Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Logo Software Industry
ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate
A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution
JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kube
ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database
Across DR-810 contains an unauthenticated file disclosure vulnerability that allows remote attackers to download the rom
WordPress Plugin Backup Migration 1.2.8 contains an information disclosure vulnerability that allows unauthenticated att
A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorizat
IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files th
Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An atta
IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005
The ZOLL ePCR IOS application reflects unsanitized user input into a WebView. Attacker-controlled strings placed into PC
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could
Chamilo LMS is a learning management system. Prior to 1.11.38, Twig template files (.tpl) under /main/template/default/
A vulnerability was found in code-projects Simple ChatBox 1.0. Affected by this issue is the function SimpleChatbox_PHP
A security vulnerability has been detected in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unkn
A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the fil
IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensiti
A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functiona
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
During WiFi association, Naxclow device firmware prints the host network’s SSID, PSK, and negotiated WPA keys in clearte
Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directorie
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows
HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or
Tandoor Recipes is a recipe manager than can be installed with the Nix package manager. Starting in version 23.05 and pr
A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.2
Frequently Asked Questions
What is CWE-538?
CWE-538 (CWE-538) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-538?
There are 29 CVE records associated with CWE-538 in our database. Of these, 2 are critical severity, 7 are high severity, and 15 are medium severity.
How can I protect against CWE-538 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-538 using AI-powered security agents.
Detect CWE-538 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-538 vulnerabilities across your infrastructure.
Get Started