CWE-548 · 60 записей
Exposure of Information Through Directory Listing
CVE этого класса
60 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2020-8161Эксплойта нет | A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Dirack project · rack · CWE-548 | Высокая8,6 | — | 3,4 % | 2 июл. 2020 г. |
34Наблюдать | CVE-2020-7858Эксплойта нет | AquaNPlayer directory traversing vulnerabilitycdnetworks · aquanplayer · CWE-548 | Высокая8,6 | — | 1,1 % | 22 апр. 2021 г. |
34Наблюдать | CVE-2021-47718Эксплойта нет | OpenBMCS Directory Listing Information Disclosureopenbmcs · openbmcs · CWE-548 | Высокая8,7 | — | 0,5 % | 9 дек. 2025 г. |
31Наблюдать | CVE-2023-7164Proof of concept | BackWPup < 4.0.4 - Unauthenticated Backup Downloadinpsyde · backwpup · CWE-548 | Высокая7,5 | — | 2,3 % | 8 апр. 2024 г. |
31Наблюдать | CVE-2018-14785Эксплойта нет | NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior.netcommwireless · nwl-25 firmware · CWE-548 | Высокая7,5 | — | 2,2 % | 10 авг. 2018 г. |
31Наблюдать | CVE-2018-16493Эксплойта нет | A path traversal vulnerability was found in module static-resource-server 1.7.2 that allows unauthorized read access to any file on the servstatic-resource-server project · static-resource-server · CWE-548 | Высокая7,5 | — | 1,8 % | 1 февр. 2019 г. |
31Наблюдать | CVE-2017-6045Эксплойта нет | An Information Exposure issue was discovered in Trihedral VTScada Versions prior to 11.2.26.trihedral · vtscada · CWE-548 | Высокая7,5 | — | 1,7 % | 21 июн. 2017 г. |
30Наблюдать | CVE-2018-10590Эксплойта нет | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prioadvantech · webaccess · CWE-548 | Высокая7,5 | — | 1,7 % | 15 мая 2018 г. |
30Наблюдать | CVE-2019-5415Эксплойта нет | A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the directory that the vzeit · serve · CWE-548 | Высокая7,5 | — | 1,6 % | 21 мар. 2019 г. |
30Наблюдать | CVE-2021-27505Эксплойта нет | mySCADA myPRO Exposure of Information Through Directory Listingmyscada · mypro · CWE-548 | Высокая7,5 | — | 1,1 % | 13 мая 2022 г. |
30Наблюдать | CVE-2021-21528Эксплойта нет | Dell EMC PowerScale OneFS versions 9.1.0, 9.2.0.x, 9.2.1.x contain an Exposure of Information through Directory Listing vulnerability.dell · emc powerscale onefs · CWE-548 | Высокая7,5 | — | 1,0 % | 12 нояб. 2021 г. |
30Наблюдать | CVE-2016-15019Эксплойта нет | tombh jekbox server.rb exposure of information through directory listingjekbox project · jekbox · CWE-548 | Высокая7,5 | — | 0,7 % | 15 янв. 2023 г. |
30Наблюдать | CVE-2023-51948Эксплойта нет | A Site-wide directory listing vulnerability in /fm in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to list the files hostactidata · actinas sl 2u-8 rdx firmware · CWE-548 | Высокая7,5 | — | 0,7 % | 19 янв. 2024 г. |
30Наблюдать | CVE-2024-22082Эксплойта нет | An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before.elspec-ltd · g5dfr firmware · CWE-548 | Высокая7,5 | — | 0,6 % | 20 мар. 2024 г. |
30Наблюдать | CVE-2021-45446Эксплойта нет | Pentaho Business Analytics Server - Exposure of Information Through Directory Listinghitachi · vantara pentaho · CWE-548 | Высокая7,5 | — | 0,4 % | 2 нояб. 2022 г. |
30Наблюдать | CVE-2025-27452Эксплойта нет | The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure.endress · meac300-fnade4 firmware · CWE-548 | Высокая7,5 | — | 0,4 % | 3 июл. 2025 г. |
30Наблюдать | CVE-2025-32750Эксплойта нет | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability.dell · powerflex appliance intelligent catalog · CWE-548 | Высокая7,5 | — | 0,4 % | 20 мая 2026 г. |
30Наблюдать | CVE-2024-28766Эксплойта нет | IBM Security Directory Integrator information disclosureibm · security directory integrator · CWE-548 | Высокая7,5 | — | 0,3 % | 26 янв. 2025 г. |
30Наблюдать | CVE-2025-28170Эксплойта нет | Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control.grandstream · gxp1628 firmware · CWE-548 | Высокая7,6 | — | 0,3 % | 29 июл. 2025 г. |
29Наблюдать | CVE-2024-2340Proof of concept | Avada <= 7.11.6 - Unauthenticated Sensitive Information Exposure via Form Uploads Directory Listingtheme-fusion · avada · CWE-548 | Средняя5,3 | — | 28,0 % | 9 апр. 2024 г. |
27Наблюдать | CVE-2025-4807Эксплойта нет | SourceCodester Online Student Clearance System exposure of information through directory listingsenior-walter · online student clearance system · CWE-548 | Средняя6,9 | — | 1,1 % | 16 мая 2025 г. |
27Наблюдать | CVE-2024-8711Эксплойта нет | SourceCodester Food Ordering Management System includes exposure of information through directory listingoretnom23 · food ordering management system · CWE-548 | Средняя6,9 | — | 0,8 % | 12 сент. 2024 г. |
27Наблюдать | CVE-2022-50788Эксплойта нет | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Information Disclosure via Log Directorysound4 · first firmware · CWE-548 | Средняя6,9 | — | 0,8 % | 30 дек. 2025 г. |
27Наблюдать | CVE-2024-7912Эксплойта нет | CodeAstro Online Railway Reservation System assets exposure of information through directory listingonline railway reservation system project · online railway reservation system · CWE-548 | Средняя6,9 | — | 0,8 % | 18 авг. 2024 г. |
27Наблюдать | CVE-2024-7809Эксплойта нет | SourceCodester Online Graduate Tracer System nbproject exposure of information through directory listingtamparongj03 · online graduate tracer system · CWE-548 | Средняя6,9 | — | 0,8 % | 14 авг. 2024 г. |
- CVE-2020-816135Наблюдать
A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Di
ВысокаяCVSS 8,6Эксплойта нетEPSS 3 %rack project · rack2 июл. 2020 г.
- CVE-2020-785834Наблюдать
AquaNPlayer directory traversing vulnerability
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %cdnetworks · aquanplayer22 апр. 2021 г.
- CVE-2021-4771834Наблюдать
OpenBMCS Directory Listing Information Disclosure
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %openbmcs · openbmcs9 дек. 2025 г.
- CVE-2023-716431Наблюдать
BackWPup < 4.0.4 - Unauthenticated Backup Download
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %inpsyde · backwpup8 апр. 2024 г.
- CVE-2018-1478531Наблюдать
NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %netcommwireless · nwl-25 firmware10 авг. 2018 г.
- CVE-2018-1649331Наблюдать
A path traversal vulnerability was found in module static-resource-server 1.7.2 that allows unauthorized read access to any file on the serv
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %static-resource-server project · static-resource-server1 февр. 2019 г.
- CVE-2017-604531Наблюдать
An Information Exposure issue was discovered in Trihedral VTScada Versions prior to 11.2.26.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %trihedral · vtscada21 июн. 2017 г.
- CVE-2018-1059030Наблюдать
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prio
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %advantech · webaccess15 мая 2018 г.
- CVE-2019-541530Наблюдать
A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the directory that the v
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %zeit · serve21 мар. 2019 г.
- CVE-2021-2750530Наблюдать
mySCADA myPRO Exposure of Information Through Directory Listing
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %myscada · mypro13 мая 2022 г.
- CVE-2021-2152830Наблюдать
Dell EMC PowerScale OneFS versions 9.1.0, 9.2.0.x, 9.2.1.x contain an Exposure of Information through Directory Listing vulnerability.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dell · emc powerscale onefs12 нояб. 2021 г.
- CVE-2016-1501930Наблюдать
tombh jekbox server.rb exposure of information through directory listing
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %jekbox project · jekbox15 янв. 2023 г.
- CVE-2023-5194830Наблюдать
A Site-wide directory listing vulnerability in /fm in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to list the files host
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %actidata · actinas sl 2u-8 rdx firmware19 янв. 2024 г.
- CVE-2024-2208230Наблюдать
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %elspec-ltd · g5dfr firmware20 мар. 2024 г.
- CVE-2021-4544630Наблюдать
Pentaho Business Analytics Server - Exposure of Information Through Directory Listing
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %hitachi · vantara pentaho2 нояб. 2022 г.
- CVE-2025-2745230Наблюдать
The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %endress · meac300-fnade4 firmware3 июл. 2025 г.
- CVE-2025-3275030Наблюдать
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %dell · powerflex appliance intelligent catalog20 мая 2026 г.
- CVE-2024-2876630Наблюдать
IBM Security Directory Integrator information disclosure
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %ibm · security directory integrator26 янв. 2025 г.
- CVE-2025-2817030Наблюдать
Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control.
ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %grandstream · gxp1628 firmware29 июл. 2025 г.
- CVE-2024-234029Наблюдать
Avada <= 7.11.6 - Unauthenticated Sensitive Information Exposure via Form Uploads Directory Listing
СредняяCVSS 5,3Proof of conceptEPSS 28 %theme-fusion · avada9 апр. 2024 г.
- CVE-2025-480727Наблюдать
SourceCodester Online Student Clearance System exposure of information through directory listing
СредняяCVSS 6,9Эксплойта нетEPSS 1 %senior-walter · online student clearance system16 мая 2025 г.
- CVE-2024-871127Наблюдать
SourceCodester Food Ordering Management System includes exposure of information through directory listing
СредняяCVSS 6,9Эксплойта нетEPSS 1 %oretnom23 · food ordering management system12 сент. 2024 г.
- CVE-2022-5078827Наблюдать
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Information Disclosure via Log Directory
СредняяCVSS 6,9Эксплойта нетEPSS 1 %sound4 · first firmware30 дек. 2025 г.
- CVE-2024-791227Наблюдать
CodeAstro Online Railway Reservation System assets exposure of information through directory listing
СредняяCVSS 6,9Эксплойта нетEPSS 1 %online railway reservation system project · online railway reservation system18 авг. 2024 г.
- CVE-2024-780927Наблюдать
SourceCodester Online Graduate Tracer System nbproject exposure of information through directory listing
СредняяCVSS 6,9Эксплойта нетEPSS 1 %tamparongj03 · online graduate tracer system14 авг. 2024 г.