← Back
CWE-522

1,467 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,467)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Litespeedtech
1Litespeed Cache
Jun 17, 2026
Oct 20, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a through < 6.5.0.1.
-
-
Jun 17, 2026
Oct 17, 2024
7.1 HIGH· v4
8.2 HIGH· v3
N/A· v2
The EWON FLEXY 202 transmits credentials using a weak encoding method base64. An attacker who is present in the network can sniff the traffic and decode the credentials.
-
-
Jun 17, 2026
Oct 17, 2024
8.7 HIGH· v4
N/A· v3
N/A· v2
The affected product is vulnerable due to insufficiently protected credentials, which may allow an attacker to impersonate Elvaco and send false information.
1Cisco
2Ata 191 Firmware
Ata 192 Firmware
Jun 17, 2026
Oct 16, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware could allow an authenticated, local attacker with low privileges to view passwords on an affec...Show more
A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware could allow an authenticated, local attacker with low privileges to view passwords on an affected device. This vulnerability is due to incorrect sanitization of HTML content from an affected device. A successful exploit could allow the attacker to view passwords that belong to other users.Show less
1Jetbrains
1Teamcity
Jun 17, 2026
Oct 8, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API
1Jenkins
1Credentials
Jun 17, 2026
Oct 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST API o...Show more
Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST API or CLI.Show less
1Advantech
1Adam 5550 Firmware
Jun 17, 2026
Sep 27, 2024
6.8 MEDIUM· v4
5.7 MEDIUM· v3
N/A· v2
Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.
1Advantech
1Adam 5630 Firmware
Jun 17, 2026
Sep 27, 2024
6.9 MEDIUM· v4
5.7 MEDIUM· v3
N/A· v2
Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.
1Topquadrant
1Topbraid Edg
Jun 17, 2026
Sep 27, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.pro...Show more
TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally. Version 8.3.0 warns when using plain text secrets.Show less
1Ibm
1Cognos Command Center
Jun 17, 2026
Sep 26, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could disclose highly sensitive user information to an authenticated user with physical access to the device.
1Pgadmin
1Pgadmin 4
Jun 17, 2026
Sep 23, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user d...Show more
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.Show less
1Ibm
2Cognos Analytics
Cognos Analytics Reports
Jun 17, 2026
Sep 22, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of a...Show more
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to launch further attacks against affected applications.Show less
1Jetbrains
1Youtrack
Jun 17, 2026
Sep 19, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page
-
-
Jun 17, 2026
Sep 19, 2024
9.1 CRITICAL· v4
N/A· v3
N/A· v2
The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as retrieved by running `git remote get-url origin`. If credentials are...Show more
The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as retrieved by running `git remote get-url origin`. If credentials are included in the repository URI (for instance, to allow for fetching of private dependencies), the final binary will contain the full URI, including said credentials.Show less
1Syscomgo
1Omflow
Jun 17, 2026
Sep 16, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read arbitrary system configurations. If LDAP authentication is enabled, attackers can obtain plaintext cre...Show more
OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read arbitrary system configurations. If LDAP authentication is enabled, attackers can obtain plaintext credentials.Show less
1Eaton
1Foreseer Electrical Power Monitoring System
Jun 17, 2026
Sep 13, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configur...Show more
The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configurations securely on the host machine. However, the keys used for this encryption were insecurely stored, which could be abused to possibly change or remove the server configuration.Show less
-
-
Jun 17, 2026
Sep 12, 2024
N/A· v4
8.5 HIGH· v3
N/A· v2
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields.
1Cisco
1Ios Xr
Jun 17, 2026
Sep 11, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB credentials. This vulnerability is due to improper...Show more
A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB credentials. This vulnerability is due to improper storage of the unencrypted database credentials on the device that is running Cisco IOS XR Software. An attacker could exploit this vulnerability by accessing the configuration files on an affected system. A successful exploit could allow the attacker to view MongoDB credentials.Show less
1Hathway
1Skyworth Cm5100 511 Firmware
Jun 17, 2026
Sep 10, 2024
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Sep 7, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and passwords). Exploiting these v...Show more
A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and passwords). Exploiting these vulnerabilities requires a user who has been assigned a low-privileged role within Veeam Backup & Replication.Show less