← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Typed Rest Client
Jun 17, 2026
Apr 26, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-rest-client library version 1.7.3 or lower are vulnerable to leak authentication data to 3rd parties....Show more
typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-rest-client library version 1.7.3 or lower are vulnerable to leak authentication data to 3rd parties. The flow of the vulnerability is as follows: First, send any request with `BasicCredentialHandler`, `BearerCredentialHandler` or `PersonalAccessTokenCredentialHandler`. Second, the target host may return a redirection (3xx), with a link to a second host. Third, the next request will use the credentials to authenticate with the second host, by setting the `Authorization` header. The expected behavior is that the next request will *NOT* set the `Authorization` header. The problem was fixed in version 1.8.0. There are no known workarounds.Show less
1Sangoma
1Freepbx Linux 7
Jun 17, 2026
Apr 26, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credentials for the Asteris...Show more
Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credentials for the Asterisk Database (MariaDB/MySQL) and Asterisk Manager Interface. For example, an attacker can make a /ari/asterisk/variable?variable=AMPDBPASS API call.Show less
2Hp
Hpe
2Oneview
Oneview Global Dashboard
Jun 17, 2026
Apr 25, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens
1Hp
1Oneview
Jun 17, 2026
Apr 25, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An HPE OneView appliance dump may expose SNMPv3 read credentials
1Hp
1Oneview
Jun 17, 2026
Apr 25, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules
1Hp
1Oneview
Jun 17, 2026
Apr 25, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An HPE OneView appliance dump may expose SAN switch administrative credentials
1Hp
1Oneview
Jun 17, 2026
Apr 25, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An HPE OneView appliance dump may expose OneView user accounts
1Hp
1Oneview
Jun 17, 2026
Apr 25, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An HPE OneView appliance dump may expose proxy credential settings
1Apache
1Superset
Jun 17, 2026
Apr 24, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An authenticated user with specific data permissions could access database connections stored passwords by requesting a specific REST API. This issue affects Apache Superset version 1.3.0 up to 2.0.1.
1Expo
1Expo Software Development Kit
Jun 17, 2026
Apr 24, 2023
N/A· v4
9.6 CRITICAL· v3
N/A· v2
A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achi...Show more
A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicious link. The link itself may be sent to the victim in various ways (including email, text message, an attacker-controlled website, etc).Show less
1Ribose
1Rnp
Jun 17, 2026
Apr 21, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Ribose RNP before 0.15.1 does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than on the tin of the algorithm.
1Uniguest
1Tripleplay
Jun 17, 2026
Apr 19, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Incorrect Access Control in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated user to modify other users passwords via a crafted request payload
1Secomea
1Gatemanager
Jun 17, 2026
Apr 19, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file is leaked.
1Aten
1Pe8108 Firmware
Jun 17, 2026
Apr 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Telnet and SNMP credentials.
1Aten
1Pe8108 Firmware
Jun 17, 2026
Apr 11, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. Restricted users have read access to administrator credentials.
1Devolutions
1Remote Desktop Manager
Jun 17, 2026
Apr 2, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Information disclosure in the user creation feature of a MSSQL data source in Devolutions Remote Desktop Manager 2023.1.9 and below on Windows allows an attacker with access to the user interface to obtain sensitive info...Show more
Information disclosure in the user creation feature of a MSSQL data source in Devolutions Remote Desktop Manager 2023.1.9 and below on Windows allows an attacker with access to the user interface to obtain sensitive information via the error message dialog that displays the password in clear text. Show less
1Jetbrains
1Intellij Idea
Jun 17, 2026
Mar 29, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.
1Cpplusworld
1Kvms Pro
Jun 17, 2026
Mar 28, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
CP Plus KVMS Pro versions 2.01.0.T.190521 and prior are vulnerable to sensitive credentials being leaked because they are insufficiently protected.  
1Deltaww
1Infrasuite Device Master
Jun 17, 2026
Mar 27, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which a low-level user could extract files and plaintext credentials of administrator users, resulting in privilege escalation...Show more
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which a low-level user could extract files and plaintext credentials of administrator users, resulting in privilege escalation.Show less
1Ibm
1Security Key Lifecycle Manager
Jun 17, 2026
Mar 21, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 247601.