Skip to main content

CWE archive

CWE-548 CVEs

Programmatic archive

57 CVEs tagged with CWE-5480 Critical, 15 High, 39 Medium, 3 Low, 0 Unrated.

CVE-2026-50233

Published Jun 5, 2026

Lyrion Music Server 9.2.0 contains an arbitrary directory listing vulnerability in its readdirectory query, exposed through both the CLI service (TCP port 9090) and the HTTP JSON-…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-41933

Published May 14, 2026

Vvveb before 1.0.8.3 contains a directory listing information disclosure vulnerability that allows unauthenticated attackers to enumerate files and directories by accessing multip…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
20.4

CVE-2026-22860

Published Feb 18, 2026

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match on the expanded path. A request…

CVSS 7.5 · High
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2023-38265

Published Feb 17, 2026

IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could disclose folder location information to an unauthenticated attacker that could aid in further attacks ag…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36921

Published Jan 6, 2026

RED-V Super Digital Signage System 5.1.1 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive webserver log files. Attackers…

CVSS 6.9 · Medium

CVE-2022-50788

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly br…

CVSS 6.9 · Medium

CVE-2021-47718

Published Dec 9, 2025

OpenBMCS 2.4 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive files by exploiting directory listing functionality. Attack…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-13200

Published Nov 15, 2025

A vulnerability was determined in SourceCodester Farm Management System 1.0. Affected by this vulnerability is an unknown functionality. This manipulation causes exposure of infor…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-62396

Published Oct 23, 2025

An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-61685

Published Oct 3, 2025

Mastra is a Typescript framework for building AI agents and assistants. Versions 0.13.8 through 0.13.20-alpha.0 are vulnerable to a Directory Traversal attack that results in the…

CVSS 6.5 · Medium

CVE-2025-23378

Published Apr 10, 2025

Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information through directory listing vulnerability. A low privileged attacker with local access…

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-2651

Published Mar 23, 2025

A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /oews/admin/. The manipulati…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2038

Published Mar 6, 2025

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /upload/. The ma…

CVSS 6.9 · Medium
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 1-25 of 57 CVEsPage 1 of 3