← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dingtian Tech
1Dt R002 Firmware
Jun 17, 2026
Sep 25, 2025
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to extract the proprietary "Dingtian Binary" protocol password by sending an unauthent...Show more
All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to extract the proprietary "Dingtian Binary" protocol password by sending an unauthenticated GET request.Show less
1Dingtian Tech
1Dt R002 Firmware
Jun 17, 2026
Sep 25, 2025
8.7 HIGH· v4
5.3 MEDIUM· v3
N/A· v2
All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to retrieve the current user's username without authentication.
1Ericsson
1Indoor Connect 8855 Firmware
Jun 17, 2026
Sep 25, 2025
5.1 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in the client which if exploited can lead to unauthorized disclosure of certain information.
-
-
Jun 17, 2026
Sep 24, 2025
6.9 MEDIUM· v4
N/A· v3
N/A· v2
In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant database was not excluded from the files gathered by Puppet backup. The key is only present on the...Show more
In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant database was not excluded from the files gathered by Puppet backup. The key is only present on the system if the user has a Puppet Enterprise Advanced license and has enabled the Infra Assistant feature. The key is used for encrypting one particular bit of data in the Infra Assistant database: the API key for their AI provider account. This has been fixed in Puppet Enterprise version 2025.6, and release notes for 2025.6 have remediation steps for users of affected versions who can't update to the latest version.Show less
-
-
Jun 17, 2026
Sep 17, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation the password will appear in the NeuVector security event log.
1Nvidia
1Nvdebug
Jun 17, 2026
Sep 9, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to a privileged account . A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of pr...Show more
The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to a privileged account . A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure and data tampering.Show less
-
-
Jun 17, 2026
Sep 9, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
When a user logs in via SAP Business One native client, the SLD backend service fails to enforce proper encryption of certain APIs. This leads to exposure of sensitive credentials within http response body. As a result,...Show more
When a user logs in via SAP Business One native client, the SLD backend service fails to enforce proper encryption of certain APIs. This leads to exposure of sensitive credentials within http response body. As a result, it has a high impact on the confidentiality, integrity, and availability of the application.Show less
-
-
Jun 17, 2026
Sep 8, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufacturer password.
-
-
Jun 17, 2026
Sep 5, 2025
9.4 CRITICAL· v4
N/A· v3
N/A· v2
Onyxia is a data science environment for kubernetes. In versions 4.6.0 through 4.8.0, Onyxia-API leaked the credentials of private helm repositories in the public (unauthenticated) /public/catalogs endpoint.vOnly instanc...Show more
Onyxia is a data science environment for kubernetes. In versions 4.6.0 through 4.8.0, Onyxia-API leaked the credentials of private helm repositories in the public (unauthenticated) /public/catalogs endpoint.vOnly instances using private helm repositories (i.e setting username & password in the catalogs configuration) are affected. This is fixed in version 4.9.0.Show less
-
-
Jun 17, 2026
Sep 5, 2025
5.1 MEDIUM· v4
N/A· v3
N/A· v2
api is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions lower than 15.0.13, 16.0.2 through 16.0.14, 17.0.1 and 17.0.2, there is an identical OAuth private key used...Show more
api is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions lower than 15.0.13, 16.0.2 through 16.0.14, 17.0.1 and 17.0.2, there is an identical OAuth private key used across multiple systems that installed the same FreePBX RPM or DEB package. An attacker with access to the shared OAuth private key could forge JWT tokens, bypass authentication, and potentially gain full access to both REST and GraphQL APIs. Systems with the "api" module enabled, configured and previously activated by an administrator for remote inbound connections may be affected. This issue is fixed in versions 15.0.13, 16.0.15 and 17.0.3.Show less
-
-
Jun 17, 2026
Sep 3, 2025
6.9 MEDIUM· v4
N/A· v3
N/A· v2
Local Deep Research is an AI-powered research assistant for deep, iterative research. Versions 0.2.0 through 0.6.7 stored confidential information, including API keys, in a local SQLite database without encryption. This...Show more
Local Deep Research is an AI-powered research assistant for deep, iterative research. Versions 0.2.0 through 0.6.7 stored confidential information, including API keys, in a local SQLite database without encryption. This behavior was not clearly documented outside of the database architecture page. Users were not given the ability to configure the database location, allowing anyone with access to the container or host filesystem to retrieve sensitive data in plaintext by accessing the .db file. This is fixed in version 1.0.0.Show less
1Copeland
1E3 Supervisory Controller Firmware
Jun 17, 2026
Sep 2, 2025
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably generate the password for ONEDAY. The oneday user cannot be deleted or modifi...Show more
E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably generate the password for ONEDAY. The oneday user cannot be deleted or modified by any user.Show less
1Copeland
1E3 Supervisory Controller Firmware
Jun 17, 2026
Sep 2, 2025
9.2 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can generate the root linux password for a vulnerable device based on known or easy to fetch parameters.
1Copeland
1E3 Supervisory Controller Firmware
Jun 17, 2026
Sep 2, 2025
7.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, which returns all usernames and password hashes for the application services.
1Pdq
1Smart Deploy
Jun 17, 2026
Aug 22, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in PDQ Smart Deploy V.3.0.2040 allows an attacker to escalate privileges via the Credential encryption routines in SDCommon.dll
-
-
Jun 17, 2026
Aug 19, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX FX backend where API keys and authentication tokens may be exposed if environment variables are misco...Show more
GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX FX backend where API keys and authentication tokens may be exposed if environment variables are misconfigured. Unauthorized users could gain access to cloud resources (Google Cloud, Firebase, GitHub, etc.).Show less
1Santesoft
1Sante Pacs Server
Jun 17, 2026
Aug 18, 2025
9.1 CRITICAL· v4
7.5 HIGH· v3
N/A· v2
The Sante PACS Server Web Portal sends credential information without encryption.
1Siemens
1Simatic Rtls Locating Manager
Jun 17, 2026
Aug 12, 2025
4.8 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected SIMATIC RTLS Locating Manager Report Clients do not properly protect credentials that are used to authenticate to the s...Show more
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected SIMATIC RTLS Locating Manager Report Clients do not properly protect credentials that are used to authenticate to the server. This could allow an authenticated local attacker to extract the credentials and use them to escalate their access rights from the Manager to the Systemadministrator role.Show less
1Bmc
1Control M/server
Jun 17, 2026
Aug 7, 2025
4.8 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could observe these credentials and use them to log in to the database server...Show more
BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could observe these credentials and use them to log in to the database server. For example, when Control-M/Server on Windows has a database connection on, it runs 'DBUStatus.exe' frequently, which then calls 'dbu_connection_details.vbs' with the username, password, database hostname, and port written in cleartext, which can be seen in event and process logs in two separate locations. Fixed in PACTV.9.0.21.307.Show less
1Netwrix
1Directory Manager
Jun 17, 2026
Aug 7, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credentials for requests to remote Excel resources.