A backup file is stored in a directory or archive that is made accessible to unauthorized actors.
Volume of CVEs assigned to CWE-530 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-56462HIGH IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive that could be restored and used to gain access to the underly | May 27, 2026 | 8.8 | 29 | NO | NO |
CVE-2020-36899HIGH QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive files through unverified 'filename | Dec 10, 2025 | 7.5 | 24 | NO | NO |
CVE-2024-12330HIGH The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin | Jan 9, 2025 | 7.5 | 22 | NO | NO |
CVE-2023-5297HIGH A vulnerability was found in Xinhu RockOA 2.3.2. It has been classified as problematic. This affects the function start of the file task.php?m=sys|runt&a=beifen. The manipulation l | Sep 29, 2023 | 7.5 | 22 | NO | NO |
A weakness has been identified in Chess Play and Learn App up to 4.9.42 on Android. This issue affects some unknown processing of the file AndroidManifest.xml of the component com. | Jun 29, 2026 | 2.4 | 21 | NO | NO |
CVE-2025-3773MEDIUM A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to extract sensitive information s | Jun 26, 2025 | 5.5 | 17 | NO | NO |
CVE-2024-2364MEDIUM A vulnerability classified as problematic has been found in Musicshelf 1.0/1.1 on Android. Affected is an unknown function of the file androidmanifest.xml of the component Backup H | Mar 10, 2024 | 4.6 | 15 | NO | NO |
A vulnerability was identified in AliasVault App up to 0.25.3 on Android/iOS. This vulnerability affects unknown code of the file shared_prefs/aliasvault.xml of the component Backu | Feb 23, 2026 | 2.5 | 14 | NO | NO |
A vulnerability classified as problematic has been found in fridgecow smartalarm 1.8.1 on Android. This affects an unknown part of the file androidmanifest.xml of the component Bac | Apr 1, 2024 | 2.4 | 14 | NO | NO |
A vulnerability was found in QKSMS up to 3.9.4 on Android. It has been classified as problematic. This affects an unknown part of the file androidmanifest.xml of the component Back | Apr 7, 2024 | 2.4 | 13 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.