← Back
CWE-522

1,467 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,467)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Echostar
1Fusion
Jun 17, 2026
Sep 5, 2024
4.1 MEDIUM· v4
4.6 MEDIUM· v3
N/A· v2
Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow read-only access to network configuration information and terminal configuration data.
-
-
Jun 17, 2026
Sep 3, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Insufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow attackers in possession of a non-administrative Visual Planning account to utilize functions normally reserved for administrators...Show more
Insufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow attackers in possession of a non-administrative Visual Planning account to utilize functions normally reserved for administrators. The affected functions allow attackers to obtain different types of configured credentials and potentially elevate their privileges to administrator level.Show less
1Ibm
1Infosphere Information Server
Jun 17, 2026
Aug 15, 2024
N/A· v4
4.9 MEDIUM· v3
N/A· v2
IBM InfoSphere Information Server 11.7 could allow a privileged user to obtain sensitive information from authentication request headers. IBM X-Force ID: 298277.
1Gncchome
1Gncc C2 Firmware
Jun 17, 2026
Aug 15, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell via the UART Debugging Port.
1Prison Management System Project
1Prison Management System
Jun 17, 2026
Aug 15, 2024
6.9 MEDIUM· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. This issue affects some unknown processing of the file /uploadImage/Profile/ of the component Profile I...Show more
A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. This issue affects some unknown processing of the file /uploadImage/Profile/ of the component Profile Image Handler. The manipulation leads to insufficiently protected credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.Show less
1Zoom
4Rooms
WorkplaceWorkplace Desktop+1 more
Jun 17, 2026
Aug 14, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Protection mechanism failure for some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct information disclosure via network access.
1Zabbix
1Zabbix
Jun 17, 2026
Aug 12, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.
1Hamastar
1Meetinghub Paperless Meetings
Jun 17, 2026
Aug 5, 2024
9.3 CRITICAL· v4
9.1 CRITICAL· v3
N/A· v2
A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XM...Show more
A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file.Show less
1Incsub
1Forminator
Jun 17, 2026
Aug 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. This makes it possible for unauthenticated a...Show more
The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. This makes it possible for unauthenticated attackers to extract the HubSpot integration developer API key and make unauthorized changes to the plugin's HubSpot integration or expose personally identifiable information from plugin users using the HubSpot integration.Show less
1Proges
1Sensor Net Connect Firmware V2
Jun 17, 2026
Jul 31, 2024
N/A· v4
4.6 MEDIUM· v3
N/A· v2
A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext unless specific security measures at other la...Show more
A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext unless specific security measures at other layers (e.g., full-disk encryption) have been enabled.Show less
1Devolutions
1Remote Desktop Manager
Jun 17, 2026
Jul 16, 2024
N/A· v4
7.4 HIGH· v3
N/A· v2
Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on Windows allows an attacker to intercept proxy credentials via a specially crafted w...Show more
Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on Windows allows an attacker to intercept proxy credentials via a specially crafted website.Show less
1Ibm
1Datacap
Jun 17, 2026
Jul 14, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 295972.
-
-
Jun 17, 2026
Jul 3, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-2024.
-
-
Jun 17, 2026
Jul 2, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
The webserver utilizes basic authentication for its user login to the configuration interface. As encryption is disabled on port 80, it enables potential eavesdropping on user traffic, making it possible to intercept the...Show more
The webserver utilizes basic authentication for its user login to the configuration interface. As encryption is disabled on port 80, it enables potential eavesdropping on user traffic, making it possible to intercept their credentials.Show less
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 1, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings
1Jetbrains
1Teamcity
Jun 17, 2026
Jul 1, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection
1Jetbrains
1Youtrack
Jun 17, 2026
Jun 18, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site
-
-
Jun 17, 2026
Jun 14, 2024
N/A· v4
3.7 LOW· v3
N/A· v2
HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header.  This could allow an attacker to intercept or manipulate data during redirection.
-
-
Jun 17, 2026
Jun 13, 2024
7.0 HIGH· v4
N/A· v3
N/A· v2
Logs storing credentials are insufficiently protected and can be decoded through the use of open source tools.
-
-
Jun 17, 2026
Jun 13, 2024
8.5 HIGH· v4
N/A· v3
N/A· v2
Utilizing default credentials, an attacker is able to log into the camera's operating system which could allow changes to be made to the operations or shutdown the camera requiring a physical reboot of the system.