The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.
Volume of CVEs assigned to CWE-538 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
92 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-51977MEDIUM An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631), can leak several pieces of se | Jun 25, 2025 | 5.3 | 80 | NO | YES |
CVE-2026-27173HIGH JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only acce | May 19, 2026 | 8.7 | 37 | NO | NO |
CVE-2019-15793HIGH In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, several locations which shift ids translate user/group ids before performing | Apr 24, 2020 | 8.8 | 36 | NO | YES |
CVE-2026-15574HIGH A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorization headers and full chat payloads, which may contain person | Jul 13, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-49298HIGH A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line ar | Jun 1, 2026 | 8.8 | 33 | NO | NO |
CVE-2016-20024CRITICAL ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate privileges by modifying executable files. Attackers can exp | Mar 16, 2026 | 9.8 | 33 | NO | NO |
CVE-2019-6851HIGH A CWE-538: File and Directory Information Exposure vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause | Oct 29, 2019 | 7.5 | 32 | NO | NO |
CVE-2026-46617HIGH Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, Fission runti | Jun 10, 2026 | 8.7 | 31 | NO | NO |
CVE-2025-12059CRITICAL Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Logo Software Industry and Trade Inc. Logo j-Platform allows Exploiting Incorrectly | Feb 11, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-23838HIGH Tandoor Recipes is a recipe manager than can be installed with the Nix package manager. Starting in version 23.05 and prior to version 26.05, when using the default configuration o | Jan 19, 2026 | 8.7 | 31 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.