CWE-548Variant

Exposure of Information Through Directory Listing

Draft in the CWE catalog · 52 CVEs mapped

52
CVEs mapped
5.5
Median CVSS
What it is

The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.

Recent examples
5.3cvss
CVE-2026-19987

CVE-2026-19987 - MEDIUM Severity Vulnerability

A security vulnerability has been detected in SourceCodester Best Employee Management System 1.0. This affects an unknown function of the file /assets/uploadImage/Profile/. Such manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely.

MEDIUMno explanation yet
0%
epss
6.9cvss
CVE-2026-50233

Lyrion Music Server 9.2.0 Arbitrary Directory Listing

Lyrion Music Server 9.2.0 contains an arbitrary directory listing vulnerability in its readdirectory query, exposed through both the CLI service (TCP port 9090) and the HTTP JSON-RPC endpoint (/jsonrpc.js). The query accepts a folder parameter and lists its contents with no restriction to the configured media directories and no authentication in the default configuration, allowing a remote, unauthenticated attacker to enumerate arbitrary locations on the host filesystem.

MEDIUMno explanation yet
0%
epss
7.5cvss
CVE-2025-32750

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-548
Abstraction
Variant
Structure
Simple
Status
Draft
References (2)