Skip to main content

CWE archive

CWE-552 CVEs

Programmatic archive

482 CVEs tagged with CWE-55244 Critical, 201 High, 225 Medium, 12 Low, 0 Unrated.

CVE-2026-11841

Published Jul 28, 2026

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A criti…

CVSS 9.4 · Critical
evidence mentions
6
Buzz score
34.5

CVE-2026-57990

Published Jul 26, 2026

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-15342

Published Jul 21, 2026

Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
32.6

CVE-2026-59703

Published Jul 8, 2026

repomix contains a local file inclusion vulnerability in the git clone endpoint that allows unauthenticated attackers to read arbitrary local git repositories. The isValidRemoteVa…

CVSS 8.7 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-13533

Published Jun 29, 2026

A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function Spyc::YAMLLoad of the file /config/config.yaml of the compo…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2025-66389

Published Jun 22, 2026

GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration co…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2026-40624

Published Jun 19, 2026

Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated attacker to achieve arbitrary code execution via a specially…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2025-14771

Published Jun 3, 2026

Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-45543

Published Jun 1, 2026

Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respond…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-45088

Published May 27, 2026

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the custom-payload-file field in model…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2024-11399

Published May 27, 2026

Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to conduct denia…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-45721

Published May 26, 2026

Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that resolves to a directory without an index file, DirPage walks u…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-40564

Published May 26, 2026

Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI is currently…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-8704

Published May 15, 2026

Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified.

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-33380

Published May 13, 2026

A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature to…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-32185

Published May 12, 2026

Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-31216

Published May 12, 2026

The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its file management API. The DELETE /storage/{object_name:path} endpo…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-31215

Published May 12, 2026

The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticSearch service interface. The DELETE /{index_name}/documents endpo…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-39871

Published May 11, 2026

A path handling issue was addressed with improved logic. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to observe unprotec…

CVSS 7.5 · High
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-7817

Published May 11, 2026

Local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities in pgAdmin 4 LLM API configuration endpoints. User-supplied api_key_file and api_url preferences…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 482 CVEsPage 1 of 20