Cyber Posture

CWE · MITRE source

CWE-548Exposure of Information Through Directory Listing

Abstraction: Variant · CVEs in our corpus: 54

The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (3)AI

Control Title Family Why it addresses this CWE
SC-30Concealment and MisdirectionSCDirectory listings and resource enumeration can be suppressed or populated with misleading entries.
SC-38Operations SecuritySCReduces exposure via directory listings or accessible files when OPSEC restricts visibility of key organizational resources.
AU-13Monitoring for Information DisclosureAUDetects information exposure through directory listings as unauthorized disclosure.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2024-23404.65.30.58182024-04-09
CVE-2020-81611.88.60.00912020-07-02
CVE-2018-147851.67.50.01512018-08-10
CVE-2020-150811.65.30.09692020-07-02
CVE-2017-60451.57.50.00522017-06-21
CVE-2018-105901.57.50.00432018-05-15
CVE-2018-164931.57.50.00612019-02-01
CVE-2019-54151.57.50.00322019-03-21
CVE-2021-215281.57.50.00272021-11-12
CVE-2021-275051.57.50.00212022-05-13
CVE-2023-519481.57.50.00182024-01-19
CVE-2024-220821.57.50.00242024-03-20
CVE-2023-499791.57.50.00572024-03-21
CVE-2025-20381.57.30.00072025-03-06
CVE-2025-49091.57.30.00312025-05-19
CVE-2025-281701.57.60.00132025-07-29
CVE-2021-477181.57.50.00272025-12-09
CVE-2022-507881.57.50.00632025-12-30
CVE-2020-369211.57.50.00302026-01-06
CVE-2026-228601.57.50.00102026-02-18
CVE-2020-78581.46.80.00422021-04-22
CVE-2024-450961.36.50.00142024-09-05
CVE-2025-616851.36.50.00522025-10-03
CVE-2024-420071.25.80.00742024-07-26
CVE-2025-48071.25.30.01592025-05-16