← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Feb 14, 2025
N/A· v4
9.9 CRITICAL· v3
N/A· v2
The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that the system can startup on its own, the credentials of the administrator were stored. Consequently,...Show more
The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that the system can startup on its own, the credentials of the administrator were stored. Consequently, the EPC2 user can execute any command with administrative privileges. This allows a privilege escalation to the administrative level.Show less
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 11, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources
1Clear
1Clearml Enterprise Server
Jun 17, 2026
Feb 6, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to reading vaults that have been previously disabled, poss...Show more
An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to reading vaults that have been previously disabled, possibly leaking sensitive credentials. An attacker can send a series of HTTP requests to trigger this vulnerability.Show less
1Zyxel
14Sbg3300 N000 Firmware
Sbg3300 Nb00 FirmwareSbg3500 N000 Firmware+11 more
Jun 17, 2026
Feb 4, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management int...Show more
**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.Show less
-
-
Jun 17, 2026
Feb 3, 2025
N/A· v4
7.6 HIGH· v3
N/A· v2
With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access.
1Rockwellautomation
1Factorytalk Assetcentre
Jun 17, 2026
Jan 30, 2025
7.0 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which could...Show more
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which could allow a threat actor to steal a token and, impersonate another user.Show less
1Rockwellautomation
1Factorytalk Assetcentre
Jun 17, 2026
Jan 30, 2025
7.3 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the configuration file of EventLogAttachmen...Show more
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the configuration file of EventLogAttachmentExtractor, ArchiveExtractor, LogCleanUp, or ArchiveLogCleanUp packages.Show less
1Rockwellautomation
1Factorytalk Assetcentre
Jun 17, 2026
Jan 30, 2025
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extr...Show more
An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extract passwords belonging to other users of the application.Show less
-
-
Jun 17, 2026
Jan 29, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Password Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileges, execute arbitrary code and obtain sensitive information via the password and account number para...Show more
Password Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileges, execute arbitrary code and obtain sensitive information via the password and account number parameters.Show less
-
-
Jun 17, 2026
Jan 29, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core_Fix7 allows remote attackers to reach the administration panel and discover hostname and version in...Show more
The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core_Fix7 allows remote attackers to reach the administration panel and discover hostname and version information by sending an arbitrary username and a blank password to the /WmAdmin/#/login/ URI.Show less
1Ibm
1Common Licensing
Jun 17, 2026
Jan 26, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user.
1M Files
1M Files Server
Jun 17, 2026
Jan 23, 2025
4.6 MEDIUM· v4
4.9 MEDIUM· v3
N/A· v2
Unsafe password recovery from configuration in M-Files Server before 25.1 allows a highly privileged user to recover external connector passwords
-
-
Jun 17, 2026
Jan 22, 2025
N/A· v4
5.7 MEDIUM· v3
N/A· v2
GRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the user's password is compared to the user's decrypted cleartext password. An attacker with Windows admin or debugging righ...Show more
GRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the user's password is compared to the user's decrypted cleartext password. An attacker with Windows admin or debugging rights can therefore steal the user's Blocky password and from there impersonate that local user.Show less
-
-
Jun 17, 2026
Jan 15, 2025
N/A· v4
6.6 MEDIUM· v3
N/A· v2
GitHub Desktop is an open-source Electron-based GitHub app designed for git development. An attacker convincing a user to clone a repository directly or through a submodule can allow the attacker access to the user's cre...Show more
GitHub Desktop is an open-source Electron-based GitHub app designed for git development. An attacker convincing a user to clone a repository directly or through a submodule can allow the attacker access to the user's credentials through the use of maliciously crafted remote URL. GitHub Desktop relies on Git to perform all network related operations (such as cloning, fetching, and pushing). When a user attempts to clone a repository GitHub Desktop will invoke `git clone` and when Git encounters a remote which requires authentication it will request the credentials for that remote host from GitHub Desktop using the git-credential protocol. Using a maliciously crafted URL it's possible to cause the credential request coming from Git to be misinterpreted by Github Desktop such that it will send credentials for a different host than the host that Git is currently communicating with thereby allowing for secret exfiltration. GitHub username and OAuth token, or credentials for other Git remote hosts stored in GitHub Desktop could be improperly transmitted to an unrelated host. Users should update to GitHub Desktop 3.4.12 or greater which fixes this vulnerability. Users who suspect they may be affected should revoke any relevant credentials.Show less
1Venki
1Supravizio Bpm
Jun 17, 2026
Jan 13, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
An NTLM hash leak in Venki Supravizio BPM up to 18.0.1 allows authenticated attackers with Application Administrator access to escalate privileges on the underlying host system.
1Hcltech
1Dryice Myxalytics
Jun 17, 2026
Jan 11, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to identity theft and system control. This vulnerability arises from poor...Show more
HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to identity theft and system control. This vulnerability arises from poor configuration, logic errors, or software bugs and can affect any application with access control, including databases, network infrastructure, and web applications.Show less
1Dell
42Vxrail D560 Firmware
Vxrail D560f FirmwareVxrail E460 Firmware+39 more
Jun 17, 2026
Jan 8, 2025
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Dell VxRail, versions 8.0.000 through 8.0.311, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information...Show more
Dell VxRail, versions 8.0.000 through 8.0.311, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.Show less
1Dell
42Vxrail D560 Firmware
Vxrail D560f FirmwareVxrail E460 Firmware+39 more
Jun 17, 2026
Jan 8, 2025
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Dell VxRail, versions 7.0.000 through 7.0.532, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information...Show more
Dell VxRail, versions 7.0.000 through 7.0.532, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.Show less
1Jetbrains
1Teamcity
Jun 17, 2026
Dec 20, 2024
N/A· v4
4.9 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission
1Huawei
1Mate 20 Pro Firmware
Jun 17, 2026
Dec 20, 2024
N/A· v4
3.3 LOW· v3
N/A· v2
There is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can crafts software package to exploit this vulnerability. Due to insufficient verification, successful...Show more
There is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can crafts software package to exploit this vulnerability. Due to insufficient verification, successful exploitation may impact the service. (Vulnerability ID: HWPSIRT-2019-12302) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9250.Show less