Threats Tagged 'cwe-548'
View all threats tagged with 'cwe-548'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-548'
Click on any threat for detailed analysis and mitigation recommendations
0 Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. Join the discussion | CVE Database V5 | 05/20/2026, 14:30:23 UTC Added: 05/20/2026, 15:34:07 UTC |
0 IBM QRadar SIEM 7.5 - 7.5.0 UP14 IF01 is affected by an information disclosure vulnerability involving exposure of directory information. IBM has addressed this vulnerability in the latest update. Join the discussion | CVE Database V5 | 12/09/2025, 13:26:15 UTC Added: 12/09/2025, 13:46:27 UTC |
0 IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL. Application files and folders are visible in the browser to a user; however, the contents of the files cannot be read obtained or modified. Join the discussion | CVE Database V5 | 10/14/2025, 14:08:42 UTC Added: 10/14/2025, 14:52:08 UTC |
0 Mastra is a Typescript framework for building AI agents and assistants. Versions 0.13.8 through 0.13.20-alpha.0 are vulnerable to a Directory Traversal attack that results in the disclosure of directory listings. The code contains a security check to prevent path traversal for reading file contents, but this check is effectively bypassed by subsequent logic that attempts to find directory suggestions. An attacker can leverage this flaw to list the contents of arbitrary directories on the user's filesystem, including the user's home directory, exposing sensitive information about the file system's structure. This issue is fixed in version 0.13.20. Join the discussion | CVE Database V5 | 10/03/2025, 22:37:09 UTC Added: 10/04/2025, 00:10:10 UTC |
0 IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 could disclose sensitive installation directory information to an authenticated user that could be used in further attacks against the system. Join the discussion | CVE Database V5 | 07/08/2025, 15:01:52 UTC Added: 07/08/2025, 15:09:29 UTC |
0 The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure. There are modules activated that are not required for the operation of the FNADE4 web application. The functionality of the some modules pose a risk to the webserver which enable dircetory listing. Join the discussion | CVE Database V5 | 07/03/2025, 11:29:04 UTC Added: 07/03/2025, 11:39:31 UTC |
The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '/wp-content/uploads/fusion-forms/' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via an Avada created form with a file upload mechanism. Join the discussion | CVE Database V5 | 04/09/2024, 18:59:06 UTC Added: 02/25/2026, 21:46:21 UTC |
Showing 1 to 7 of 7 results