Threats Tagged 'cwe-538'
View all threats tagged with 'cwe-538'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-538'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-50099: CWE-538 Insertion of sensitive information into Externally-Accessible file or directory in Naxclow Smart Doorbell X3CVE-2026-50099 0 During WiFi association, Naxclow device firmware prints the host network’s SSID, PSK, and negotiated WPA keys in cleartext to an exposed UART console on production hardware. The UART pads are labeled, run with default serial settings, and drop to an interactive RT-Thread shell that permits arbitrary memory reads, enabling full firmware extraction. An attacker with brief physical access, common for outdoor-mounted devices, can therefore recover WiFi credentials and bootstrap firmware-side attacks. Join the discussion | CVE Database V5 | 06/12/2026, 18:24:14 UTC Added: 06/12/2026, 18:55:14 UTC |
CVE-2026-29114: CWE-538 Insertion of sensitive information into Externally-Accessible file or directory in Dahua IPCCVE-2026-29114 0 A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that CA is installed and trusted on client systems, the attacker could issue fraudulent certificates trusted by those clients and undermine the certificate trust chain. Join the discussion | CVE Database V5 | 06/10/2026, 05:44:50 UTC Added: 06/10/2026, 06:41:08 UTC |
CVE-2026-49298: CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory in Apache Software Foundation Apache AirflowCVE-2026-49298 0 A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. `pods/get` in the Airflow namespace) could harvest the JWT from `kubectl describe pod` output and then call state-mutating Execution API endpoints — triggering Dag runs, clearing runs, reading or writing Variables / Connections / XComs — as if they were a running task. Affects deployments using the `KubernetesExecutor`. Users are advised to upgrade to `apache-airflow` 3.2.2 or later. This is the airflow-core half of the same vulnerability addressed by [CVE-2026-27173](https://www.cve.org/CVERecord?id=CVE-2026-27173), which shipped the apache-airflow-providers-cncf-kubernetes side of the fix. Deployments that already upgraded `apache-airflow-providers-cncf-kubernetes` to 10.17.0 or later per the CVE-2026-27173 advisory should additionally upgrade `apache-airflow` to 3.2.2 or later to close the core-side surface — the two fixes are complementary, not duplicates. Join the discussion | CVE Database V5 | 06/01/2026, 07:34:32 UTC Added: 06/01/2026, 09:18:49 UTC |
CVE Database V5 | 05/21/2026, 08:38:25 UTC Added: 05/21/2026, 11:36:59 UTC | |
CVE-2026-27173: CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory in Apache Software Foundation Apache Airflow CNCF Kubernetes providerCVE-2026-27173 0 JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running tasks via Task SDK and potentially allow to modify state of Airflow Database for tasks. Join the discussion | CVE Database V5 | 05/19/2026, 19:19:00 UTC Added: 05/19/2026, 20:33:33 UTC |
CVE-2026-33705: CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory in chamilo chamilo-lmsCVE-2026-33705 0 Chamilo LMS is a learning management system. Prior to 1.11.38, Twig template files (.tpl) under /main/template/default/ are directly accessible without authentication via HTTP GET requests. These templates expose internal application logic, variable names, AJAX endpoint URLs, and admin panel structure. This vulnerability is fixed in 1.11.38. Join the discussion | CVE Database V5 | 04/10/2026, 18:32:45 UTC Added: 04/11/2026, 05:17:38 UTC |
CVE-2024-51977: CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory in Brother Industries, Ltd HL-L8260CDNCVE-2024-51977 0 An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631), can leak several pieces of sensitive information from a vulnerable device. The URI path /etc/mnt_info.csv can be accessed via a GET request and no authentication is required. The returned result is a comma separated value (CSV) table of information. The leaked information includes the device’s model, firmware version, IP address, and serial number. Join the discussion | CVE Database V5 | 06/25/2025, 07:15:16 UTC Added: 03/30/2026, 16:23:20 UTC |
CVE-2025-36051: CWE-538 Insertion of sensitive information into Externally-Accessible file or directory in IBM QRadar SIEMCVE-2025-36051 0 IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files that could be read by a local user. Join the discussion | CVE Database V5 | 03/19/2026, 01:55:44 UTC Added: 03/19/2026, 02:24:20 UTC |
CVE-2026-21672: CWE-538 File and Directory Information Exposure in Veeam Backup and ReplicationCVE-2026-21672 0 A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers. Join the discussion | CVE Database V5 | 03/12/2026, 16:26:52 UTC Added: 03/12/2026, 17:44:48 UTC |
CVE-2026-2817: CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory in VMware Spring Data GeodeCVE-2026-2817 0 Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directories under the system temp location. On shared hosts, a local user with basic privileges can access another user’s extracted snapshot contents, leading to unintended exposure of cache data. Join the discussion | CVE Database V5 | 02/19/2026, 17:18:09 UTC Added: 02/19/2026, 18:47:13 UTC |
Showing 1 to 10 of 20 results