VYPR

CWE-548

Exposure of Information Through Directory Listing

VariantDraft

Description

The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (57)

page 2 of 3
  • CVE-2024-45096MedSep 5, 2024
    risk 0.42cvss 6.5epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user with access to the package to obtain sensitive information through a directory listing.

  • CVE-2024-42007MedJul 26, 2024
    risk 0.38cvss 5.8epss 0.01

    SPX (aka php-spx) through 0.4.15 allows SPX_UI_URI Directory Traversal to read arbitrary files.

  • CVE-2024-2340MedApr 9, 2024
    risk 0.37cvss 5.3epss 0.28

    The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '/wp-content/uploads/fusion-forms/' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via an Avada…

  • CVE-2022-30625MedJul 18, 2022
    risk 0.37cvss 5.7epss 0.00

    Directory listing is a web server function that displays the directory contents when there is no index file in a specific website directory. A directory listing provides an attacker with the complete index of all the resources located inside of the directory. The specific risks…

  • CVE-2025-61685MedOct 3, 2025
    risk 0.35cvss 6.5epss 0.01

    Mastra is a Typescript framework for building AI agents and assistants. Versions 0.13.8 through 0.13.20-alpha.0 are vulnerable to a Directory Traversal attack that results in the disclosure of directory listings. The code contains a security check to prevent path traversal for…

  • CVE-2025-4807MedMay 16, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, was found in SourceCodester Online Student Clearance System 1.0. This affects an unknown part. The manipulation leads to exposure of information through directory listing. It is possible to initiate the attack remotely. The…

  • CVE-2025-2652MedMar 23, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to exposure of information through directory listing. The attack…

  • CVE-2025-2651MedMar 23, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /oews/admin/. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack…

  • CVE-2024-8711MedSep 12, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in SourceCodester Food Ordering Management System 1.0. Affected by this issue is some unknown functionality of the file /includes/. The manipulation leads to exposure of information through directory listing.…

  • CVE-2024-7912MedAug 18, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in CodeAstro Online Railway Reservation System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/assets/. The manipulation leads to exposure of information through directory listing. The attack can be…

  • CVE-2024-7809MedAug 15, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /tracking/nbproject/. The manipulation leads to exposure of information through directory…

  • CVE-2022-36243MedMay 30, 2023
    risk 0.35cvss 5.3epss 0.01

    Shop Beat Solutions (pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Directory Traversal via server.shopbeat.co.za. Information Exposure Through Directory Listing vulnerability in "studio" software of Shop Beat. This issue affects: Shop Beat studio studio…

  • CVE-2021-23195MedJan 21, 2022
    risk 0.35cvss 5.3epss 0.01

    Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 has the option for automated indexing (directory listing) activated. When accessing a directory, a web server delivers its entire content in HTML form. If an index file does not exist and directory…

  • CVE-2021-32515MedJul 7, 2021
    risk 0.35cvss 5.3epss 0.01

    Directory listing vulnerability in share_link in QSAN Storage Manager allows attackers to list arbitrary directories and further access credential information. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

  • CVE-2020-15790MedSep 9, 2020
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). If configured in an insecure manner, the web server might be susceptible to a directory listing attack.

  • CVE-2026-50233MedJun 5, 2026
    risk 0.34cvss 5.3epss 0.00

    Lyrion Music Server 9.2.0 contains an arbitrary directory listing vulnerability in its readdirectory query, exposed through both the CLI service (TCP port 9090) and the HTTP JSON-RPC endpoint (/jsonrpc.js). The query accepts a folder parameter and lists its contents with no…

  • CVE-2023-38265MedFeb 17, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could disclose folder location information to an unauthenticated attacker that could aid in further attacks against the system.

  • CVE-2025-13200MedNov 15, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was determined in SourceCodester Farm Management System 1.0. Affected by this vulnerability is an unknown functionality. This manipulation causes exposure of information through directory listing. The attack is possible to be carried out remotely. The exploit has…

  • CVE-2025-27906MedOct 14, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL. Application files and folders are visible in the browser to a user; however, the contents of the files cannot be read obtained or modified.

  • CVE-2025-27452MedJul 3, 2025
    risk 0.34cvss 5.3epss 0.00

    The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure. There are modules activated that are not required for the operation of the FNADE4 web application. The functionality of the some modules pose a risk to the…