CWE-548 · 60 records
Exposure of Information Through Directory Listing
CVEs in this class
60 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2020-8161No exploit | A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Dirack project · rack · CWE-548 | High8.6 | — | 3.4% | Jul 2, 2020 |
34Monitor | CVE-2020-7858No exploit | AquaNPlayer directory traversing vulnerabilitycdnetworks · aquanplayer · CWE-548 | High8.6 | — | 1.1% | Apr 22, 2021 |
34Monitor | CVE-2021-47718No exploit | OpenBMCS Directory Listing Information Disclosureopenbmcs · openbmcs · CWE-548 | High8.7 | — | 0.5% | Dec 9, 2025 |
31Monitor | CVE-2023-7164Proof of concept | BackWPup < 4.0.4 - Unauthenticated Backup Downloadinpsyde · backwpup · CWE-548 | High7.5 | — | 2.3% | Apr 8, 2024 |
31Monitor | CVE-2018-14785No exploit | NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior.netcommwireless · nwl-25 firmware · CWE-548 | High7.5 | — | 2.2% | Aug 10, 2018 |
31Monitor | CVE-2018-16493No exploit | A path traversal vulnerability was found in module static-resource-server 1.7.2 that allows unauthorized read access to any file on the servstatic-resource-server project · static-resource-server · CWE-548 | High7.5 | — | 1.8% | Feb 1, 2019 |
31Monitor | CVE-2017-6045No exploit | An Information Exposure issue was discovered in Trihedral VTScada Versions prior to 11.2.26.trihedral · vtscada · CWE-548 | High7.5 | — | 1.7% | Jun 21, 2017 |
30Monitor | CVE-2018-10590No exploit | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prioadvantech · webaccess · CWE-548 | High7.5 | — | 1.7% | May 15, 2018 |
30Monitor | CVE-2019-5415No exploit | A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the directory that the vzeit · serve · CWE-548 | High7.5 | — | 1.6% | Mar 21, 2019 |
30Monitor | CVE-2021-27505No exploit | mySCADA myPRO Exposure of Information Through Directory Listingmyscada · mypro · CWE-548 | High7.5 | — | 1.1% | May 13, 2022 |
30Monitor | CVE-2021-21528No exploit | Dell EMC PowerScale OneFS versions 9.1.0, 9.2.0.x, 9.2.1.x contain an Exposure of Information through Directory Listing vulnerability.dell · emc powerscale onefs · CWE-548 | High7.5 | — | 1.0% | Nov 12, 2021 |
30Monitor | CVE-2016-15019No exploit | tombh jekbox server.rb exposure of information through directory listingjekbox project · jekbox · CWE-548 | High7.5 | — | 0.7% | Jan 15, 2023 |
30Monitor | CVE-2023-51948No exploit | A Site-wide directory listing vulnerability in /fm in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to list the files hostactidata · actinas sl 2u-8 rdx firmware · CWE-548 | High7.5 | — | 0.7% | Jan 19, 2024 |
30Monitor | CVE-2024-22082No exploit | An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before.elspec-ltd · g5dfr firmware · CWE-548 | High7.5 | — | 0.6% | Mar 20, 2024 |
30Monitor | CVE-2021-45446No exploit | Pentaho Business Analytics Server - Exposure of Information Through Directory Listinghitachi · vantara pentaho · CWE-548 | High7.5 | — | 0.4% | Nov 2, 2022 |
30Monitor | CVE-2025-27452No exploit | The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure.endress · meac300-fnade4 firmware · CWE-548 | High7.5 | — | 0.4% | Jul 3, 2025 |
30Monitor | CVE-2025-32750No exploit | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability.dell · powerflex appliance intelligent catalog · CWE-548 | High7.5 | — | 0.4% | May 20, 2026 |
30Monitor | CVE-2024-28766No exploit | IBM Security Directory Integrator information disclosureibm · security directory integrator · CWE-548 | High7.5 | — | 0.3% | Jan 26, 2025 |
30Monitor | CVE-2025-28170No exploit | Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control.grandstream · gxp1628 firmware · CWE-548 | High7.6 | — | 0.3% | Jul 29, 2025 |
29Monitor | CVE-2024-2340Proof of concept | Avada <= 7.11.6 - Unauthenticated Sensitive Information Exposure via Form Uploads Directory Listingtheme-fusion · avada · CWE-548 | Medium5.3 | — | 28.0% | Apr 9, 2024 |
27Monitor | CVE-2025-4807No exploit | SourceCodester Online Student Clearance System exposure of information through directory listingsenior-walter · online student clearance system · CWE-548 | Medium6.9 | — | 1.1% | May 16, 2025 |
27Monitor | CVE-2024-8711No exploit | SourceCodester Food Ordering Management System includes exposure of information through directory listingoretnom23 · food ordering management system · CWE-548 | Medium6.9 | — | 0.8% | Sep 12, 2024 |
27Monitor | CVE-2022-50788No exploit | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Information Disclosure via Log Directorysound4 · first firmware · CWE-548 | Medium6.9 | — | 0.8% | Dec 30, 2025 |
27Monitor | CVE-2024-7912No exploit | CodeAstro Online Railway Reservation System assets exposure of information through directory listingonline railway reservation system project · online railway reservation system · CWE-548 | Medium6.9 | — | 0.8% | Aug 18, 2024 |
27Monitor | CVE-2024-7809No exploit | SourceCodester Online Graduate Tracer System nbproject exposure of information through directory listingtamparongj03 · online graduate tracer system · CWE-548 | Medium6.9 | — | 0.8% | Aug 14, 2024 |
- CVE-2020-816135Monitor
A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Di
HighCVSS 8.6No exploitEPSS 3%rack project · rackJul 2, 2020
- CVE-2020-785834Monitor
AquaNPlayer directory traversing vulnerability
HighCVSS 8.6No exploitEPSS 1%cdnetworks · aquanplayerApr 22, 2021
- CVE-2021-4771834Monitor
OpenBMCS Directory Listing Information Disclosure
HighCVSS 8.7No exploitEPSS 1%openbmcs · openbmcsDec 9, 2025
- CVE-2023-716431Monitor
BackWPup < 4.0.4 - Unauthenticated Backup Download
HighCVSS 7.5Proof of conceptEPSS 2%inpsyde · backwpupApr 8, 2024
- CVE-2018-1478531Monitor
NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior.
HighCVSS 7.5No exploitEPSS 2%netcommwireless · nwl-25 firmwareAug 10, 2018
- CVE-2018-1649331Monitor
A path traversal vulnerability was found in module static-resource-server 1.7.2 that allows unauthorized read access to any file on the serv
HighCVSS 7.5No exploitEPSS 2%static-resource-server project · static-resource-serverFeb 1, 2019
- CVE-2017-604531Monitor
An Information Exposure issue was discovered in Trihedral VTScada Versions prior to 11.2.26.
HighCVSS 7.5No exploitEPSS 2%trihedral · vtscadaJun 21, 2017
- CVE-2018-1059030Monitor
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prio
HighCVSS 7.5No exploitEPSS 2%advantech · webaccessMay 15, 2018
- CVE-2019-541530Monitor
A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the directory that the v
HighCVSS 7.5No exploitEPSS 2%zeit · serveMar 21, 2019
- CVE-2021-2750530Monitor
mySCADA myPRO Exposure of Information Through Directory Listing
HighCVSS 7.5No exploitEPSS 1%myscada · myproMay 13, 2022
- CVE-2021-2152830Monitor
Dell EMC PowerScale OneFS versions 9.1.0, 9.2.0.x, 9.2.1.x contain an Exposure of Information through Directory Listing vulnerability.
HighCVSS 7.5No exploitEPSS 1%dell · emc powerscale onefsNov 12, 2021
- CVE-2016-1501930Monitor
tombh jekbox server.rb exposure of information through directory listing
HighCVSS 7.5No exploitEPSS 1%jekbox project · jekboxJan 15, 2023
- CVE-2023-5194830Monitor
A Site-wide directory listing vulnerability in /fm in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to list the files host
HighCVSS 7.5No exploitEPSS 1%actidata · actinas sl 2u-8 rdx firmwareJan 19, 2024
- CVE-2024-2208230Monitor
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before.
HighCVSS 7.5No exploitEPSS 1%elspec-ltd · g5dfr firmwareMar 20, 2024
- CVE-2021-4544630Monitor
Pentaho Business Analytics Server - Exposure of Information Through Directory Listing
HighCVSS 7.5No exploitEPSS 0%hitachi · vantara pentahoNov 2, 2022
- CVE-2025-2745230Monitor
The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure.
HighCVSS 7.5No exploitEPSS 0%endress · meac300-fnade4 firmwareJul 3, 2025
- CVE-2025-3275030Monitor
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability.
HighCVSS 7.5No exploitEPSS 0%dell · powerflex appliance intelligent catalogMay 20, 2026
- CVE-2024-2876630Monitor
IBM Security Directory Integrator information disclosure
HighCVSS 7.5No exploitEPSS 0%ibm · security directory integratorJan 26, 2025
- CVE-2025-2817030Monitor
Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control.
HighCVSS 7.6No exploitEPSS 0%grandstream · gxp1628 firmwareJul 29, 2025
- CVE-2024-234029Monitor
Avada <= 7.11.6 - Unauthenticated Sensitive Information Exposure via Form Uploads Directory Listing
MediumCVSS 5.3Proof of conceptEPSS 28%theme-fusion · avadaApr 9, 2024
- CVE-2025-480727Monitor
SourceCodester Online Student Clearance System exposure of information through directory listing
MediumCVSS 6.9No exploitEPSS 1%senior-walter · online student clearance systemMay 16, 2025
- CVE-2024-871127Monitor
SourceCodester Food Ordering Management System includes exposure of information through directory listing
MediumCVSS 6.9No exploitEPSS 1%oretnom23 · food ordering management systemSep 12, 2024
- CVE-2022-5078827Monitor
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Information Disclosure via Log Directory
MediumCVSS 6.9No exploitEPSS 1%sound4 · first firmwareDec 30, 2025
- CVE-2024-791227Monitor
CodeAstro Online Railway Reservation System assets exposure of information through directory listing
MediumCVSS 6.9No exploitEPSS 1%online railway reservation system project · online railway reservation systemAug 18, 2024
- CVE-2024-780927Monitor
SourceCodester Online Graduate Tracer System nbproject exposure of information through directory listing
MediumCVSS 6.9No exploitEPSS 1%tamparongj03 · online graduate tracer systemAug 14, 2024