CWE-522
1,467 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,467)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. |
An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify database connections to disclose a connections' cleartext password via the...Show more |
Insufficiently protected credentials in the Intel(R) DCM software before version 5.0.1 may allow an authenticated user to potentially enable information disclosure via network access. |
A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to insufficient...Show more |
PostgresNIO is a Swift client for PostgreSQL. Any user of PostgresNIO prior to version 1.14.2 connecting to servers with TLS enabled is vulnerable to a man-in-the-middle attacker injecting false responses to the client's...Show more |
SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the binaries over the network. This could allow an unauthenticated attacker with deep knowledge to...Show more |
Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request.
|
An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions, 8.7.0 all versions may allow a local attacker with syst...Show more |
1Lenovo 109Thinkagile Hx1021 Firmware Thinkagile Hx1320 FirmwareThinkagile Hx1321 Firmware+106 moreJun 17, 2026 Apr 28, 2023 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposu...Show more |
Plaintext Password in Registry vulnerability in 42gears surelock windows surelockwinsetupv2.40.0.Exe on Windows (Registery modules) allows Retrieve Admin user credentials This issue affects surelock windows: from 2...Show more |
1Gajshield 1Data Security Firewall Firmware Jun 17, 2026 Apr 27, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to insecure default credentials which allows remote attacker to login as superuser by using default userna...Show more |
typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-rest-client library version 1.7.3 or lower are vulnerable to leak authentication data to 3rd parties....Show more |
Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credentials for the Asteris...Show more |
2Hp Hpe2Oneview Oneview Global DashboardJun 17, 2026 Apr 25, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens |
An HPE OneView appliance dump may expose SNMPv3 read credentials |
An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules |
An HPE OneView appliance dump may expose SAN switch administrative credentials |
An HPE OneView appliance dump may expose OneView user accounts |
An HPE OneView appliance dump may expose proxy credential settings |
An authenticated user with specific data permissions could access database connections stored passwords by requesting a specific REST API. This issue affects Apache Superset version 1.3.0 up to 2.0.1. |