CWE-538
Insertion of Sensitive Information into Externally-Accessible File or Directory
The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.
90 vulnerabilities with CWE-538
CVE-2023-5937
LOW
Nozomi Networks Arc < 1.6.0 - Sensitive Information Exposure via World-Readable Configuration Files
CVSS 3.8
CVE-2023-4595
HIGH
Seattlelab SLMail - Information Exposure
CVSS 7.5
CVE-2023-46723
HIGH
lte-pic32-writer <0.0.1 - Info Disclosure
CVSS 8.9
CVE-2023-38558
MEDIUM
SIMATIC PCS neo Administration Console V4.0 and V4.0 Update 1 - Credential Leak via Windows Admin Credential Exposure
CVSS 5.5
CVE-2023-4480
MEDIUM
phpfusion < 9.10.30 - Path Traversal and Arbitrary File Write via Fusion File Manager
CVSS 5.5
CVE-2023-28444
CRITICAL
angular-server-side-configuration - Info Disclosure
CVSS 9.9
CVE-2022-43933
MEDIUM
Brocade SANnav <2.2.2 - Info Disclosure
CVSS 4.4
CVE-2022-4318
HIGH
cri-o < 1.26.0 - Arbitrary File Write via Environment Variable
CVSS 7.8
CVE-2022-26329
LOW
NetIQ Identity Manager <4.8.5 - Info Disclosure
CVSS 1.8
CVE-2022-23508
HIGH
Weave GitOps - Privilege Escalation
CVSS 8.8
CVE-2022-44623
MEDIUM
JetBrains TeamCity <2022.10 - Info Disclosure
CVSS 6.5
CVE-2022-20864
MEDIUM
Cisco IOS XE ROM Monitor - Unauthenticated Sensitive Information Exposure via Console Commands
CVSS 4.6
CVE-2022-0013
MEDIUM
Cortex XDR Agent 5.0-5.0.11, 6.1-6.1.8, 7.2-7.2.3, 7.3-7.3.1 - Arbitrary File Read via Support File
CVSS 5.0
CVE-2021-4471
HIGH
TG8 Firewall - Unauthenticated Credential Exposure via HTTP Directory Traversal
CVE-2021-40363
HIGH
SIMATIC PCS 7, WinCC - Info Disclosure
CVSS 7.8
CVE-2021-3709
MEDIUM
apport Path Traversal in check_attachment_for_errors()
CVSS 6.5
CVE-2021-32822
MEDIUM
hbs - File Disclosure via Express Render API Configuration Overwrite
CVSS 4.0
CVE-2021-1406
MEDIUM
Cisco Unified Communications Manager - Authenticated Exposure of Sensitive Information via Downloadable Files
CVSS 4.9
CVE-2021-21250
HIGH
OneDev < 4.0.3 - Arbitrary File Read via XML External Entity Injection in BuildSpec
CVSS 7.7
CVE-2020-37104
HIGH
ASTPP 4.0.1 - Unauthenticated Sensitive Information Disclosure via Database Backup Download
CVSS 7.5
CVE-2019-25717
MEDIUM
Dräger Infinity Delta/Kappa Patient Monitors Unauthenticated Log File Disclosure
CVSS 4.3
CVE-2019-25706
HIGH
Across DR-810 ROM-0 Unauthenticated File Disclosure
CVSS 7.5
CVE-2019-15793
MEDIUM
Linux kernel <5.3 - Privilege Escalation
CVSS 6.5
CVE-2019-6851
HIGH
Schneider Electric Modicon M580, M340, Premium, Quantum - File and Directory Information Exposure via TFTP Protocol
CVSS 7.5
CVE-2019-7618
MEDIUM
Elastic Code <7.3.2 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities
90