CWE-522
1,396 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,396)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that the system can startup on its own, the credentials of the administrator were stored. Consequently,...Show more |
In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources |
An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to reading vaults that have been previously disabled, poss...Show more |
1Zyxel 14Sbg3300 N000 Firmware Sbg3300 Nb00 FirmwareSbg3500 N000 Firmware+11 moreJun 17, 2026 Feb 4, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 **UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management int...Show more |
With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access. |
1Rockwellautomation 1Factorytalk Assetcentre Jun 17, 2026 Jan 30, 2025 7.0 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which could...Show more |
1Rockwellautomation 1Factorytalk Assetcentre Jun 17, 2026 Jan 30, 2025 7.3 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the configuration file of EventLogAttachmen...Show more |
1Rockwellautomation 1Factorytalk Assetcentre Jun 17, 2026 Jan 30, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extr...Show more |
Password Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileges, execute arbitrary code and obtain sensitive information via the password and account number para...Show more |
The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core_Fix7 allows remote attackers to reach the administration panel and discover hostname and version in...Show more |
IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user. |
Unsafe password recovery from configuration in M-Files Server before 25.1 allows a highly privileged user to recover external connector passwords |
GRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the user's password is compared to the user's decrypted cleartext password. An attacker with Windows admin or debugging righ...Show more |
GitHub Desktop is an open-source Electron-based GitHub app designed for git development. An attacker convincing a user to clone a repository directly or through a submodule can allow the attacker access to the user's cre...Show more |
An NTLM hash leak in Venki Supravizio BPM up to 18.0.1 allows authenticated attackers with Application Administrator access to escalate privileges on the underlying host system. |
HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to identity theft and system control. This vulnerability arises from poor...Show more |
1Dell 42Vxrail D560 Firmware Vxrail D560f FirmwareVxrail E460 Firmware+39 moreJun 17, 2026 Jan 8, 2025 N/A· v4 4.4 MEDIUM· v3 N/A· v2 Dell VxRail, versions 8.0.000 through 8.0.311, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information...Show more |
1Dell 42Vxrail D560 Firmware Vxrail D560f FirmwareVxrail E460 Firmware+39 moreJun 17, 2026 Jan 8, 2025 N/A· v4 4.4 MEDIUM· v3 N/A· v2 Dell VxRail, versions 7.0.000 through 7.0.532, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information...Show more |
In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission |
There is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can crafts software package to exploit this vulnerability. Due to insufficient verification, successful...Show more |