CWE-522
1,396 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,396)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. The Key Storage converter plugin mechanism was not enabled correctly in Rundeck 4.2.0 and 4.2.1, resulting in use of the e...Show more |
1Devolutions 1Remote Desktop Manager Jun 17, 2026 Jun 15, 2022 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 A lack of password masking in Devolutions Remote Desktop Manager allows physically proximate attackers to observe sensitive data. A caching issue can cause sensitive fields to sometimes stay revealed when closing and reo...Show more |
1Siemens 1Sicam Gridedge Essential Jun 17, 2026 Jun 14, 2022 6.9 MEDIUM· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application discloses password hashes of other users upon request. This could allow an authenticated user to retrieve...Show more |
Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure. |
Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certain cases. Credentials could be the remote vSnap, offload targets, or VADP credentials depending on t...Show more |
1Dell 3Unity Operating Environment Unity Xt Operating EnvironmentUnityvsa Operating EnvironmentJun 17, 2026 Jun 2, 2022 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certain off-array tools are run on the system. The credentials of a user with high pri...Show more |
PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authenticated attacker could potentially exploit this vulnerability, leading t...Show more |
6Brocade DebianFedoraproject+3 more13Clustered Data Ontap CurlDebian Linux+10 moreJun 17, 2026 Jun 2, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number. |
5Brocade DebianHaxx+2 more12Clustered Data Ontap CurlDebian Linux+9 moreJun 17, 2026 Jun 2, 2022 N/A· v4 5.7 MEDIUM· v3 3.5 LOW· v2 An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authenticat...Show more |
1Bd 16Pyxis Anesthesia Station Es Firmware Pyxis Ciisafe FirmwarePyxis Logistics Firmware+13 moreJun 17, 2026 Jun 2, 2022 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operat...Show more |
Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integratio...Show more |
Mobotix Control Center (MxCC) through 2.5.4.5 has Insufficiently Protected Credentials, Storing Passwords in a Recoverable Format via the MxCC.ini config file. The credential storage method in this software enables an at...Show more |
Jenkins Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier allows attackers with Job/Configure permission to access credentials with attacker-specified IDs stored in the private per-user credentials stores of any...Show more |
1Konicaminolta 45Bizhub 226i Firmware Bizhub 227 FirmwareBizhub 246i Firmware+42 moreJun 17, 2026 May 16, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Konica Minolta bizhub MFP devices before 2022-04-14 use cleartext password storage for the /var/log/nginx/html/ADMINPASS and /etc/shadow files. |
An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse improperly secured access to arbitrary files on the server (via /Electron/dow...Show more |
Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to access a victim's HTTP request, get the victim's cookie, perform a base64...Show more |
Dell EMC Repository Manager version 3.4.0 contains a plain-text password storage vulnerability. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The at...Show more |
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. When you pass the config to the javascript, some entries are filtered out. The v...Show more |
A malicious actor having access to the exported configuration file may obtain the stored credentials and thereby gain access to the protected resource. If the same passwords were used for other resources, further such as...Show more |
1Zohocorp 4Manageengine Adaudit Plus Manageengine Admanager PlusManageengine Adselfservice Plus+1 moreJun 17, 2026 Apr 18, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps. |