CWE-522
1,396 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,396)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Dingtian Tech 1Dt R002 Firmware Jun 17, 2026 Sep 25, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to extract the proprietary "Dingtian Binary" protocol password by sending an unauthent...Show more |
1Dingtian Tech 1Dt R002 Firmware Jun 17, 2026 Sep 25, 2025 8.7 HIGH· v4 5.3 MEDIUM· v3 N/A· v2 All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to retrieve the current user's username without authentication. |
1Ericsson 1Indoor Connect 8855 Firmware Jun 17, 2026 Sep 25, 2025 5.1 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in the client which if exploited can lead to unauthorized disclosure of certain information. |
In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant database was not excluded from the files gathered by Puppet backup. The key is only present on the...Show more |
When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation the password will appear in the NeuVector security event log. |
The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to a privileged account . A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of pr...Show more |
When a user logs in via SAP Business One native client, the SLD backend service fails to enforce proper encryption of certain APIs. This leads to exposure of sensitive credentials within http response body. As a result,...Show more |
An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufacturer password. |
Onyxia is a data science environment for kubernetes. In versions 4.6.0 through 4.8.0, Onyxia-API leaked the credentials of private helm repositories in the public (unauthenticated) /public/catalogs endpoint.vOnly instanc...Show more |
api is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions lower than 15.0.13, 16.0.2 through 16.0.14, 17.0.1 and 17.0.2, there is an identical OAuth private key used...Show more |
Local Deep Research is an AI-powered research assistant for deep, iterative research. Versions 0.2.0 through 0.6.7 stored confidential information, including API keys, in a local SQLite database without encryption. This...Show more |
1Copeland 1E3 Supervisory Controller Firmware Jun 17, 2026 Sep 2, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably generate the password for ONEDAY. The oneday user cannot be deleted or modifi...Show more |
1Copeland 1E3 Supervisory Controller Firmware Jun 17, 2026 Sep 2, 2025 9.2 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can generate the root linux password for a vulnerable device based on known or easy to fetch parameters. |
1Copeland 1E3 Supervisory Controller Firmware Jun 17, 2026 Sep 2, 2025 7.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, which returns all usernames and password hashes for the application services. |
An issue in PDQ Smart Deploy V.3.0.2040 allows an attacker to escalate privileges via the Credential encryption routines in SDCommon.dll |
GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX FX backend where API keys and authentication tokens may be exposed if environment variables are misco...Show more |
1Santesoft 1Sante Pacs Server Jun 17, 2026 Aug 18, 2025 9.1 CRITICAL· v4 7.5 HIGH· v3 N/A· v2 The Sante PACS Server Web Portal sends credential information without encryption. |
1Siemens 1Simatic Rtls Locating Manager Jun 17, 2026 Aug 12, 2025 4.8 MEDIUM· v4 7.8 HIGH· v3 N/A· v2 A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected SIMATIC RTLS Locating Manager Report Clients do not properly protect credentials that are used to authenticate to the s...Show more |
BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could observe these credentials and use them to log in to the database server...Show more |
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credentials for requests to remote Excel resources. |