 MEDIUM
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.7.3). The affected application uses an improperly protected file to import SSH keys. This could allow attackers with access to the filesystem of the host on which SICAM GridEdge runs to inject a custom SSH key to that file.
CVE-2022-34049 1 Wavlink 2 Wl-wn530hg4, Wl-wn530hg4 Firmware 2026-06-17 N/A 5.3 MEDIUM
An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.
CVE-2022-33901 1 Multisafepay 1 Multisafepay Plugin For Woocommerce 2026-06-17 N/A 5.3 MEDIUM
Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin <= 4.13.1 at WordPress.
CVE-2022-33686 1 Google 1 Android 2026-06-17 2.1 LOW 2.3 LOW
Exposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.
CVE-2022-33158 2 Microsoft, Trendmicro 2 Windows, Vpn Proxy One Pro 2026-06-17 N/A 7.8 HIGH
Trend Micro VPN Proxy Pro version 5.2.1026 and below contains a vulnerability involving some overly permissive folders in a key directory which could allow a local attacker to obtain privilege escalation on an affected system.
CVE-2022-32143 1 Codesys 2 Plcwinnt, Runtime Toolkit 2026-06-17 6.5 MEDIUM 8.8 HIGH
In multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the PLC. All requests are processed on the controller only if no level 1 password is configured on the controller or if remote attacker has previously successfully authenticated himself to the controller. A successful Attack may lead to a denial of service, change of local files, or drain of confidential Information. User interaction is not required
CVE-2022-31475 1 Givewp 1 Givewp 2026-06-17 N/A 5.5 MEDIUM
Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.
CVE-2022-30428 1 Ginadmin Project 1 Ginadmin 2026-06-17 5.0 MEDIUM 7.5 HIGH
In ginadmin through 05-10-2022, the incoming path value is not filtered, resulting in arbitrary file reading.
CVE-2022-2981 1 Wpchill 1 Download Monitor 2026-06-17 N/A 4.9 MEDIUM
The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.
CVE-2022-2392 1 Lana 1 Lana Downloads Manager 2026-06-17 N/A 6.5 MEDIUM
The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that can be exploited by users with "Contributor" permissions or higher.
CVE-2022-2357 1 Wsm Downloader Project 1 Wsm Downloader 2026-06-17 N/A 7.5 HIGH
The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file download feature to download any local files, including sensitive ones like wp-config.php.
CVE-2022-2222 1 Wpchill 1 Download Monitor 2026-06-17 4.0 MEDIUM 4.9 MEDIUM
The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.
CVE-2022-29720 1 74cms 1 74cmsse 2026-06-17 5.0 MEDIUM 7.5 HIGH
74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Download.php.
CVE-2022-29447 1 Wow-company 1 Hover Effects 2026-06-17 4.0 MEDIUM 6.8 MEDIUM
Authenticated (administrator or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Hover Effects plugin <= 2.1 at WordPress.
CVE-2022-29446 1 Wow-company 1 Counter Box 2026-06-17 4.0 MEDIUM 6.8 MEDIUM
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugin <= 1.1.1 at WordPress.
CVE-2022-29302 1 Contec 2 Sv-cpt-mc310, Sv-cpt-mc310 Firmware 2026-06-17 2.1 LOW 5.5 MEDIUM
SolarView Compact ver.6.00 was discovered to contain a local file disclosure via /html/Solar_Ftp.php.
CVE-2022-28462 1 Xxyopen 1 Novel-plus 2026-06-17 5.0 MEDIUM 7.5 HIGH
novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.
CVE-2022-28445 1 Kitesky 1 Kitecms 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
KiteCMS v1.1.1 was discovered to contain an arbitrary file read vulnerability via the background management module.