CWE-538
83 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-538page 1 of 2
- CVE-2014-0771NONECVSS 0.0EG 0.02014-04-12
The BWOCXRUN.BwocxrunCtrl.1 control contains a method named “OpenUrlToBuffer.” This method takes a URL as a parameter and returns its contents to the caller in JavaScript. The URLs are accessed in the security context of the current…
- CVE-2014-0772NONECVSS 0.0EG 0.02014-04-12
The BWOCXRUN.BwocxrunCtrl.1 control contains a method named OpenUrlToBufferTimeout. This method takes a URL as a parameter and returns its contents to the caller in JavaScript. The URLs are accessed in the security context of the curren…
- CVE-2016-15056HIGHCVSS 8.7EG 0.02025-11-14
Ubee EVW3226 cable modem/routers firmware versions up to and including 1.0.20 store configuration backup files in the web root after they are generated for download. These backup files remain accessible without authentication until the nex…
- CVE-2017-16770MEDIUMCVSS 6.5EG 6.52018-02-27
File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to obtain other user's sensitive files via the fi…
- CVE-2017-5387LOWCVSS 3.3EG 3.32018-06-11
The existence of a specifically requested local file can be found due to the double firing of the "onerror" when the "source" attribute on a "<track>" tag refers to a file that does not exist if the source page is loaded locally. This vuln…
- CVE-2017-9947MEDIUMCVSS 5.3EG 5.32017-10-23
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. A directory traversal vulnerability could allow a remote attacker with network access to the integrated web server …
- CVE-2018-10590HIGHCVSS 7.5EG 7.52018-05-15
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an information …
- CVE-2018-11798MEDIUMCVSS 6.5EG 6.52019-01-07
The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.
- CVE-2018-16970MEDIUMCVSS 4.3EG 4.32018-09-12
Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to download non-purchased course files via a modified id parameter.
- CVE-2018-20932LOWCVSS 2.7EG 2.72019-08-01
cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406).
- CVE-2018-4847MEDIUMCVSS 4.6EG 4.62018-04-23
A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive information (e.g. session key for accessing server) in Siemens WinCC OA Operator iOS app could allow an at…
- CVE-2019-10320MEDIUMCVSS 4.3EG 4.32019-05-21
Jenkins Credentials Plugin 2.1.18 and earlier allowed users with permission to create or update credentials to confirm the existence of files on the Jenkins master with an attacker-specified path, and obtain the certificate content of file…
- CVE-2019-12623MEDIUMCVSS 4.3EG 4.32019-08-21
A vulnerability in the web server functionality of Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform file enumeration on an affected system. The vulne…
- CVE-2019-15793MEDIUMCVSS 6.5EG 6.52020-04-24
In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, several locations which shift ids translate user/group ids before performing operations in the lower filesystem were translating them in…
- CVE-2019-25706HIGHCVSS 7.5EG 7.52026-04-12
Across DR-810 contains an unauthenticated file disclosure vulnerability that allows remote attackers to download the rom-0 backup file containing sensitive information by sending a simple GET request. Attackers can access the rom-0 endpoin…
- CVE-2019-25717MEDIUMCVSS 4.3EG 4.32026-06-02
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection. Attackers can retrieve device interna…
- CVE-2019-6851HIGHCVSS 7.5EG 7.52019-10-29
A CWE-538: File and Directory Information Exposure vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information from the controller when usin…
- CVE-2019-7618MEDIUMCVSS 6.5EG 6.52019-10-01
A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local filesystem of the Kibana instance running C…
- CVE-2020-37104HIGHCVSS 7.5EG 7.52026-02-11
ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database backup files by predicting backup filename patterns. Attackers can generate a list of 6-digit PIN combinations and fuzz…
- CVE-2021-1406MEDIUMCVSS 4.9EG 4.92021-04-08
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to access sensitive information on an a…
- CVE-2021-21250HIGHCVSS 7.7EG 7.72021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which may lead to arbitrary file read. When BuildSpec is provided in XML format, the spec is processed by XmlBuildSpecMigrator.migra…
- CVE-2021-32822MEDIUMCVSS 4.0EG 4.02021-08-16
The npm hbs package is an Express view engine wrapper for Handlebars. Depending on usage, users of hbs may be vulnerable to a file disclosure vulnerability. There is currently no patch for this vulnerability. hbs mixes pure template data w…
- CVE-2021-3709MEDIUMCVSS 6.5EG 5.52021-10-01
Function check_attachment_for_errors() in file data/general-hooks/ubuntu.py could be tricked into exposing private data via a constructed crash file. This issue affects: apport 2.14.1 versions prior to 2.14.1-0ubuntu3.29+esm8; 2.20.1 versi…
- CVE-2021-40363HIGHCVSS 7.8EG 7.82022-02-09
A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7), SIMATIC WinCC V16 (…
- CVE-2021-4471HIGHCVSS 8.7EG 0.02025-11-14
TG8 Firewall exposes a directory such as /data/ over HTTP without authentication. This directory stores credential files for previously logged-in users. A remote unauthenticated attacker can enumerate and download files within the director…
- CVE-2022-0013MEDIUMCVSS 5.0EG 5.02022-01-12
A file information exposure vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker to read the contents of arbitrary files on the system with elevated privileges when generating a support file. This i…
- CVE-2022-20864MEDIUMCVSS 4.6EG 4.62022-10-10
A vulnerability in the password-recovery disable feature of Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco Catalyst Switches could allow an unauthenticated, local attacker to recover the configuration or reset the enable password. Th…
- CVE-2022-23508HIGHCVSS 8.8EG 8.82023-01-09
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in GitOps run could allow a local user or process to alter a Kubernetes cluster's…
- CVE-2022-26329LOWCVSS 1.8EG 5.32023-01-26
File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to determine whether a file exists on the filesystem. This issue affects: Micro Focus NetIQ Identity Manager NetIQ Identity Man…
- CVE-2022-4318HIGHCVSS 7.8EG 7.82023-09-25
A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
- CVE-2022-43933MEDIUMCVSS 4.4EG 4.42024-11-21
An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration secrets are logged in supportsave. Supportsave file is generated by an admin user troubleshooting the switch. …
- CVE-2022-44623MEDIUMCVSS 6.5EG 7.52022-11-03
In JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner settings
- CVE-2023-28444CRITICALCVSS 9.9EG 9.92023-03-24
angular-server-side-configuration helps configure an angular application at runtime on the server or in a docker container via environment variables. angular-server-side-configuration detects used environment variables in TypeScript (.ts) …
- CVE-2023-38558MEDIUMCVSS 5.5EG 5.52023-09-14
A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Administration Console) V4.0 Update 1 (All versions). The affected application leaks Windows admin credentials. An attack…
- CVE-2023-4480MEDIUMCVSS 5.5EG 5.52023-09-05
Due to an out-of-date dependency in the “Fusion File Manager” component accessible through the admin panel, an attacker can send a crafted request that allows them to read the contents of files on the system accessible within the priv…
- CVE-2023-4595HIGHCVSS 7.5EG 7.52023-11-23
An information exposure vulnerability has been found, the exploitation of which could allow a remote user to retrieve sensitive information stored on the server such as credential files, configuration files, application files, etc., simply…
- CVE-2023-46723HIGHCVSS 8.9EG 8.92023-10-31
lte-pic32-writer is a writer for PIC32 devices. In versions 0.0.1 and prior, those who use `sendto.txt` are vulnerable to attackers who known the IMEI reading the sendto.txt. The sendto.txt file can contain the SNS(such as slack and zulip)…
- CVE-2023-4933MEDIUMCVSS 5.3EG 5.32023-10-16
The WP Job Openings WordPress plugin before 3.4.3 does not block listing the contents of the directories where it stores attachments to job applications, allowing unauthenticated visitors to list and download private attachments if the aut…
- CVE-2023-5003HIGHCVSS 7.5EG 7.52023-10-16
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains acce…
- CVE-2023-54346HIGHCVSS 7.5EG 7.52026-05-05
WordPress Plugin Backup Migration 1.2.8 contains an information disclosure vulnerability that allows unauthenticated attackers to download complete database backups by accessing predictable file paths. Attackers can enumerate backup direct…
- CVE-2023-5937LOWCVSS 3.8EG 3.82024-05-15
On Windows systems, the Arc configuration files resulted to be world-readable. This can lead to information disclosure by local attackers, via exfiltration of sensitive data from configuration files.
- CVE-2023-7062HIGHCVSS 8.8EG 8.82024-07-10
The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4. This makes it possible for attackers with contributor access or higher to read the contents of arbitr…
- CVE-2024-0191MEDIUMCVSS 5.3EG 5.32024-01-02
A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/uploads/. The manipulation leads to file and directory information exposure.…
- CVE-2024-21501MEDIUMCVSS 5.3EG 5.32024-02-24
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An atta…
- CVE-2024-22045HIGHCVSS 7.6EG 7.62024-03-12
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.1 SP1). The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, bu…
- CVE-2024-22433HIGHCVSS 8.8EG 8.82024-02-06
Dell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSettings.get_ldap_info in DP Search. A remote unauthorized unauthenticated attacker could potentially exploit this vulnerabi…
- CVE-2024-31954HIGHCVSS 7.3EG 7.32024-05-14
An issue was discovered in the installer in Samsung Portable SSD for T5 1.6.10 on Windows. Because it is possible to tamper with the directory and DLL files used during the installation process, an attacker can escalate privileges through …
- CVE-2024-47579MEDIUMCVSS 6.8EG 6.82024-12-10
An attacker authenticated as an administrator can use an exposed webservice to upload or download a custom PDF font file on the system server. Using the upload functionality to copy an internal file into a font file and subsequently using…
- CVE-2024-47580MEDIUMCVSS 6.8EG 6.82024-12-10
An attacker authenticated as an administrator can use an exposed webservice to create a PDF with an embedded attachment. By specifying the file to be an internal server file and subsequently downloading the generated PDF, the attacker can…
- CVE-2024-51977MEDIUMCVSS 5.3EG 5.32025-06-25
An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631), can leak several pieces of sensitive information from a vulnerable device. The URI path …
Map vulnerabilities like CWE-538 to your infrastructure
EchelonGraph correlates every CVE — across CWE-538 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →