CWE-219 · 6 kayıt
Storage of File with Sensitive Data Under Web Root
Bu sınıftaki CVE’ler
6 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
34İzleyin | CVE-2024-39776İstismar yok | Avtec Outpost Storage of File with Sensitive Data Under Web Rootavtecinc · outpost uploader utility · CWE-219 | Yüksek8,7 | — | %0,4 | 22 Ağu 2024 |
31İzleyin | CVE-2022-21236İstismar yok | An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_20121102.reolink · rlc-410w firmware · CWE-219 | Yüksek7,5 | — | %1,8 | 28 Oca 2022 |
31İzleyin | CVE-2024-56159Kavram kanıtı | Server source code is exposed to the public if sourcemaps are enabledastro · astro · CWE-219 | Yüksek7,8 | — | %1,5 | 19 Ara 2024 |
26İzleyin | CVE-2022-36306İstismar yok | An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web seairspan · airvelocity 1500 firmware · CWE-219 | Orta6,5 | — | %1,0 | 15 Ağu 2022 |
22İzleyin | CVE-2002-2024İstismar yok | Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reasohorde · imp · CWE-219 | Orta5,3 | — | %1,9 | 31 Ara 2002 |
21İzleyin | CVE-2023-39467İstismar yok | Triangle MicroWorks SCADA Data Gateway certificate Information Disclosure Vulnerabilitytrianglemicroworks · scada data gateway · CWE-219 | Orta5,3 | — | %0,6 | 2 May 2024 |
- CVE-2024-3977634İzleyin
Avtec Outpost Storage of File with Sensitive Data Under Web Root
YüksekCVSS 8,7İstismar yokEPSS %0avtecinc · outpost uploader utility22 Ağu 2024
- CVE-2022-2123631İzleyin
An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_20121102.
YüksekCVSS 7,5İstismar yokEPSS %2reolink · rlc-410w firmware28 Oca 2022
- CVE-2024-5615931İzleyin
Server source code is exposed to the public if sourcemaps are enabled
YüksekCVSS 7,8Kavram kanıtıEPSS %2astro · astro19 Ara 2024
- CVE-2022-3630626İzleyin
An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web se
OrtaCVSS 6,5İstismar yokEPSS %1airspan · airvelocity 1500 firmware15 Ağu 2022
- CVE-2002-202422İzleyin
Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reaso
OrtaCVSS 5,3İstismar yokEPSS %2horde · imp31 Ara 2002
- CVE-2023-3946721İzleyin
Triangle MicroWorks SCADA Data Gateway certificate Information Disclosure Vulnerability
OrtaCVSS 5,3İstismar yokEPSS %1trianglemicroworks · scada data gateway2 May 2024