CWE-538— Insertion of Sensitive Information into Externally-Accessible File or Directory
The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.— MITRE CWE catalog
102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-538page 1 of 3
- CVE-2023-28444CRITICALCVSS 9.9EG 9.92023-03-24
angular-server-side-configuration helps configure an angular application at runtime on the server or in a docker container via environment variables. angular-server-side-configuration detects used environment variables in TypeScript (.ts) …
- CVE-2016-20024CRITICALCVSS 9.8EG 9.82026-03-16
ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate privileges by modifying executable files. Attackers can exploit world-writable permissions on the ZKTimeNet3.0 directo…
- CVE-2025-12059CRITICALCVSS 9.8EG 9.82026-02-11
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Logo Software Industry and Trade Inc. Logo j-Platform allows Exploiting Incorrectly Configured Access Control Security Levels. This issue aff…
- CVE-2025-11079CRITICALCVSS 9.8EG 9.82025-09-27
A security flaw has been discovered in Campcodes Farm Management System 1.0. Affected by this issue is some unknown functionality. The manipulation results in file and directory information exposure. The attack may be performed from remote…
- CVE-2026-49298HIGHCVSS 8.8EG 8.82026-06-01
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API us…
- CVE-2026-21672HIGHCVSS 8.8EG 8.82026-03-12
A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.
- CVE-2023-7062HIGHCVSS 8.8EG 8.82024-07-10
The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4. This makes it possible for attackers with contributor access or higher to read the contents of arbitr…
- CVE-2024-22433HIGHCVSS 8.8EG 8.82024-02-06
Dell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSettings.get_ldap_info in DP Search. A remote unauthorized unauthenticated attacker could potentially exploit this vulnerabi…
- CVE-2022-23508HIGHCVSS 8.8EG 8.82023-01-09
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in GitOps run could allow a local user or process to alter a Kubernetes cluster's…
- CVE-2026-46617HIGHCVSS 8.7EG 8.72026-05-21
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, Fission runtime pods were created with ServiceAccountName: fission-fetch…
- CVE-2026-27173HIGHCVSS 8.7EG 8.72026-05-19
JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running t…
- CVE-2026-23838HIGHCVSS 8.7EG 8.72026-01-19
Tandoor Recipes is a recipe manager than can be installed with the Nix package manager. Starting in version 23.05 and prior to version 26.05, when using the default configuration of Tandoor Recipes, specifically using SQLite and default `M…
- CVE-2021-4471HIGHCVSS 8.7EG 8.72025-11-14
TG8 Firewall exposes a directory such as /data/ over HTTP without authentication. This directory stores credential files for previously logged-in users. A remote unauthenticated attacker can enumerate and download files within the director…
- CVE-2016-15056HIGHCVSS 8.7EG 8.72025-11-14
Ubee EVW3226 cable modem/routers firmware versions up to and including 1.0.20 store configuration backup files in the web root after they are generated for download. These backup files remain accessible without authentication until the nex…
- CVE-2022-4318HIGHCVSS 7.8EG 7.82023-09-25
A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
- CVE-2021-40363HIGHCVSS 7.8EG 7.82022-02-09
A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7), SIMATIC WinCC V16 (…
- CVE-2021-21250HIGHCVSS 7.7EG 7.72021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which may lead to arbitrary file read. When BuildSpec is provided in XML format, the spec is processed by XmlBuildSpecMigrator.migra…
- CVE-2024-22045HIGHCVSS 7.6EG 7.62024-03-12
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.1 SP1). The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, bu…
- CVE-2026-15574HIGHCVSS 7.5EG 7.52026-07-13
A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorization headers and full chat payloads, which may contain personally identifiable information (PII) and secrets, to persist…
- CVE-2023-54346HIGHCVSS 7.5EG 7.52026-05-05
WordPress Plugin Backup Migration 1.2.8 contains an information disclosure vulnerability that allows unauthenticated attackers to download complete database backups by accessing predictable file paths. Attackers can enumerate backup direct…
- CVE-2019-25706HIGHCVSS 7.5EG 7.52026-04-12
Across DR-810 contains an unauthenticated file disclosure vulnerability that allows remote attackers to download the rom-0 backup file containing sensitive information by sending a simple GET request. Attackers can access the rom-0 endpoin…
- CVE-2020-37104HIGHCVSS 7.5EG 7.52026-02-11
ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database backup files by predicting backup filename patterns. Attackers can generate a list of 6-digit PIN combinations and fuzz…
- CVE-2025-61138HIGHCVSS 7.5EG 7.52025-11-20
Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.
- CVE-2023-46723HIGHCVSS 7.5EG 7.52023-10-31
lte-pic32-writer is a writer for PIC32 devices. In versions 0.0.1 and prior, those who use `sendto.txt` are vulnerable to attackers who known the IMEI reading the sendto.txt. The sendto.txt file can contain the SNS(such as slack and zulip)…
- CVE-2023-5003HIGHCVSS 7.5EG 7.52023-10-16
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains acce…
- CVE-2019-6851HIGHCVSS 7.5EG 7.52019-10-29
A CWE-538: File and Directory Information Exposure vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information from the controller when usin…
- CVE-2018-10590HIGHCVSS 7.5EG 7.52018-05-15
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an information …
- CVE-2016-10399HIGHCVSS 7.5EG 7.52017-07-27
Sendio versions before 8.2.1 were affected by a Local File Inclusion vulnerability that allowed an unauthenticated, remote attacker to read potentially sensitive system files via a specially crafted URL.
- CVE-2023-4595HIGHCVSS 6.5EG 7.52023-11-23
An information exposure vulnerability has been found, the exploitation of which could allow a remote user to retrieve sensitive information stored on the server such as credential files, configuration files, application files, etc., simply…
- CVE-2022-44623HIGHCVSS 6.5EG 7.52022-11-03
In JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner settings
- CVE-2025-68429HIGHCVSS 7.3EG 7.32025-12-17
Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present starting in versions 7.0.0 and prior to versions 7.6.21, 8.6.15, 9.1.17, and 10.1.10 relates to Storybook’s handling …
- CVE-2024-31954HIGHCVSS 7.3EG 7.32024-05-14
An issue was discovered in the installer in Samsung Portable SSD for T5 1.6.10 on Windows. Because it is possible to tamper with the directory and DLL files used during the installation process, an attacker can escalate privileges through …
- CVE-2025-46820HIGHCVSS 7.1EG 7.12025-05-06
phpgt/Dom provides access to modern DOM APIs. Versions of phpgt/Dom prior to 4.1.8 expose the GITHUB_TOKEN in the Dom workflow run artifact. The ci.yml workflow file uses actions/upload-artifact@v4 to upload the build artifact. This artifa…
- CVE-2026-67361MEDIUMCVSS 6.9EG 6.92026-08-21
Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - The file upload endpoint accepted POST requests from unauthenticated visitors with no CS…
- CVE-2026-57442MEDIUMCVSS 6.9EG 6.92026-06-19
MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, PathFilter in src/pathfilter.ts uses root-anchored deny-list patterns, so nested .git, .obsidian, and node_modules path…
- CVE-2024-6880MEDIUMCVSS 6.9EG 6.92025-01-10
During MegaBIP installation process, a user is encouraged to change a default path to administrative portal, as keeping it secret is listed by the author as one of the protection mechanisms. Publicly available source code of "/registered…
- CVE-2024-47580MEDIUMCVSS 6.8EG 6.82024-12-10
An attacker authenticated as an administrator can use an exposed webservice to create a PDF with an embedded attachment. By specifying the file to be an internal server file and subsequently downloading the generated PDF, the attacker can…
- CVE-2024-47579MEDIUMCVSS 6.8EG 6.82024-12-10
An attacker authenticated as an administrator can use an exposed webservice to upload or download a custom PDF font file on the system server. Using the upload functionality to copy an internal file into a font file and subsequently using…
- CVE-2025-36372MEDIUMCVSS 6.5EG 6.52026-06-30
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information to an authenticated user from the monitoring and event tables.
- CVE-2025-52642MEDIUMCVSS 6.5EG 6.52026-03-16
HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or system behaviour. Exposure of internal paths may reveal environment structure details which could potentially aid in fu…
- CVE-2025-27017MEDIUMCVSS 6.5EG 6.52025-03-12
Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB components generate during processing. An authorized user with read access to the provenance e…
- CVE-2025-0194MEDIUMCVSS 6.5EG 6.52025-01-08
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. Under certain conditions, access tokens may have been logged whe…
- CVE-2021-3709MEDIUMCVSS 6.5EG 6.52021-10-01
Function check_attachment_for_errors() in file data/general-hooks/ubuntu.py could be tricked into exposing private data via a constructed crash file. This issue affects: apport 2.14.1 versions prior to 2.14.1-0ubuntu3.29+esm8; 2.20.1 versi…
- CVE-2019-15793MEDIUMCVSS 6.5EG 6.52020-04-24
In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, several locations which shift ids translate user/group ids before performing operations in the lower filesystem were translating them in…
- CVE-2019-7618MEDIUMCVSS 6.5EG 6.52019-10-01
A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local filesystem of the Kibana instance running C…
- CVE-2018-11798MEDIUMCVSS 6.5EG 6.52019-01-07
The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.
- CVE-2017-16770MEDIUMCVSS 6.5EG 6.52018-02-27
File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to obtain other user's sensitive files via the fi…
- CVE-2024-51977MEDIUMCVSS 5.3EG 6.42025-06-25
An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631), can leak several pieces of sensitive information from a vulnerable device. The URI path …
- CVE-2025-36051MEDIUMCVSS 5.5EG 6.22026-03-19
IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files that could be read by a local user.
- CVE-2025-24689MEDIUMCVSS 5.9EG 5.92025-01-27
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta allows Retrieve Embedded Sensitive Data.This issue affects…
Map vulnerabilities like CWE-538 to your infrastructure
EchelonGraph correlates every CVE — across CWE-538 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →