← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Apr 14, 2025
9.3 CRITICAL· v4
N/A· v3
N/A· v2
Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery. Passwords are either stored in plain text using reversible encryption, allowing an attacker with sufficient privileg...Show more
Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery. Passwords are either stored in plain text using reversible encryption, allowing an attacker with sufficient privileges to extract plain text passwords easily. This issue affects BASEC: from 14 Dec 2021.Show less
1Adobe
3Commerce
Commerce B2bMagento
Jun 17, 2026
Apr 8, 2025
N/A· v4
2.7 LOW· v3
N/A· v2
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could lead to a security feature bypass. A high privile...Show more
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to gain unauthorized access to protected resources by obtaining sensitive credential information. Exploitation of this issue does not require user interaction.Show less
1Microsoft
1Azure Local Cluster
Jun 17, 2026
Apr 8, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally.
-
-
Jun 17, 2026
Mar 28, 2025
8.5 HIGH· v4
N/A· v3
N/A· v2
The exposure of credentials in the call forwarding configuration module in MeetMe products in versions prior to 2024-09 allows an attacker to gain access to some important assets via configuration files.
-
-
Jun 17, 2026
Mar 20, 2025
N/A· v4
9.0 CRITICAL· v3
N/A· v2
Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication Bypass, Interface Ma...Show more
Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication Bypass, Interface Manipulation, Authentication Abuse, Harvesting Information via API Event Monitoring. This issue affects SecHard: before 3.3.0.20220411.Show less
-
-
Jun 17, 2026
Mar 17, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An issue in the storage of NFC card data in Dorset DG 201 Digital Lock H5_433WBSK_v2.2_220605 allows attackers to produce cloned NFC cards to bypass authentication.
1Devolutions
1Devolutions Server
Jun 17, 2026
Mar 13, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user to unadvertently leak his SSH password due to missing password masking.
1Nintex
1Automation
Jun 17, 2026
Mar 10, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are readable by unauthorized users.
1Ibm
1Sterling File Gateway
Jun 17, 2026
Mar 10, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path of the server which could aid in further attacks against the system.
-
-
Jun 17, 2026
Mar 7, 2025
7.1 HIGH· v4
N/A· v3
N/A· v2
Pass-Back vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to discover stored SMTP credentials.
-
-
Jun 17, 2026
Mar 5, 2025
10.0 CRITICAL· v4
N/A· v3
N/A· v2
Insufficiently Protected Credentials vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux, 64 bit allows Privilege Abuse. This vulnerability could allow an authenticated user to obtain higher pri...Show more
Insufficiently Protected Credentials vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux, 64 bit allows Privilege Abuse. This vulnerability could allow an authenticated user to obtain higher privileged user’s sensitive information via crafted payload. This issue affects Identity Manager Advanced Edition: from 4.8.0.0 through 4.8.7.0102, 4.9.0.0.Show less
1Printerlogic
2Vasion Print
Virtual Appliance
Jun 17, 2026
Mar 5, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Private Keys in Docker Overlay V-2023-013.
1Printerlogic
2Vasion Print
Virtual Appliance
Jun 17, 2026
Mar 5, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Cross Tenant Password Exposure V-2024-003.
1Ibm
1Engineering Requirements Management Doors Next
Jun 17, 2026
Mar 3, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose application logic or other sensitive information.
1Ibm
1Engineering Requirements Management Doors Next
Jun 17, 2026
Mar 3, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose application logic or other sensitive information.
-
-
Jul 5, 2026
Feb 28, 2025
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Cryptographic key extraction from internal flash in Minut M2 with firmware version #15142 allows physically proximate attackers to inject modified firmware into any other Minut M2 product via USB.
-
-
Jun 17, 2026
Feb 27, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.
1Extremenetworks
1Xiq Se
Jun 17, 2026
Feb 27, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation.
-
-
Jun 17, 2026
Feb 26, 2025
N/A· v4
2.7 LOW· v3
N/A· v2
A Credential Disclosure vulnerability exists where an administrator could extract the stored SMTP account credentials due to lack of encryption.
-
-
Jun 17, 2026
Feb 20, 2025
N/A· v4
6.3 MEDIUM· v3
N/A· v2
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. (CWE-522)   Hitachi Vantara Pentaho Data Integration &...Show more
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. (CWE-522)   Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when saving connections to RedShift.   Products must not disclose sensitive information without cause. Disclosure of sensitive information can lead to further exploitation.Show less