CWE-548— Exposure of Information Through Directory Listing
The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.— MITRE CWE catalog
60 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-548page 2 of 2
- CVE-2026-82778MEDIUMCVSS 4.3EG 4.32026-09-14
An exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.
- CVE-2026-82775MEDIUMCVSS 4.3EG 4.32026-09-14
An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the direc…
- CVE-2025-2827MEDIUMCVSS 4.3EG 4.32025-07-08
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 could disclose sensitive installation directory information to an authenticated user that could be used in further attacks against the system.
- CVE-2025-1138MEDIUMCVSS 4.3EG 4.32025-05-15
IBM InfoSphere Information Server 11.7 could disclose sensitive information to an authenticated user that could aid in further attacks against the system through a directory listing.
- CVE-2024-35113MEDIUMCVSS 4.3EG 4.32025-01-25
IBM Control Center 6.2.1 and 6.3.1 could allow an authenticated user to obtain sensitive information exposed through a directory listing.
- CVE-2021-32511MEDIUMCVSS 4.3EG 4.32021-07-07
QSAN Storage Manager through directory listing vulnerability in ViewBroserList allows remote authenticated attackers to list arbitrary directories via the file path parameter. The referred vulnerability has been solved with the updated ver…
- CVE-2021-32510MEDIUMCVSS 4.3EG 4.32021-07-07
QSAN Storage Manager through directory listing vulnerability in antivirus function allows remote authenticated attackers to list arbitrary directories by injecting file path parameter. The referred vulnerability has been solved with the up…
- CVE-2025-23378LOWCVSS 3.3EG 3.32025-04-10
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information through directory listing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to inf…
- CVE-2024-56464LOWCVSS 2.7EG 2.72025-12-09
IBM QRadar SIEM 7.5 - 7.5.0 UP14 IF01 is affected by an information disclosure vulnerability involving exposure of directory information. IBM has addressed this vulnerability in the latest update.
- CVE-2024-28766LOWCVSS 2.4EG 2.42025-01-27
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory contents that could aid in further attacks against the system.
Map vulnerabilities like CWE-548 to your infrastructure
EchelonGraph correlates every CVE — across CWE-548 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →