CWE-522
1,467 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,467)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wavlink 3Wn530hg4 Firmware Wn531g3 FirmwareWn572hg3 FirmwareJun 17, 2026 May 7, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered where a page is exposed that has the current administrator password in cleartext in the source code of the page. No authentication is required in order to reach the page (a certain live_?.shtml pa...Show more |
1Blaauwproducts 1Remote Kiln Control Jun 17, 2026 May 7, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /lang/nl.bak, or /lang/en.bak. |
Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a `$` character in some circumstances. |
Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps. |
BMC Control-M/Agent 7.0.00.000 has Insecure Password Storage. |
In Rukovoditel 2.5.2, users' passwords and usernames are stored in a cookie with URL encoding, base64 encoding, and hashing. Thus, an attacker can easily apply brute force on them. |
In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials. |
IBM UrbanCode Deploy (UCD) 7.0.4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 171250. |
2Abb Busch Jaeger26186/11 Firmware Tg/s3.2 FirmwareJun 17, 2026 Apr 22, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The backup function in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway saves the current settings and configuration of the application, including credentials of existing user accounts and other co...Show more |
1Netgear 18D6220 Firmware D6400 FirmwareD8500 Firmware+15 moreNov 21, 2024 Apr 22, 2020 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 Certain NETGEAR devices are affected by administrative password disclosure. This affects D6220 before V1.0.0.28, D6400 before V1.0.0.60, D8500 before V1.0.3.29, DGN2200v4 before 1.0.0.82, DGN2200Bv4 before 1.0.0.82, R630...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraGit+1 moreJun 17, 2026 Apr 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that b...Show more |
1Netgear 2R6700 Firmware R6800 FirmwareNov 21, 2024 Apr 20, 2020 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38 and R6800 before 1.1.0.38. |
1Netgear 3D7000 Firmware R6700 FirmwareR6800 FirmwareNov 21, 2024 Apr 20, 2020 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, and D7000 before 1.0.1.50. |
1Netgear 3D7000 Firmware R6700 FirmwareR6800 FirmwareNov 21, 2024 Apr 20, 2020 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, and D7000 before 1.0.1.50. |
1Microfocus 2Enterprise Developer Enterprise ServerJun 17, 2026 Apr 17, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patch Update 16, and version 5.0 Patch Update 6. The vulnerability could al...Show more |
MikroTik WinBox 3.22 and below stores the user's cleartext password in the settings.cfg.viw configuration file when the Keep Password field is set and no Master Password is set. Keep Password is set by default and, by de...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraGit+3 moreJun 17, 2026 Apr 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git uses external "credential helper" programs to store and retrieve password...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Apr 14, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclosure. It involves social engineering in order to gain access to system a...Show more |
In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3. |
1Vmware 1Tanzu Application Service For Vms Jun 17, 2026 Apr 10, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x versions prior to 2.8.5, includes a version of PCF Autoscaling that writes database connection propertie...Show more |