← Back
CWE-522

1,467 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,467)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Jun 9, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to rece...Show more
Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.Show less
1Ibm
2Cognos Controller
Controller
Jun 17, 2026
May 27, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently included within the source code.
1Meddream
1Pacs Server
Jun 17, 2026
May 22, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
MedDream WEB DICOM Viewer Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Me...Show more
MedDream WEB DICOM Viewer Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of MedDream WEB DICOM Viewer. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Web Portal. The issue results from the lack of encryption when transmitting credentials. An attacker can leverage this vulnerability to disclose transmitted credentials, leading to further compromise. Was ZDI-CAN-25842.Show less
-
-
Jun 17, 2026
May 20, 2025
6.3 MEDIUM· v4
8.7 HIGH· v3
N/A· v2
A passback vulnerability which relates to office/small office multifunction printers and laser printers.
-
-
Jun 17, 2026
May 20, 2025
6.3 MEDIUM· v4
8.7 HIGH· v3
N/A· v2
A passback vulnerability which relates to production printers and office multifunction printers.
1Synology
1Active Backup For Microsoft 365
Jun 17, 2026
May 16, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive information via unspecified vectors.
1Ibm
1Sterling Partner Engagement Manager
Jun 17, 2026
May 7, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm Charts and is not stored as a Kubernetes secret.
-
-
Jun 17, 2026
May 6, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
phpgt/Dom provides access to modern DOM APIs. Versions of phpgt/Dom prior to 4.1.8 expose the GITHUB_TOKEN in the Dom workflow run artifact. The ci.yml workflow file uses actions/upload-artifact@v4 to upload the build ar...Show more
phpgt/Dom provides access to modern DOM APIs. Versions of phpgt/Dom prior to 4.1.8 expose the GITHUB_TOKEN in the Dom workflow run artifact. The ci.yml workflow file uses actions/upload-artifact@v4 to upload the build artifact. This artifact is a zip of the current directory, which includes the automatically generated .git/config file containing the run's GITHUB_TOKEN. Seeing as the artifact can be downloaded prior to the end of the workflow, there is a few seconds where an attacker can extract the token from the artifact and use it with the GitHub API to push malicious code or rewrite release commits in your repository. Any downstream user of the repository may be affected, but the token should only be valid for the duration of the workflow run, limiting the time during which exploitation could occur. Version 4.1.8 fixes the issue.Show less
1Bectechnologies
1Router Firmware
Jun 17, 2026
Apr 23, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installation...Show more
BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of BEC Technologies routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within /cgi-bin/tools_usermanage.asp. The issue results from transmitting a list of users and their credentials to be handled on the client side. An attacker can leverage this vulnerability to disclose transported credentials, leading to further compromise. Was ZDI-CAN-25895.Show less
-
-
Jun 17, 2026
Apr 22, 2025
6.9 MEDIUM· v4
N/A· v3
N/A· v2
MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided for the `spec.audiences` field, the default will be of the Kubernetes apiserver. Without scoping, it...Show more
MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided for the `spec.audiences` field, the default will be of the Kubernetes apiserver. Without scoping, it can be replayed to other internal systems, which may unintentionally trust it. This issue has been patched in version 7.1.0.Show less
1Electrolink
1Fm/dab/tv Transmitter Web Management System
Jun 17, 2026
Apr 18, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and Display v1.4, v1.2 allows unauthorized attackers to access credentials in plaintext.
-
-
Jun 17, 2026
Apr 14, 2025
9.3 CRITICAL· v4
N/A· v3
N/A· v2
Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery. Passwords are either stored in plain text using reversible encryption, allowing an attacker with sufficient privileg...Show more
Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery. Passwords are either stored in plain text using reversible encryption, allowing an attacker with sufficient privileges to extract plain text passwords easily. This issue affects BASEC: from 14 Dec 2021.Show less
1Adobe
3Commerce
Commerce B2bMagento
Jun 17, 2026
Apr 8, 2025
N/A· v4
2.7 LOW· v3
N/A· v2
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could lead to a security feature bypass. A high privile...Show more
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to gain unauthorized access to protected resources by obtaining sensitive credential information. Exploitation of this issue does not require user interaction.Show less
1Microsoft
1Azure Local Cluster
Jun 17, 2026
Apr 8, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally.
-
-
Jun 17, 2026
Mar 28, 2025
8.5 HIGH· v4
N/A· v3
N/A· v2
The exposure of credentials in the call forwarding configuration module in MeetMe products in versions prior to 2024-09 allows an attacker to gain access to some important assets via configuration files.
-
-
Jun 17, 2026
Mar 20, 2025
N/A· v4
9.0 CRITICAL· v3
N/A· v2
Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication Bypass, Interface Ma...Show more
Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication Bypass, Interface Manipulation, Authentication Abuse, Harvesting Information via API Event Monitoring. This issue affects SecHard: before 3.3.0.20220411.Show less
-
-
Jun 17, 2026
Mar 17, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An issue in the storage of NFC card data in Dorset DG 201 Digital Lock H5_433WBSK_v2.2_220605 allows attackers to produce cloned NFC cards to bypass authentication.
1Devolutions
1Devolutions Server
Jun 17, 2026
Mar 13, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user to unadvertently leak his SSH password due to missing password masking.
1Nintex
1Automation
Jun 17, 2026
Mar 10, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are readable by unauthorized users.
1Ibm
1Sterling File Gateway
Jun 17, 2026
Mar 10, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path of the server which could aid in further attacks against the system.