CWE-219 · 6 записей
Storage of File with Sensitive Data Under Web Root
CVE этого класса
6 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
34Наблюдать | CVE-2024-39776Эксплойта нет | Avtec Outpost Storage of File with Sensitive Data Under Web Rootavtecinc · outpost uploader utility · CWE-219 | Высокая8,7 | — | 0,4 % | 22 авг. 2024 г. |
31Наблюдать | CVE-2022-21236Эксплойта нет | An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_20121102.reolink · rlc-410w firmware · CWE-219 | Высокая7,5 | — | 1,8 % | 28 янв. 2022 г. |
31Наблюдать | CVE-2024-56159Proof of concept | Server source code is exposed to the public if sourcemaps are enabledastro · astro · CWE-219 | Высокая7,8 | — | 1,5 % | 19 дек. 2024 г. |
26Наблюдать | CVE-2022-36306Эксплойта нет | An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web seairspan · airvelocity 1500 firmware · CWE-219 | Средняя6,5 | — | 1,0 % | 15 авг. 2022 г. |
22Наблюдать | CVE-2002-2024Эксплойта нет | Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reasohorde · imp · CWE-219 | Средняя5,3 | — | 1,9 % | 31 дек. 2002 г. |
21Наблюдать | CVE-2023-39467Эксплойта нет | Triangle MicroWorks SCADA Data Gateway certificate Information Disclosure Vulnerabilitytrianglemicroworks · scada data gateway · CWE-219 | Средняя5,3 | — | 0,6 % | 2 мая 2024 г. |
- CVE-2024-3977634Наблюдать
Avtec Outpost Storage of File with Sensitive Data Under Web Root
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %avtecinc · outpost uploader utility22 авг. 2024 г.
- CVE-2022-2123631Наблюдать
An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_20121102.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %reolink · rlc-410w firmware28 янв. 2022 г.
- CVE-2024-5615931Наблюдать
Server source code is exposed to the public if sourcemaps are enabled
ВысокаяCVSS 7,8Proof of conceptEPSS 2 %astro · astro19 дек. 2024 г.
- CVE-2022-3630626Наблюдать
An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web se
СредняяCVSS 6,5Эксплойта нетEPSS 1 %airspan · airvelocity 1500 firmware15 авг. 2022 г.
- CVE-2002-202422Наблюдать
Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reaso
СредняяCVSS 5,3Эксплойта нетEPSS 2 %horde · imp31 дек. 2002 г.
- CVE-2023-3946721Наблюдать
Triangle MicroWorks SCADA Data Gateway certificate Information Disclosure Vulnerability
СредняяCVSS 5,3Эксплойта нетEPSS 1 %trianglemicroworks · scada data gateway2 мая 2024 г.