CWE-522
1,467 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,467)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow read-only access to network configuration information and terminal configuration data. |
Insufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow attackers in possession of a non-administrative Visual Planning account to utilize functions normally reserved for administrators...Show more |
1Ibm 1Infosphere Information Server Jun 17, 2026 Aug 15, 2024 N/A· v4 4.9 MEDIUM· v3 N/A· v2 IBM InfoSphere Information Server 11.7 could allow a privileged user to obtain sensitive information from authentication request headers. IBM X-Force ID: 298277. |
Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell via the UART Debugging Port. |
1Prison Management System Project 1Prison Management System Jun 17, 2026 Aug 15, 2024 6.9 MEDIUM· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. This issue affects some unknown processing of the file /uploadImage/Profile/ of the component Profile I...Show more |
1Zoom 4Rooms WorkplaceWorkplace Desktop+1 moreJun 17, 2026 Aug 14, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Protection mechanism failure for some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct information disclosure via network access. |
The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text. |
1Hamastar 1Meetinghub Paperless Meetings Jun 17, 2026 Aug 5, 2024 9.3 CRITICAL· v4 9.1 CRITICAL· v3 N/A· v2 A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XM...Show more |
The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. This makes it possible for unauthenticated a...Show more |
1Proges 1Sensor Net Connect Firmware V2 Jun 17, 2026 Jul 31, 2024 N/A· v4 4.6 MEDIUM· v3 N/A· v2 A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext unless specific security measures at other la...Show more |
Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on Windows allows an attacker to intercept proxy credentials via a specially crafted w...Show more |
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 295972. |
The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-2024. |
The webserver utilizes basic authentication for its user login to the configuration interface. As encryption is disabled on port 80, it enables potential eavesdropping on user traffic, making it possible to intercept the...Show more |
In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings |
In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection |
In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site |
HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header. This could allow an attacker to intercept or manipulate data during redirection. |
Logs storing credentials are insufficiently protected and can be decoded through the use of open source tools. |
Utilizing default credentials, an attacker is able to log into the camera's operating system which could allow changes to be made to the operations or shutdown the camera requiring a physical reboot of the system. |