CWE-522
1,467 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,467)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Insecure Permissions vulnerability in Sichuan Tianyi Kanghe Communication Co., Ltd China Telecom Tianyi Home Gateway v.TEWA-700G allows a local attacker to obtain sensitive information via the default password parameter. |
1Ibm 2Sterling External Authentication Server Sterling Secure ProxyJun 17, 2026 Sep 5, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be read by a local user with container access. IBM X-Force ID: 255585. |
A pass-back vulnerability exists where an authenticated, remote attacker with administrator privileges could uncover stored SMTP credentials within the Nessus application.This issue affects Nessus: before 10.6.0....Show more |
1Fresenius Kabi 1Pharmahelp Firmware Jun 17, 2026 Aug 22, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in Fresenius Kabi PharmaHelp 5.1.759.0 allows attackers to gain escalated privileges via via capture of user login information. |
Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. Prior to version 1.0.5 Social media skeleton did not properly salt passwords leaving user password...Show more |
1Zohocorp 1Manageengine Admanager Plus Jun 17, 2026 Aug 17, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the authenticated users. |
1Jenkins 1Maven Artifact Choicelistprovider (nexus) Jun 17, 2026 Aug 16, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.14 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials t...Show more |
Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Overall/Read permission to access and capture credentials they are not entitled to. |
1Broadcom 1Raid Controller Web Interface Jun 17, 2026 Aug 15, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Windows |
1Broadcom 1Raid Controller Web Interface Jun 17, 2026 Aug 15, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux |
In processMessageImpl of ClientModeImpl.java, there is a possible credential disclosure in the TOFU flow due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution pr...Show more |
1Gatesair 1Flexiva Fax 150w Firmware Jul 9, 2026 Aug 3, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An isssue in GatesAIr Flexiva FM Transmitter/Exiter Fax 150W allows a remote attacker to gain privileges via the LDAP and SMTP credentials. |
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium) |
Plaintext Storage of a Password vulnerability in Infodrom Software E-Invoice Approval System allows Read Sensitive Strings Within an Executable.
This issue affects E-Invoice Approval System: before v.20230701. |
Weintek Weincloud v0.13.6
could allow an attacker to abuse the registration functionality to login with testing credentials to the official website. |
An issue found in DERICIA Co. Ltd, DELICIA v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp DELICIA function. |
1Sonicwall 2Analytics Global Management SystemJun 17, 2026 Jul 13, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions. |
Jenkins mabl Plugin 0.0.46 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to. |
An issue was discovered in Keeper Password Manager for Desktop version 16.10.2 (fixed in 17.2), and the KeeperFill Browser Extensions version 16.5.4 (fixed in 17.2), allows local attackers to gain sensitive information v...Show more |
1Microsoft 3Windows Server 2016 Windows Server 2019Windows Server 2022Jun 17, 2026 Jul 11, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Active Directory Federation Service Security Feature Bypass Vulnerability |