The product stores sensitive data under the web document root with insufficient access control, which might make it accessible to untrusted parties.
Volume of CVEs assigned to CWE-219 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-56159MEDIUM Astro is a web framework for content-driven websites. A bug in the build process allows any unauthenticated user to read parts of the server source code. During build, along with c | Dec 19, 2024 | 5.3 | 26 | NO | YES |
CVE-2022-21236HIGH An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a disc | Jan 28, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-36306MEDIUM An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web server binary, and the web server configur | Aug 16, 2022 | 6.5 | 23 | NO | NO |
CVE-2024-39776HIGH Avtec Outpost stores sensitive information in an insecure location without proper access controls in place. | Aug 22, 2024 | 7.5 | 22 | NO | NO |
CVE-2002-2024MEDIUM Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reason=chpass2, (3) spelling.php3, and (4) ld | Dec 31, 2002 | 5.3 | 22 | NO | NO |
CVE-2023-39467MEDIUM Triangle MicroWorks SCADA Data Gateway certificate Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected in | May 3, 2024 | 5.3 | 16 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.