CWE-538
83 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-538page 2 of 2
- CVE-2024-6880MEDIUMCVSS 6.9EG 0.02025-01-10
During MegaBIP installation process, a user is encouraged to change a default path to administrative portal, as keeping it secret is listed by the author as one of the protection mechanisms. Publicly available source code of "/registered…
- CVE-2024-9671MEDIUMCVSS 5.3EG 5.32024-10-09
A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invoice if the URL is known or guessed.
- CVE-2025-0194MEDIUMCVSS 6.5EG 6.52025-01-08
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. Under certain conditions, access tokens may have been logged whe…
- CVE-2025-11079MEDIUMCVSS 5.3EG 5.32025-09-27
A security flaw has been discovered in Campcodes Farm Management System 1.0. Affected by this issue is some unknown functionality. The manipulation results in file and directory information exposure. The attack may be performed from remote…
- CVE-2025-11891MEDIUMCVSS 5.3EG 5.32025-11-11
The Shelf Planner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.1 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially…
- CVE-2025-12059CRITICALCVSS 9.8EG 9.82026-02-11
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Logo Software Industry and Trade Inc. Logo j-Platform allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affec…
- CVE-2025-12699MEDIUMCVSS 5.5EG 5.52026-02-10
The ZOLL ePCR IOS application reflects unsanitized user input into a WebView. Attacker-controlled strings placed into PCR fields (run number, incident, call sign, notes) are interpreted as HTML/JS when the app prints or renders that conten…
- CVE-2025-20665MEDIUMCVSS 5.5EG 5.52025-05-05
In devinfo, there is a possible information disclosure due to a missing SELinux policy. This could lead to local information disclosure of device identifier with no additional execution privileges needed. User interaction is not needed for…
- CVE-2025-22306MEDIUMCVSS 5.3EG 5.32025-01-07
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Spencer Haws Link Whisper Free link-whisper.This issue affects Link Whisper Free: from n/a through <= 0.7.7.
- CVE-2025-22633MEDIUMCVSS 5.8EG 5.82025-02-23
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in StellarWP Give – Divi Donation Modules give-donation-modules-for-divi allows Retrieve Embedded Sensitive Data.This issue affects Give – Di…
- CVE-2025-22773MEDIUMCVSS 5.3EG 5.32025-01-15
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in WP Chill Htaccess File Editor htaccess-file-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects …
- CVE-2025-24689MEDIUMCVSS 5.9EG 5.92025-01-27
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta allows Retrieve Embedded Sensitive Data.This issue affects…
- CVE-2025-25586MEDIUMCVSS 4.2EG 4.22025-03-18
yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml.
- CVE-2025-27017MEDIUMCVSS 6.5EG 6.52025-03-12
Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB components generate during processing. An authorized user with read access to the provenance e…
- CVE-2025-27150MEDIUMCVSS 5.3EG 5.32025-03-04
Tuleap is an Open Source Suite to improve management of software developments and collaboration. The password to connect the Redis instance is not purged from the archive generated with tuleap collect-system-data. These archives are likely…
- CVE-2025-31421MEDIUMCVSS 5.8EG 5.82025-04-04
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Oblak Studio Srbtranslatin srbtranslatin allows Retrieve Embedded Sensitive Data.This issue affects Srbtranslatin: from n/a through <= 3.2.0.
- CVE-2025-31550MEDIUMCVSS 5.8EG 5.82025-04-01
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in thom4 WP-LESS wp-less allows Retrieve Embedded Sensitive Data.This issue affects WP-LESS: from n/a through <= 1.9.6.
- CVE-2025-31558MEDIUMCVSS 5.8EG 5.82025-04-03
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Greg TailPress tailpress allows Retrieve Embedded Sensitive Data.This issue affects TailPress: from n/a through <= 0.4.4.
- CVE-2025-36058MEDIUMCVSS 5.5EG 5.52026-01-20
IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation and IBM Business Automation Workflow…
- CVE-2025-46602MEDIUMCVSS 4.4EG 4.42025-10-27
Dell SupportAssist OS Recovery, versions prior to 5.5.15.0, contain an Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability. A low privileged attacker with local access could potentially exploit thi…
- CVE-2025-46820HIGHCVSS 7.1EG 7.12025-05-06
phpgt/Dom provides access to modern DOM APIs. Versions of phpgt/Dom prior to 4.1.8 expose the GITHUB_TOKEN in the Dom workflow run artifact. The ci.yml workflow file uses actions/upload-artifact@v4 to upload the build artifact. This artifa…
- CVE-2025-57734MEDIUMCVSS 4.3EG 4.32025-08-20
In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files
- CVE-2025-58458MEDIUMCVSS 4.3EG 4.32025-09-03
In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit…
- CVE-2025-61138HIGHCVSS 7.5EG 7.52025-11-20
Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.
- CVE-2025-68429HIGHCVSS 7.3EG 7.32025-12-17
Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present starting in versions 7.0.0 and prior to versions 7.6.21, 8.6.15, 9.1.17, and 10.1.10 relates to Storybook’s handling …
- CVE-2025-8452MEDIUMCVSS 4.3EG 4.32025-08-12
By using the "uscan" protocol provided by the eSCL specification, an attacker can discover the serial number of multi-function printers that implement the Brother-provided firmware. This serial number can, in turn, can be leveraged by the …
- CVE-2026-10254MEDIUMCVSS 5.3EG 5.32026-06-01
A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/. This manipulation causes file and directory information exposure. The attack can be initiated remotely. The …
- CVE-2026-23838HIGHCVSS 8.7EG 0.02026-01-19
Tandoor Recipes is a recipe manager than can be installed with the Nix package manager. Starting in version 23.05 and prior to version 26.05, when using the default configuration of Tandoor Recipes, specifically using SQLite and default `M…
- CVE-2026-27173HIGHCVSS 8.7EG 8.72026-05-19
JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running t…
- CVE-2026-33705MEDIUMCVSS 5.3EG 5.32026-04-10
Chamilo LMS is a learning management system. Prior to 1.11.38, Twig template files (.tpl) under /main/template/default/ are directly accessible without authentication via HTTP GET requests. These templates expose internal application logic…
- CVE-2026-49298HIGHCVSS 8.8EG 0.02026-06-01
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API us…
- CVE-2026-6160MEDIUMCVSS 5.3EG 5.32026-04-13
A vulnerability was found in code-projects Simple ChatBox 1.0. Affected by this issue is the function SimpleChatbox_PHP of the file chatbox.sql of the component Endpoint. Performing a manipulation results in file and directory information …
- CVE-2026-7071MEDIUMCVSS 5.3EG 5.32026-04-27
A security vulnerability has been detected in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/user-cvs/. The manipulation leads to file and directory information exposure. Remo…
Map vulnerabilities like CWE-538 to your infrastructure
EchelonGraph correlates every CVE — across CWE-538 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →