The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.
Volume of CVEs assigned to CWE-548 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
57 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2340MEDIUM The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '/wp-content/uploads/fusion-forms/' directory. Th | Apr 9, 2024 | 5.3 | 38 | NO | YES |
CVE-2025-32750HIGH Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could pote | May 20, 2026 | 7.5 | 31 | NO | NO |
CVE-2020-8161HIGH A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack wh | Jul 2, 2020 | 8.6 | 29 | NO | NO |
CVE-2026-22860HIGH Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match on the expanded path. A request | Feb 18, 2026 | 7.5 | 28 | NO | NO |
CVE-2025-28170HIGH Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing unauthorized access to sensiti | Jul 29, 2025 | 7.6 | 28 | NO | NO |
CVE-2020-7858HIGH There is a directory traversing vulnerability in the download page url of AquaNPlayer 2.0.0.92. The IP of the download page url is localhost and an attacker can traverse directorie | Apr 22, 2021 | 8.6 | 26 | NO | NO |
CVE-2022-50788HIGH SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly bro | Dec 30, 2025 | 7.5 | 25 | NO | NO |
CVE-2016-15019HIGH A vulnerability was found in tombh jekbox. It has been rated as problematic. This issue affects some unknown processing of the file lib/server.rb. The manipulation leads to exposur | Jan 15, 2023 | 7.5 | 25 | NO | NO |
CVE-2021-45446HIGH A vulnerability in
Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and
8.3.0.25 does not cascade the hidden property to the children of the Home folder | Nov 2, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-27505HIGH mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive directory listing information. | May 13, 2022 | 7.5 | 25 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.