CWE-538 · 84 kayıt
Insertion of Sensitive Information into Externally-Accessible File or Directory
Bu sınıftaki CVE’ler
84 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2019-6851İstismar yok | A CWE-538: File and Directory Information Exposure vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (alschneider-electric · modicon m580 firmware · CWE-538 | Yüksek7,5 | — | %29,9 | 29 Eki 2019 |
39İzleyin | CVE-2024-22433İstismar yok | Dell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSettings.get_ldap_info indell · data protection search · CWE-538 | Kritik9,8 | — | %0,6 | 6 Şub 2024 |
39İzleyin | CVE-2025-12059İstismar yok | Improper Access Control in Logo Software's Logo j-Platformlogo software industry and trade inc. · logo j-platform · CWE-538 | Kritik9,8 | — | %0,3 | 11 Şub 2026 |
38İzleyin | CVE-2023-5003Kavram kanıtı | Active Directory Integration < 4.1.10 - Unauthenticated Log Disclosureminiorange · active directory integration \/ ldap integration · CWE-538 | Yüksek7,5 | — | %25,9 | 16 Eki 2023 |
37İzleyin | CVE-2016-20024İstismar yok | ZKTeco ZKTime.Net 3.0.1.6 Insecure File Permissions Privilege Escalationzkteco inc. · zkteco zktime.net · CWE-538 | Kritik9,3 | — | %0,7 | 16 Mar 2026 |
35İzleyin | CVE-2024-51977Silahlaştırılmış | Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konbrother industries, ltd · hl-l8260cdn · CWE-538 | Orta5,3 | — | %46,6 | 25 Haz 2025 |
35İzleyin | CVE-2026-49298İstismar yok | Apache Airflow: JWT Token Exposure in KubernetesExecutor Command-Line Argumentsapache · airflow · CWE-538 | Yüksek8,8 | — | %0,8 | 1 Haz 2026 |
35İzleyin | CVE-2023-7062İstismar yok | Advanced File Manager Shortcodes <= 2.4 - Authenticated (Contributor+) Directory Traversaladvanced file manager · advanced file manager shortcodes · CWE-538 | Yüksek8,8 | — | %0,7 | 9 Tem 2024 |
35İzleyin | CVE-2019-15793Kavram kanıtı | Mishandling of file-system uid/gid with namespaces in shiftfslinux · linux kernel · CWE-538 | Yüksek8,8 | — | %0,7 | 23 Nis 2020 |
35İzleyin | CVE-2026-21672İstismar yok | A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.veeam · backup and replication · CWE-538 | Yüksek8,8 | — | %0,2 | 12 Mar 2026 |
34İzleyin | CVE-2021-4471İstismar yok | TG8 Firewall Unauthenticated User Password Disclosuretg8 · tg8 firewall · CWE-538 | Yüksek8,7 | — | %0,6 | 14 Kas 2025 |
34İzleyin | CVE-2016-15056İstismar yok | Ubee EVW3226 Unauthenticated Backup File Disclosureubee interactive · ubee evw3226 · CWE-538 | Yüksek8,7 | — | %0,6 | 14 Kas 2025 |
34İzleyin | CVE-2020-37104İstismar yok | ASTPP 4.0.1 VoIP Billing - Database Backup Downloadinextrix · astpp · CWE-538 | Yüksek8,7 | — | %0,6 | 11 Şub 2026 |
34İzleyin | CVE-2019-25706İstismar yok | Across DR-810 ROM-0 Unauthenticated File Disclosureacross · dr-810 · CWE-538 | Yüksek8,7 | — | %0,5 | 12 Nis 2026 |
34İzleyin | CVE-2026-23838İstismar yok | Tandoor Recipes module allows SQLite database to be externally accessible with the default settingsnixos · nixpkgs · CWE-538 | Yüksek8,7 | — | %0,5 | 19 Oca 2026 |
34İzleyin | CVE-2023-54346İstismar yok | WordPress Plugin Backup Migration 1.2.8 Unauthenticated Database Backup Downloadbackupbliss · wordpress plugin backup migration · CWE-538 | Yüksek8,7 | — | %0,3 | 5 May 2026 |
34İzleyin | CVE-2026-27173İstismar yok | Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line Argumentsapache · apache-airflow-providers-cncf-kubernetes · CWE-538 | Yüksek8,7 | — | %0,2 | 19 May 2026 |
31İzleyin | CVE-2022-4318İstismar yok | Cri-o: /etc/passwd tampering privesckubernetes · cri-o · CWE-538 | Yüksek7,8 | — | %0,3 | 25 Eyl 2023 |
31İzleyin | CVE-2021-40363İstismar yok | A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versionsiemens · simatic pcs 7 · CWE-538 | Yüksek7,8 | — | %0,2 | 9 Şub 2022 |
30İzleyin | CVE-2016-10399İstismar yok | Sendio versions before 8.2.1 were affected by a Local File Inclusion vulnerability that allowed an unauthenticated, remote attacker to read sendio · sendio · CWE-538 | Yüksek7,5 | — | %1,4 | 27 Tem 2017 |
30İzleyin | CVE-2022-44623İstismar yok | In JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner settingsjetbrains · teamcity · CWE-538 | Yüksek7,5 | — | %0,6 | 3 Kas 2022 |
30İzleyin | CVE-2026-15574İstismar yok | Vllm-orchestrator-gateway: vllm-orchestrator-gateway: authorization header and full chat payloads logged at hard-coded debug defaultred hat · red hat openshift ai (rhoai) · CWE-538 | Yüksek7,5 | — | %0,4 | 13 Tem 2026 |
30İzleyin | CVE-2023-46723İstismar yok | lte-pic32-writer's sendto.txt may disclose URL and the API keypajip · lte-pic32-writer · CWE-538 | Yüksek7,5 | — | %0,4 | 31 Eki 2023 |
30İzleyin | CVE-2025-61138İstismar yok | Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.qlik · qlik sense · CWE-538 | Yüksek7,5 | — | %0,3 | 20 Kas 2025 |
29İzleyin | CVE-2024-31954İstismar yok | An issue was discovered in the installer in Samsung Portable SSD for T5 1.6.10 on Windows.CWE-538 | Yüksek7,3 | — | %0,2 | 14 May 2024 |
- CVE-2019-685139İzleyin
A CWE-538: File and Directory Information Exposure vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (al
YüksekCVSS 7,5İstismar yokEPSS %30schneider-electric · modicon m580 firmware29 Eki 2019
- CVE-2024-2243339İzleyin
Dell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSettings.get_ldap_info in
KritikCVSS 9,8İstismar yokEPSS %1dell · data protection search6 Şub 2024
- CVE-2025-1205939İzleyin
Improper Access Control in Logo Software's Logo j-Platform
KritikCVSS 9,8İstismar yokEPSS %0logo software industry and trade inc. · logo j-platform11 Şub 2026
- CVE-2023-500338İzleyin
Active Directory Integration < 4.1.10 - Unauthenticated Log Disclosure
YüksekCVSS 7,5Kavram kanıtıEPSS %26miniorange · active directory integration \/ ldap integration16 Eki 2023
- CVE-2016-2002437İzleyin
ZKTeco ZKTime.Net 3.0.1.6 Insecure File Permissions Privilege Escalation
KritikCVSS 9,3İstismar yokEPSS %1zkteco inc. · zkteco zktime.net16 Mar 2026
- CVE-2024-5197735İzleyin
Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Kon
OrtaCVSS 5,3SilahlaştırılmışEPSS %47brother industries, ltd · hl-l8260cdn25 Haz 2025
- CVE-2026-4929835İzleyin
Apache Airflow: JWT Token Exposure in KubernetesExecutor Command-Line Arguments
YüksekCVSS 8,8İstismar yokEPSS %1apache · airflow1 Haz 2026
- CVE-2023-706235İzleyin
Advanced File Manager Shortcodes <= 2.4 - Authenticated (Contributor+) Directory Traversal
YüksekCVSS 8,8İstismar yokEPSS %1advanced file manager · advanced file manager shortcodes9 Tem 2024
- CVE-2019-1579335İzleyin
Mishandling of file-system uid/gid with namespaces in shiftfs
YüksekCVSS 8,8Kavram kanıtıEPSS %1linux · linux kernel23 Nis 2020
- CVE-2026-2167235İzleyin
A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.
YüksekCVSS 8,8İstismar yokEPSS %0veeam · backup and replication12 Mar 2026
- CVE-2021-447134İzleyin
TG8 Firewall Unauthenticated User Password Disclosure
YüksekCVSS 8,7İstismar yokEPSS %1tg8 · tg8 firewall14 Kas 2025
- CVE-2016-1505634İzleyin
Ubee EVW3226 Unauthenticated Backup File Disclosure
YüksekCVSS 8,7İstismar yokEPSS %1ubee interactive · ubee evw322614 Kas 2025
- CVE-2020-3710434İzleyin
ASTPP 4.0.1 VoIP Billing - Database Backup Download
YüksekCVSS 8,7İstismar yokEPSS %1inextrix · astpp11 Şub 2026
- CVE-2019-2570634İzleyin
Across DR-810 ROM-0 Unauthenticated File Disclosure
YüksekCVSS 8,7İstismar yokEPSS %1across · dr-81012 Nis 2026
- CVE-2026-2383834İzleyin
Tandoor Recipes module allows SQLite database to be externally accessible with the default settings
YüksekCVSS 8,7İstismar yokEPSS %1nixos · nixpkgs19 Oca 2026
- CVE-2023-5434634İzleyin
WordPress Plugin Backup Migration 1.2.8 Unauthenticated Database Backup Download
YüksekCVSS 8,7İstismar yokEPSS %0backupbliss · wordpress plugin backup migration5 May 2026
- CVE-2026-2717334İzleyin
Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line Arguments
YüksekCVSS 8,7İstismar yokEPSS %0apache · apache-airflow-providers-cncf-kubernetes19 May 2026
- CVE-2022-431831İzleyin
Cri-o: /etc/passwd tampering privesc
YüksekCVSS 7,8İstismar yokEPSS %0kubernetes · cri-o25 Eyl 2023
- CVE-2021-4036331İzleyin
A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All version
YüksekCVSS 7,8İstismar yokEPSS %0siemens · simatic pcs 79 Şub 2022
- CVE-2016-1039930İzleyin
Sendio versions before 8.2.1 were affected by a Local File Inclusion vulnerability that allowed an unauthenticated, remote attacker to read
YüksekCVSS 7,5İstismar yokEPSS %1sendio · sendio27 Tem 2017
- CVE-2022-4462330İzleyin
In JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner settings
YüksekCVSS 7,5İstismar yokEPSS %1jetbrains · teamcity3 Kas 2022
- CVE-2026-1557430İzleyin
Vllm-orchestrator-gateway: vllm-orchestrator-gateway: authorization header and full chat payloads logged at hard-coded debug default
YüksekCVSS 7,5İstismar yokEPSS %0red hat · red hat openshift ai (rhoai)13 Tem 2026
- CVE-2023-4672330İzleyin
lte-pic32-writer's sendto.txt may disclose URL and the API key
YüksekCVSS 7,5İstismar yokEPSS %0pajip · lte-pic32-writer31 Eki 2023
- CVE-2025-6113830İzleyin
Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.
YüksekCVSS 7,5İstismar yokEPSS %0qlik · qlik sense20 Kas 2025
- CVE-2024-3195429İzleyin
An issue was discovered in the installer in Samsung Portable SSD for T5 1.6.10 on Windows.
YüksekCVSS 7,3İstismar yokEPSS %014 May 2024