CWE-522
1,396 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,396)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Jenkins 1Data Theorem Mobile App Security Jun 17, 2026 Sep 25, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins Data Theorem: CI/CD Plugin 1.3 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master f...Show more |
1Netapp 1Ontap Select Deploy Administration Utility Jun 17, 2026 Sep 24, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext. |
An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a...Show more |
1Supermicro 321A1sa2 2750f Firmware A1sai 2550f FirmwareA1sai 2750f Firmware+318 moreJun 17, 2026 Sep 21, 2019 N/A· v4 10.0 CRITICAL· v3 5.0 MEDIUM· v2 On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devic...Show more |
1Microfocus 1Service Manager Jun 17, 2026 Sep 18, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Clear text password in browser in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive d...Show more |
1Microfocus 1Service Manager Jun 17, 2026 Sep 18, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could...Show more |
VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability where Virtual Machines deployed from an OVF could expose login information via...Show more |
1Schneider Electric 4Ap9630 Firmware Ap9631 FirmwareAp9635 Firmware+1 moreJun 17, 2026 Sep 17, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A Credentials Management CWE-255 vulnerability exists in the APC UPS Network Management Card 2 AOS v6.5.6, which could cause Remote Monitoring Credentials to be viewed in plaintext when Remote Monitoring is enabled, and...Show more |
Jenkins Beaker Builder Plugin 1.9 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system. |
An issue was discovered in TeamViewer 14.2.2558. Updating the product as a non-administrative user requires entering administrative credentials into the GUI. Subsequently, these credentials are processed in Teamviewer.ex...Show more |
In Knowage through 6.1.1, an authenticated user that accesses the users page will obtain all user password hashes. |
In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which includes databases. |
Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database. |
1Zebra 8220xi4 Firmware Zt220 FirmwareZt230 Firmware+5 moreJun 17, 2026 Aug 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a passcode to limit the functionality of the front panel is applied, speci...Show more |
1Dell 6Emc Powerconnect 7000 Firmware Emc Powerconnect 8024 FirmwareEmc Powerconnect M6220 Firmware+3 moreJun 17, 2026 Aug 20, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the...Show more |
The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subsequent hosts that the...Show more |
Jenkins eggPlant Plugin 2.2 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. |
1Google 1Cloud Messaging Notification Jun 17, 2026 Aug 7, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins Google Cloud Messaging Notification Plugin 1.0 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file sy...Show more |
Jenkins TestLink Plugin 3.16 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. |
1Microdigital 3Mdc N2190v Firmware Mdc N4090 FirmwareMdc N4090w FirmwareJun 17, 2026 Aug 6, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The file in question is /usr/local/ipsca/mipsca.db. If a camera is compromised, the attacker can gain a...Show more |