CWE-548: Exposure of Information Through Directory Listing
The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.
51 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-4909 — SourceCodester Client Database Management System exposure of information through directory listing
- CVE-2025-2038 — code-projects Blood Bank Management System upload exposure of information through directory listing
- CVE-2025-4807 — SourceCodester Online Student Clearance System exposure of information through directory listing
- CVE-2025-2652 — SourceCodester Employee and Visitor Gate Pass Logging System exposure of information through directory listing
- CVE-2025-2651 — SourceCodester Online Eyewear Shop admin exposure of information through directory listing
- CVE-2025-13200 — SourceCodester Farm Management System exposure of information through directory listing
- CVE-2025-61685 — Mastra Docs MCP Server `@mastra/mcp-docs-server` Leads to Information Exposure
- CVE-2026-22860 — Rack has a Directory Traversal via Rack:Directory
- CVE-2025-32750 — Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerabilit
- CVE-2026-50233 — Lyrion Music Server 9.2.0 Arbitrary Directory Listing
- CVE-2026-41933 — Vvveb < 1.0.8.3 Directory Listing Information Disclosure
- CVE-2026-19987 — SourceCodester Best Employee Management System Profile exposure of information through directory listing
- CVE-2025-27906 — IBM Content Navigator information disclosure
- CVE-2025-27452 — CVE-2025-27452
- CVE-2025-2827 — IBM Sterling File Gateway information disclosure
- CVE-2025-1138 — IBM Information Server information disclosure
- CVE-2025-23378 — Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information through directory listing
- CVE-2024-56464 — IBM QRadar SIEM is affected by an information disclosure vulnerability
- CVE-2024-28766 — IBM Security Directory Integrator information disclosure
Recently published
- CVE-2026-19987 — SourceCodester Best Employee Management System Profile exposure of information through directory listing
- CVE-2026-50233 — Lyrion Music Server 9.2.0 Arbitrary Directory Listing
- CVE-2025-32750 — Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerabilit
- CVE-2026-41933 — Vvveb < 1.0.8.3 Directory Listing Information Disclosure
- CVE-2026-22860 — Rack has a Directory Traversal via Rack:Directory
- CVE-2024-56464 — IBM QRadar SIEM is affected by an information disclosure vulnerability
- CVE-2025-13200 — SourceCodester Farm Management System exposure of information through directory listing
- CVE-2025-27906 — IBM Content Navigator information disclosure
- CVE-2025-61685 — Mastra Docs MCP Server `@mastra/mcp-docs-server` Leads to Information Exposure
- CVE-2025-2827 — IBM Sterling File Gateway information disclosure
- CVE-2025-27452 — CVE-2025-27452
- CVE-2025-4909 — SourceCodester Client Database Management System exposure of information through directory listing
- CVE-2025-4807 — SourceCodester Online Student Clearance System exposure of information through directory listing
- CVE-2025-1138 — IBM Information Server information disclosure
- CVE-2025-23378 — Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information through directory listing
- CVE-2025-2652 — SourceCodester Employee and Visitor Gate Pass Logging System exposure of information through directory listing
- CVE-2025-2651 — SourceCodester Online Eyewear Shop admin exposure of information through directory listing
- CVE-2025-2038 — code-projects Blood Bank Management System upload exposure of information through directory listing
- CVE-2024-28766 — IBM Security Directory Integrator information disclosure