CWE-538: CWE-538

23
Total CVEs
1
Critical
8
High
6.5
Avg CVSS

Yearly Trend

2026
4
2025
12
2024
4
2023
3

Top Affected Vendors

1 Dell 2
2 Google 1
3 Gitlab 1
4 Fedoraproject 1
5 Ibm 1
6 Redhat 1
7 Siemens 1
8 Jetbrains 1
9 Qlik 1
10 R1bbit 1

All CWE-538 CVEs (23)

CVE-2025-12059
9.8

This vulnerability allows attackers to insert sensitive information into externally accessible files or directories in Logo j-Platform due to incorrec...

Feb 11, 2026
CVE-2023-46723
8.9

This vulnerability in lte-pic32-writer exposes sensitive API keys and webhook URLs stored in the sendto.txt file to attackers who know the device's IM...

Oct 31, 2023
CVE-2024-22433
8.8

Dell Data Protection Search versions 19.2.0 and above expose LDAP passwords in plain text through the LdapSettings.get_ldap_info function. This allows...

Feb 6, 2024
CVE-2022-4318
7.8

This vulnerability in cri-o allows attackers to inject arbitrary lines into the /etc/passwd file using a specially crafted environment variable. This ...

Sep 25, 2023
CVE-2024-22045
7.6

SINEMA Remote Connect Client versions before V3.1 SP1 expose sensitive information through accessible files and the web interface. This allows authent...

Mar 12, 2024
CVE-2020-37104
7.5

CVE-2020-37104 allows unauthenticated attackers to download database backup files from ASTPP VoIP billing software by brute-forcing predictable 6-digi...

Feb 11, 2026
CVE-2025-61138
7.5

Qlik Sense Enterprise v14.212.13 contains an information leak vulnerability via the /dev-hub/ directory that exposes sensitive data. This affects orga...

Nov 20, 2025
CVE-2023-4595
7.5

This CVE describes an information exposure vulnerability in BVRP Software SLmail where remote attackers can retrieve sensitive server files by appendi...

Nov 23, 2023
CVE-2024-31954
7.3

This vulnerability in Samsung Portable SSD T5 installer allows attackers with existing user access to escalate privileges through arbitrary code execu...

May 14, 2024
CVE-2024-47580
6.8

This vulnerability allows authenticated administrators to exploit an exposed webservice to create PDFs with embedded attachments. By specifying intern...

Dec 10, 2024
CVE-2025-0194
6.5

This vulnerability in GitLab CE/EE could expose access tokens in application logs under specific API request conditions. Attackers who gain access to ...

Jan 8, 2025
CVE-2025-24689
5.9

The Import and export users and customers WordPress plugin versions up to 1.27.12 contains a vulnerability where sensitive information can be inserted...

Jan 27, 2025
CVE-2025-31558
5.8

This vulnerability in the TailPress WordPress plugin allows attackers to retrieve embedded sensitive data by accessing externally-accessible files. It...

Apr 3, 2025
CVE-2025-31550
5.8

This vulnerability in the WP-LESS WordPress plugin allows attackers to retrieve sensitive data embedded in CSS files. It affects WordPress sites using...

Apr 1, 2025
CVE-2025-36058
5.5

This vulnerability in IBM Business Automation Workflow containers allows attackers to access sensitive configuration information stored in config maps...

Jan 20, 2026
CVE-2025-20665
5.5

This CVE describes an information disclosure vulnerability in devinfo on MediaTek devices where missing SELinux policies allow unauthorized access to ...

May 5, 2025
CVE-2025-11891
5.3

The Shelf Planner WordPress plugin exposes sensitive information through publicly accessible log files in versions up to 2.7.0. Unauthenticated attack...

Nov 11, 2025
CVE-2025-46602
4.4

Dell SupportAssist OS Recovery versions before 5.5.15.0 can expose sensitive information to local low-privileged attackers through file/directory acce...

Oct 27, 2025
CVE-2025-57734
4.3

This vulnerability exposes AWS credentials in Docker script files within JetBrains TeamCity CI/CD servers. Attackers who gain access to these files co...

Aug 20, 2025
CVE-2025-8452
4.3

This vulnerability allows attackers on the local network to discover Brother multi-function printer serial numbers via the eSCL/uscan protocol. The se...

Aug 12, 2025
CVE-2025-25586
4.2

This vulnerability allows unauthenticated attackers to access sensitive configuration information in yimioa software versions before v2024.07.04. The ...

Mar 18, 2025
CVE-2026-23838
N/A

Tandoor Recipes' default NixOS configuration exposes the SQLite database file externally when using SQLite with default MEDIA_ROOT settings. This allo...

Jan 19, 2026
CVE-2021-4471
N/A

TG8 Firewall exposes the /data/ directory via HTTP without authentication, allowing remote attackers to download credential files containing usernames...

Nov 14, 2025

About CWE-538 (CWE-538)

Our database tracks 23 CVEs classified as CWE-538, with 1 rated critical and 8 rated high severity. The average CVSS score for CWE-538 vulnerabilities is 6.5.

External reference: View CWE-538 on MITRE CWE →

Monitor CWE-538 Vulnerabilities

Get alerted when new CWE-538 CVEs affect your infrastructure.

Start Monitoring Free