← Back
CWE-522

1,467 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,467)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ovarro
8Tbox Lt2 530 Firmware
Tbox Lt2 532 FirmwareTbox Lt2 540 Firmware+5 more
Jun 17, 2026
Jul 28, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.
1Jenkins
1Http Request
Jun 17, 2026
Jul 27, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller fi...Show more
Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.Show less
1Anchore
2Anchore
Anchorectl
Jun 17, 2026
Jul 20, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add the credentials used to access Anchore Enterprise API in the Software Bill of Ma...Show more
Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add the credentials used to access Anchore Enterprise API in the Software Bill of Materials (SBOM) generated by anchorectl. Users of anchorectl version 0.1.4 should upgrade to anchorectl version 0.1.5 to resolve this issue.Show less
1Hcltech
1Bigfix Platform
Jun 17, 2026
Jul 19, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
BigFix Web Reports authorized users may see SMTP credentials in clear text.
1Westerndigital
2My Cloud Home Duo Firmware
My Cloud Home Firmware
Jun 17, 2026
Jul 12, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Implemented protections on AWS credentials that were not properly protected.
1Codesys
1Opc Da Server
Jun 17, 2026
Jul 11, 2022
N/A· v4
5.5 MEDIUM· v3
4.7 MEDIUM· v2
The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is visible to all authorized Microsoft Windows users of the system.
1Rpc.py Project
1Rpc.py
Jun 17, 2026
Jul 8, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, although JSON (not Pickle) is the default data format, an unauthenticated cl...Show more
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, although JSON (not Pickle) is the default data format, an unauthenticated client can cause the data to be processed with unpickle.Show less
1Hcltechsw
1Hcl Launch
Jun 17, 2026
Jul 6, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
HCL Launch stores user credentials in plain clear text which can be read by a local user.
1Pingidentity
1Pingid Integration For Windows Login
Jun 17, 2026
Jun 30, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circumstances.
1Jenkins
1Hpe Network Virtualization
Jun 17, 2026
Jun 30, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins HPE Network Virtualization Plugin 1.0 stores passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
1Jenkins
1Rqm
Jun 17, 2026
Jun 30, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins RQM Plugin 2.8 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
1Jenkins
1Cisco Spark
Jun 17, 2026
Jun 30, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Cisco Spark Plugin 1.1.1 and earlier stores bearer tokens unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system...Show more
Jenkins Cisco Spark Plugin 1.1.1 and earlier stores bearer tokens unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.Show less
1Jenkins
1Elasticsearch Query
Jun 17, 2026
Jun 30, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Elasticsearch Query Plugin 1.2 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file syste...Show more
Jenkins Elasticsearch Query Plugin 1.2 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.Show less
1Jenkins
1Jigomerge
Jun 17, 2026
Jun 30, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Jigomerge Plugin 0.9 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller...Show more
Jenkins Jigomerge Plugin 0.9 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.Show less
1Jenkins
1Skype Notifier
Jun 17, 2026
Jun 30, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Skype notifier Plugin 1.1.0 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
1Jenkins
1Opsgenie
Jun 17, 2026
Jun 30, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins OpsGenie Plugin 1.9 and earlier stores API keys unencrypted in its global configuration file and in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission (...Show more
Jenkins OpsGenie Plugin 1.9 and earlier stores API keys unencrypted in its global configuration file and in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission (config.xml), or access to the Jenkins controller file system.Show less
1Jenkins
1Rocketchat Notifier
Jun 17, 2026
Jun 30, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the...Show more
Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.Show less
1Jenkins
1Build Notifications
Jun 17, 2026
Jun 30, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file syst...Show more
Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.Show less
1Jenkins
1Deployment Dashboard
Jun 17, 2026
Jun 30, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Deployment Dashboard Plugin 1.0.10 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file s...Show more
Jenkins Deployment Dashboard Plugin 1.0.10 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.Show less
1Marvalglobal
1Marval Msm
Jun 17, 2026
Jun 28, 2022
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, this means that the user can also escalate achieve Privilege Escalation b...Show more
Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, this means that the user can also escalate achieve Privilege Escalation by changing the administrator password.Show less